Changes Since Last Assessment
Counts are for Bedrock, SageMaker, AgentCore, and AWS Agent Registry. Agentic AI Security and OWASP rows are mostly derived from those findings, so one change can appear in several areas. The table below includes all assessment areas.
Changes by Assessment Area
| Assessment Area | Regressed | New | Still open | Resolved | No longer reported | No longer assessed |
|---|---|---|---|---|---|---|
| By Service | ||||||
| Bedrock | 0 | 1 | 6 | 0 | 1 | 0 |
| SageMaker | 1 | 0 | 2 | 0 | 0 | 1 |
| AgentCore | 0 | 0 | 5 | 2 | 0 | 0 |
| AWS Agent Registry | 2 | 1 | 0 | 0 | 0 | 0 |
| By Service total | 3 | 2 | 13 | 2 | 1 | 1 |
| By Lens | ||||||
| Agentic AI Security | 0 | 0 | 6 | 1 | 0 | 0 |
| By Governance Framework | ||||||
| Responsible AI GRC | 0 | 0 | 19 | 0 | 0 | 0 |
| By Compliance Standard | ||||||
| OWASP Top 10 LLM | 0 | 0 | 22 | 1 | 1 | 2 |
| Account ID | Region | Check ID | Finding | Severity | Change |
|---|---|---|---|---|---|
123456789012 |
us-east-1 |
SM-04 |
GuardDuty Not Enabled
Details and remediation |
High | ▼ Regressed Passed → Failed |
123456789012 |
Global |
AR-01 |
AWS Agent Registry IAM Full Access Policy
Details and remediationDetails (previous run) No roles with overly permissive AWS Agent Registry access found. Details (current run)
The following roles have AWS Agent Registry full-access policies: sample-registry-admin-role Resolution
Replace full-access policies with least-privilege AWS Agent Registry actions and scoped resources. |
High | ▼ Regressed Passed → Failed |
123456789012 |
Global |
AR-01 |
AWS Agent Registry IAM Wildcard Permissions
Details and remediationDetails (previous run) No roles with overly permissive AWS Agent Registry access found. Details (current run)
The following roles have wildcard or allow-except AWS Agent Registry permissions on all resources: sample-registry-admin-role Resolution
Replace wildcard permissions with required AWS Agent Registry actions and scoped resources. |
High | ▼ Regressed Passed → Failed |
123456789012 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
Role 'sample-new-app-role' has overly permissive marketplace subscription access through policy 'AWSMarketplaceFullAccess' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | ✚ New Not present → Failed |
123456789012 |
Global |
AR-02 |
AWS Agent Registry Stale Access Check
Details and remediationDetails (previous run) The following principals have AWS Agent Registry permissions but no service-last-accessed evidence: role 'AIMLSecurityMemberRole' Details (current run)
The following principals have AWS Agent Registry permissions they have not used: role 'sample-registry-role' Resolution
Review and remove unused AWS Agent Registry permissions following least privilege. |
Medium | ✚ New N/A → Failed |
123456789012 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
Role 'RescoAppStack-Ec2Role8DF2B528-BZ4vfVHs10Kw' has overly permissive marketplace subscription access through policy 'AWSElasticBeanstalkWebTier' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | ● Still open Failed → Failed |
123456789012 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
Role 'aws-elasticbeanstalk-ec2-role' has overly permissive marketplace subscription access through policy 'AWSElasticBeanstalkMulticontainerDocker' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | ● Still open Failed → Failed |
123456789012 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
Role 'xray-sample-SampleInstanceProfileRole-2YE24B4A5Y3RU' has overly permissive marketplace subscription access through policy 'AWSElasticBeanstalkWebTier' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | ● Still open Failed → Failed |
123456789012 |
Global |
BR-15 |
Cross-Account Guardrails Enforcement Check
|
High | ● Still open Failed → Failed |
123456789012 |
us-east-1 |
BR-37 |
Bedrock Account Data Retention
|
High | ● Still open Failed → Failed |
123456789012 |
us-east-2 |
BR-37 |
Bedrock Account Data Retention
|
High | ● Still open Failed → Failed |
123456789012 |
us-east-1 |
SM-26 |
GuardDuty AI Protection
|
High | ● Still open Failed → Failed |
123456789012 |
us-west-2 |
SM-26 |
GuardDuty AI Protection
|
High | ● Still open Failed → Failed |
123456789012 |
us-east-1 |
AC-17 |
AgentCore Online Evaluation Coverage
|
Medium | ● Still open Failed → Failed |
123456789012 |
us-east-2 |
AC-14 |
AgentCore Identity Token Vault CMK Encryption
|
High | ● Still open Failed → Failed |
123456789012 |
us-east-2 |
AC-17 |
AgentCore Online Evaluation Coverage
Details and remediationDetails (previous run) No AgentCore online evaluation configurations found. Details (current run) Online evaluation 'sample-agent-eval' (sample-agent-eval-0001) is missing one or more operational coverage settings. Note
Each run reported one Failed row for this check, so the two rows were paired, but their details differ. Check whether one resource was fixed and another started failing. Resolution
Set the evaluation ACTIVE and ENABLED, use non-zero sampling, add evaluators, and configure CloudWatch input and output log groups. |
Medium | ● Still open Failed → Failed · details changed |
123456789012 |
us-west-2 |
AC-14 |
AgentCore Identity Token Vault CMK Encryption
|
High | ● Still open Failed → Failed |
123456789012 |
us-west-2 |
AC-17 |
AgentCore Online Evaluation Coverage
|
Medium | ● Still open Failed → Failed |
123456789012 |
Global |
AG-09 |
Agentic AI Guardrail Enforcement Boundary
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Organization-level guardrail enforcement helps prevent agents from bypassing required safety controls across accounts. Source check BR-15: The Organizations Bedrock policy type is not enabled and no account-level enforced guardrail configuration was observed. Resolution
Use IAM and organization controls to require approved guardrails for model and agent invocations where supported. |
High | ● Still open Failed → Failed |
123456789012 |
us-east-1 |
AG-32 |
Agentic AI Online Evaluation Assurance
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Online evaluation provides continuous evidence about agent behavior, quality, and policy-relevant outcomes. Source check AC-17: No AgentCore online evaluation configurations found. Resolution
Configure an active AgentCore online evaluation with sampling, evaluators, CloudWatch input logs, and an output log group. |
Medium | ● Still open Failed → Failed |
123456789012 |
us-east-2 |
AG-28 |
Agentic AI Identity Token Vault Protection
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Agent credentials stored in the Identity token vault should use customer-controlled encryption where enhanced key control is required. Source check AC-14: AgentCore token vault 'default' uses a service-managed or AWS-owned key. Resolution
Configure the AgentCore Identity token vault with a customer-managed KMS key. |
High | ● Still open Failed → Failed |
123456789012 |
us-east-2 |
AG-32 |
Agentic AI Online Evaluation Assurance
Details and remediationDetails (previous run) Agentic AI security domain: Auditability & Continuous Assurance. Online evaluation provides continuous evidence about agent behavior, quality, and policy-relevant outcomes. Source check AC-17: No AgentCore online evaluation configurations found. Details (current run) Agentic AI security domain: Auditability & Continuous Assurance. Online evaluation provides continuous evidence about agent behavior, quality, and policy-relevant outcomes. Source check AC-17: Online evaluation 'sample-agent-eval' (sample-agent-eval-0001) is missing one or more operational coverage settings. Note
Each run reported one Failed row for this check, so the two rows were paired, but their details differ. Check whether one resource was fixed and another started failing. Resolution
Configure an active AgentCore online evaluation with sampling, evaluators, CloudWatch input logs, and an output log group. |
Medium | ● Still open Failed → Failed · details changed |
123456789012 |
us-west-2 |
AG-28 |
Agentic AI Identity Token Vault Protection
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Agent credentials stored in the Identity token vault should use customer-controlled encryption where enhanced key control is required. Source check AC-14: AgentCore token vault 'default' uses a service-managed or AWS-owned key. Resolution
Configure the AgentCore Identity token vault with a customer-managed KMS key. |
High | ● Still open Failed → Failed |
123456789012 |
us-west-2 |
AG-32 |
Agentic AI Online Evaluation Assurance
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Online evaluation provides continuous evidence about agent behavior, quality, and policy-relevant outcomes. Source check AC-17: No AgentCore online evaluation configurations found. Resolution
Configure an active AgentCore online evaluation with sampling, evaluators, CloudWatch input logs, and an output log group. |
Medium | ● Still open Failed → Failed |
123456789012 |
Global |
FS-01 |
AWS Shield Advanced Not Enabled
Details and remediationDetails
AWS Shield Advanced is not subscribed. GenAI API endpoints are vulnerable to volumetric DDoS attacks that can exhaust token quotas and inflate costs. Resolution
1. Subscribe to AWS Shield Advanced for DDoS protection. 2. After subscribing, explicitly add resource protections in the Shield Advanced console for each Bedrock-facing resource (API Gateway stages, ALBs, CloudFront distributions, Route 53 hosted zones). Shield Advanced subscription alone does NOT automatically protect resources — each resource must be individually added to receive protection. 3. Enable Shield Response Team (SRT) access and configure proactive engagement. 4. Alternatively, use AWS Firewall Manager with a Shield Advanced policy to automate resource protection based on tags or resource types. |
Low | ● Still open Failed → Failed |
123456789012 |
Global |
FS-01 |
No Regional WAF Web ACLs Found
Details and remediationDetails
No AWS WAF regional Web ACLs found. Without WAF, GenAI endpoints lack rate-based rules to block abusive callers. Resolution
1. Create a WAF Web ACL with rate-based rules (e.g., 1000 req/5 min per IP). 2. Associate the ACL with API Gateway stages or ALBs fronting Bedrock. 3. Add AWS Managed Rules for known bad inputs. |
Medium | ● Still open Failed → Failed |
123456789012 |
Global |
FS-04 |
No Cost Anomaly Detection Monitors
Details and remediationDetails
No AWS Cost Anomaly Detection monitors found. Unexpected spikes in Bedrock/SageMaker usage (e.g., from prompt injection loops) will go undetected. Resolution
1. Create a Cost Anomaly Detection monitor scoped to AWS/Bedrock and AWS/SageMaker. 2. Configure alert subscriptions (SNS/email) for anomalies above threshold. 3. Set daily spend budgets with AWS Budgets as a secondary control. |
Medium | ● Still open Failed → Failed |
123456789012 |
Global |
FS-05 |
No Bedrock CloudWatch Alarms Found
Details and remediationDetails
No CloudWatch alarms found for Bedrock metrics. Token exhaustion and throttling events will not trigger operational alerts. Resolution
Create CloudWatch alarms for: - AWS/Bedrock InvocationThrottles (threshold > 0) - AWS/Bedrock TokensProcessed (threshold based on quota) - Custom application-level token counters via EMF |
Medium | ● Still open Failed → Failed |
123456789012 |
Global |
FS-06 |
No AI/ML Service Budgets Configured
Details and remediationDetails
No AWS Budgets found scoped to Bedrock or SageMaker. Unbounded GenAI spend can go undetected until the monthly bill. Resolution
1. Create cost budgets for AWS Bedrock and SageMaker with 80%/100% alert thresholds. 2. Add SNS notifications to on-call channels. 3. Consider budget actions to apply IAM deny policies when thresholds are breached. |
Medium | ● Still open Failed → Failed |
123456789012 |
Global |
FS-09 |
Agent Lambda Functions Without Concurrency Limits
Details and remediationDetails
Agent-related Lambda functions without reserved concurrency: aiml-security-aiml-sec-123456789012-AgentCoreAssessment, aiml-security-aiml-sec-123456789012-CleanupBucket, aiml-security-aiml-sec-123456789012-ResolveRegions, aiml-security-aiml-sec-123456789012-SagemakerAssessment, aiml-security-aiml-sec-123456789012-GenerateReport, aiml-security-aiml-sec-123456789012-AgentRegistryAssessment, aiml-security-aiml-sec-123456789012-RAIGRCAssessment, aiml-security-aiml-sec-123456789012-BedrockAssessment, AIML-Standalone-CodeBuildStartBuildLambda-eAzlGvTTrtQW, aiml-security-aiml-sec-123456789012-IAMPermissionCaching. Unlimited concurrency allows runaway agent loops to exhaust account limits. Resolution
1. Set reserved concurrency on agent Lambda functions. 2. Implement maximum iteration counts in agent orchestration logic. 3. Use Step Functions with MaxConcurrency and timeout states. 4. Add circuit-breaker patterns to agent tool invocations. |
Medium | ● Still open Failed → Failed |
123456789012 |
Global |
FS-11 |
No Agent Rate Alarms Found
Details and remediationDetails
No CloudWatch alarms found for agent invocation rates. Looping or runaway agents will not trigger operational alerts. Resolution
Create CloudWatch alarms on: - Bedrock agent invocation counts (threshold based on expected max) - Lambda invocation errors for agent functions - Step Functions execution failures and timeouts |
Medium | ● Still open Failed → Failed |
123456789012 |
Global |
FS-12 |
No Bedrock-Scoped SCPs Found
Details and remediationDetails
No Service Control Policies reference Bedrock. Without SCPs, any account in the organization can access any Bedrock model, including unapproved third-party models. Resolution
1. Create an SCP that denies bedrock:InvokeModel, bedrock:InvokeModelWithResponseStream, and bedrock:CreateModelInvocationJob outside approved model access. 2. Use Resource or NotResource with approved foundation-model, custom-model, provisioned-model, and inference-profile ARNs to express the allowlist. 3. Maintain a model inventory and update the SCP when models are approved/retired. |
High | ● Still open Failed → Failed |
123456789012 |
Global |
FS-15 |
No Bedrock Evaluation Jobs Found
Details and remediationDetails
No Bedrock Model Evaluation jobs found. Models have not been evaluated for adversarial robustness. Model-risk management (SR 11-7) expects documented model validation/evaluation. Resolution
1. Run Bedrock Model Evaluation with adversarial/red-team datasets. 2. Use FMEval library for automated robustness testing. 3. Schedule periodic re-evaluation after model updates. |
Medium | ● Still open Failed → Failed |
123456789012 |
Global |
FS-22 |
Overly Permissive Knowledge Base IAM Roles
Details and remediationDetails
787 role(s) with wildcard KB permissions: - Role 'Admin' allows '*' - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-sl8sQor1MSud' allows 'bedrock:ListGuardrails' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-sl8sQor1MSud' allows 'bedrock:GetGuardrail' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-sl8sQor1MSud' allows 'bedrock:GetModelInvocationLoggingConfiguration' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-sl8sQor1MSud' allows 'bedrock:ListPrompts' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-sl8sQor1MSud' allows 'bedrock:GetPrompt' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-sl8sQor1MSud' allows 'bedrock:ListAgents' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-sl8sQor1MSud' allows 'bedrock:GetAgent' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-sl8sQor1MSud' allows 'bedrock:ListCustomModels' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-sl8sQor1MSud' allows 'bedrock:GetCustomModel' on Resource '*' (no ARN scoping to specific Knowledge Bases) Resolution
Replace wildcard bedrock:* with specific actions such as bedrock:Retrieve, bedrock:RetrieveAndGenerate. Scope resources to specific Knowledge Base ARNs. |
High | ● Still open Failed → Failed |
123456789012 |
Global |
FS-26 |
No OpenSearch Serverless Network Policies
|
High | ● Still open Failed → Failed |
123456789012 |
Global |
FS-27 |
No Automated Reasoning Policies Found
Details and remediationDetails
No Bedrock Automated Reasoning policies have been created. ARC (GA August 2025) uses formal verification to guarantee that GenAI outputs comply with authored business rules — e.g., loan criteria, regulatory thresholds, policy constraints. Without ARC policies, factual accuracy of outputs is not formally verified, only heuristically filtered by contextual grounding thresholds. Resolution
1. In the Amazon Bedrock console → Guardrails → Automated Reasoning, create a policy document encoding your business rules (e.g., eligibility criteria, rate limits, regulatory thresholds). 2. Associate the ARC policy with your guardrail (automatedReasoningPolicy.policies field in CreateGuardrail/UpdateGuardrail). 3. Set confidenceThreshold on the policy to control strictness. 4. ARC requires cross-Region inference — ensure your guardrail has a guardrailProfileArn configured (crossRegionDetails in GetGuardrail response). 5. Reference: AWS Announcement — Automated Reasoning checks GA (August 2025). |
Medium | ● Still open Failed → Failed |
123456789012 |
Global |
FS-39 |
No SageMaker Clarify Bias Monitoring
Details and remediationDetails
No SageMaker Clarify model bias monitoring schedules found. Models making financial decisions (credit, insurance) may exhibit discriminatory bias without detection. Resolution
1. Configure SageMaker Clarify bias detection for all models making credit, insurance, or employment decisions. 2. Define protected attributes (age, gender, race proxies). 3. Set bias metric thresholds and alert on violations. 4. Document bias testing results for regulatory examination. |
High | ● Still open Failed → Failed |
123456789012 |
Global |
FS-41 |
No SageMaker Clarify Explainability Monitoring
Details and remediationDetails
No SageMaker Clarify explainability monitoring found. Models making adverse financial decisions may not provide required explanations (ECOA adverse action notices). Resolution
1. Configure SageMaker Clarify explainability for credit/lending models. 2. Generate SHAP values for feature importance. 3. Map top features to human-readable adverse action reason codes. 4. Store explanations for regulatory examination. |
High | ● Still open Failed → Failed |
123456789012 |
Global |
FS-44 |
Amazon Macie Enabled but Automated Discovery Disabled
Details and remediationDetails
Amazon Macie is enabled, but automated sensitive data discovery is DISABLED. Enabling Macie alone does not scan any data, so S3 buckets containing training data and KB data sources are not being evaluated for PII. Resolution
1. Enable automated sensitive data discovery in Macie. 2. Confirm the classification scope includes training data and KB source buckets. 3. Alternatively, create targeted classification jobs for those buckets. |
High | ● Still open Failed → Failed |
123456789012 |
Global |
FS-48 |
No Active Knowledge Bases for RAG
Details and remediationDetails
No active Bedrock Knowledge Bases found. GenAI responses are not grounded in authoritative data sources, increasing hallucination risk. Resolution
1. Create Bedrock Knowledge Bases with authoritative financial data. 2. Use RetrieveAndGenerate API to ground responses. 3. Configure data sources with current regulatory and product information. |
Medium | ● Still open Failed → Failed |
123456789012 |
Global |
FS-50 |
No Guardrails With Relevance Grounding Filters
Details and remediationDetails
No guardrails have RELEVANCE contextual grounding filters. Without relevance filters, responses that are off-topic or unrelated to the user query will not be blocked, increasing hallucination risk in RAG-based applications. Resolution
Enable the RELEVANCE contextual grounding filter in Bedrock Guardrails with a threshold of ≥0.7 to block responses that are not relevant to the user query. Also enable the GROUNDING filter (≥0.7) to block responses not supported by the retrieved source context. |
Medium | ● Still open Failed → Failed |
123456789012 |
Global |
FS-55 |
No Output Validation Functions Found
Details and remediationDetails
No Lambda functions with output validation/sanitization naming found. GenAI outputs may be passed directly to downstream systems without validation. Resolution
1. Implement output validation Lambda functions in GenAI pipelines. 2. Validate output schema, length, and content before downstream use. 3. Sanitize outputs before rendering in web UIs (XSS prevention). 4. Encode outputs appropriately for the target context (HTML, SQL, JSON). |
Medium | ● Still open Failed → Failed |
123456789012 |
Global |
FS-68 |
API Gateway Request Body Size Limits Not Enforced
Details and remediationDetails
Found 4 REST API(s) and 0 regional WAF Web ACL(s), but none enforce a maximum request-body size. Note: an API Gateway request validator does NOT cap body size (it validates the schema and required params; the REST limit is a fixed 10 MB), and a WAF body SizeConstraint only inspects the first ~16 KB of the body by default. Oversized prompts can exhaust Bedrock token quotas and inflate costs. Resolution
1. Add a maxLength (or maxItems/maxProperties) bound to the request-body JSON-Schema model used by your request validator, so oversized prompts are rejected with a 400. 2. Add a WAF SizeConstraintStatement on the request Body sized within WAF's body-inspection window (default 16 KB; raise via the web ACL AssociationConfig, or set OversizeHandling=MATCH to block bodies beyond the window), and associate the ACL with the API stage. 3. Set the max_tokens parameter in Bedrock API calls to cap output length. 4. Implement client-side token counting before submitting requests. |
Medium | ● Still open Failed → Failed |
123456789012 |
Global |
OW-02 |
OWASP LLM02: Macie Sensitive-Data Discovery
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-44: Amazon Macie is enabled, but automated sensitive data discovery is DISABLED. Enabling Macie alone does not scan any data, so S3 buckets containing training data and KB data sources are not being evaluated for PII. Resolution
Enable Amazon Macie with automated discovery on S3 buckets that hold training or knowledge-base data. |
High | ● Still open Failed → Failed |
123456789012 |
Global |
OW-03 |
OWASP LLM03: Adversarial Evaluation Coverage
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check FS-15: No Bedrock Model Evaluation jobs found. Models have not been evaluated for adversarial robustness. Model-risk management (SR 11-7) expects documented model validation/evaluation. Resolution
Run Bedrock evaluation jobs that include adversarial and safety datasets before promoting a model to production. |
Medium | ● Still open Failed → Failed |
123456789012 |
Global |
OW-03 |
OWASP LLM03: SCP-Enforced Model Allowlist
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check FS-12: No Service Control Policies reference Bedrock. Without SCPs, any account in the organization can access any Bedrock model, including unapproved third-party models. Resolution
Attach an Organizations SCP that denies Bedrock inference outside allowlisted model and inference-profile ARNs using Resource or NotResource scoping. |
High | ● Still open Failed → Failed |
123456789012 |
Global |
OW-05 |
OWASP LLM05: Output-Validation Lambda
Details and remediationDetails
OWASP category: LLM05:2025 Improper Output Handling. Source check FS-55: No Lambda functions with output validation/sanitization naming found. GenAI outputs may be passed directly to downstream systems without validation. Resolution
Deploy an output-validation / sanitisation Lambda between the model response and any downstream consumer to filter injection payloads in generated output. |
Medium | ● Still open Failed → Failed |
123456789012 |
Global |
OW-06 |
OWASP LLM06: Agent Tool Concurrency Limits
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check FS-09: Agent-related Lambda functions without reserved concurrency: aiml-security-aiml-sec-123456789012-AgentCoreAssessment, aiml-security-aiml-sec-123456789012-CleanupBucket, aiml-security-aiml-sec-123456789012-ResolveRegions, aiml-security-aiml-sec-123456789012-SagemakerAssessment, aiml-security-aiml-sec-123456789012-GenerateReport, aiml-security-aiml-sec-123456789012-AgentRegistryAssessment, aiml-security-aiml-sec-123456789012-RAIGRCAssessment, aiml-security-aiml-sec-123456789012-BedrockAssessment, AIML-Standalone-CodeBuildStartBuildLambda-eAzlGvTTrtQW, aiml-security-aiml-sec-123456789012-IAMPermissionCaching. Unlimited concurrency allows runaway agent loops to exhaust account limits. Resolution
Set reserved concurrency on agent action-group Lambdas so a runaway agent cannot exhaust downstream capacity. |
Medium | ● Still open Failed → Failed |
123456789012 |
Global |
OW-08 |
OWASP LLM08: KB IAM Scope
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-22: 787 role(s) with wildcard KB permissions: - Role 'Admin' allows '*' - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-sl8sQor1MSud' allows 'bedrock:ListGuardrails' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-sl8sQor1MSud' allows 'bedrock:GetGuardrail' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-sl8sQor1MSud' allows 'bedrock:GetModelInvocationLoggingConfiguration' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-sl8sQor1MSud' allows 'bedrock:ListPrompts' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-sl8sQor1MSud' allows 'bedrock:GetPrompt' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-sl8sQor1MSud' allows 'bedrock:ListAgents' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-sl8sQor1MSud' allows 'bedrock:GetAgent' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-sl8sQor1MSud' allows 'bedrock:ListCustomModels' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-sl8sQor1MSud' allows 'bedrock:GetCustomModel' on Resource '*' (no ARN scoping to specific Knowledge Bases) Resolution
Scope Knowledge Base IAM roles to specific KB ARNs; remove wildcard bedrock:* on KB actions. |
High | ● Still open Failed → Failed |
123456789012 |
Global |
OW-08 |
OWASP LLM08: OpenSearch Serverless Network Policy
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-26: No OpenSearch Serverless network policies found. Vector store collections may be publicly accessible. Resolution
Set AllowFromPublic=false on the OpenSearch Serverless network policy and restrict access to bedrock.amazonaws.com or a specific VPC endpoint. |
High | ● Still open Failed → Failed |
123456789012 |
Global |
OW-09 |
OWASP LLM09: Active Knowledge Base Present
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check FS-48: No active Bedrock Knowledge Bases found. GenAI responses are not grounded in authoritative data sources, increasing hallucination risk. Resolution
Deploy at least one ACTIVE Knowledge Base when Bedrock models are used, so grounded retrieval is available. |
Medium | ● Still open Failed → Failed |
123456789012 |
Global |
OW-10 |
OWASP LLM10: API Gateway Request Body Size Limits
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-68: Found 4 REST API(s) and 0 regional WAF Web ACL(s), but none enforce a maximum request-body size. Note: an API Gateway request validator does NOT cap body size (it validates the schema and required params; the REST limit is a fixed 10 MB), and a WAF body SizeConstraint only inspects the first ~16 KB of the body by default. Oversized prompts can exhaust Bedrock token quotas and inflate costs. Resolution
Configure API Gateway request validation or an equivalent ingress control so GenAI endpoints reject oversized request bodies before they can drive excessive model consumption. |
Medium | ● Still open Failed → Failed |
123456789012 |
Global |
OW-10 |
OWASP LLM10: AWS Budgets with Bedrock Filters
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-06: No AWS Budgets found scoped to Bedrock or SageMaker. Unbounded GenAI spend can go undetected until the monthly bill. Resolution
Configure AWS Budgets with FilterExpression / CostFilters targeting Bedrock or SageMaker spend, with an alerting SNS action. |
Medium | ● Still open Failed → Failed |
123456789012 |
Global |
OW-10 |
OWASP LLM10: Cost Anomaly Detection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-04: No AWS Cost Anomaly Detection monitors found. Unexpected spikes in Bedrock/SageMaker usage (e.g., from prompt injection loops) will go undetected. Resolution
Configure AWS Cost Anomaly Detection monitors that include Bedrock and SageMaker. |
Medium | ● Still open Failed → Failed |
123456789012 |
Global |
OW-10 |
OWASP LLM10: Token / Throttle Alarms
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-05: No CloudWatch alarms found for Bedrock metrics. Token exhaustion and throttling events will not trigger operational alerts. Resolution
Create CloudWatch alarms on the Bedrock namespace for InvocationThrottles and token counters. |
Medium | ● Still open Failed → Failed |
123456789012 |
Global |
OW-10 |
OWASP LLM10: WAF Rate-Based & Shield Protection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-01: AWS Shield Advanced is not subscribed. GenAI API endpoints are vulnerable to volumetric DDoS attacks that can exhaust token quotas and inflate costs. Resolution
Add a WAF RateBasedStatement plus a SizeConstraintStatement on the GenAI ingress and subscribe to AWS Shield Advanced. |
Low | ● Still open Failed → Failed |
123456789012 |
Global |
OW-10 |
OWASP LLM10: WAF Rate-Based & Shield Protection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-01: No AWS WAF regional Web ACLs found. Without WAF, GenAI endpoints lack rate-based rules to block abusive callers. Resolution
Add a WAF RateBasedStatement plus a SizeConstraintStatement on the GenAI ingress and subscribe to AWS Shield Advanced. |
Medium | ● Still open Failed → Failed |
123456789012 |
us-east-1 |
OW-01 |
OWASP LLM01: GuardDuty AI Protection
|
High | ● Still open Failed → Failed |
123456789012 |
us-east-1 |
OW-02 |
OWASP LLM02: Bedrock Data Retention Boundary
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check BR-37: Bedrock account data retention is inherit; this does not establish an explicit account-level zero-data-retention setting. Resolution
Configure Bedrock account data retention as none and disable provider data sharing when prompts or responses may contain sensitive information. |
High | ● Still open Failed → Failed |
123456789012 |
us-east-1 |
OW-10 |
OWASP LLM10: GuardDuty AI Protection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check SM-26: GuardDuty is enabled, but the AI Protection detector feature is not enabled. Resolution
Enable the GuardDuty AI_PROTECTION detector feature to detect supported anomalous model invocation and cost-harvesting activity. |
High | ● Still open Failed → Failed |
123456789012 |
us-east-2 |
OW-02 |
OWASP LLM02: AgentCore Token Vault CMK Encryption
Details and remediation |
High | ● Still open Failed → Failed |
123456789012 |
us-east-2 |
OW-02 |
OWASP LLM02: Bedrock Data Retention Boundary
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check BR-37: Bedrock account data retention is inherit; this does not establish an explicit account-level zero-data-retention setting. Resolution
Configure Bedrock account data retention as none and disable provider data sharing when prompts or responses may contain sensitive information. |
High | ● Still open Failed → Failed |
123456789012 |
us-west-2 |
OW-01 |
OWASP LLM01: GuardDuty AI Protection
|
High | ● Still open Failed → Failed |
123456789012 |
us-west-2 |
OW-02 |
OWASP LLM02: AgentCore Token Vault CMK Encryption
Details and remediation |
High | ● Still open Failed → Failed |
123456789012 |
us-west-2 |
OW-10 |
OWASP LLM10: GuardDuty AI Protection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check SM-26: GuardDuty is enabled, but the AI Protection detector feature is not enabled. Resolution
Enable the GuardDuty AI_PROTECTION detector feature to detect supported anomalous model invocation and cost-harvesting activity. |
High | ● Still open Failed → Failed |
123456789012 |
Global |
AC-09 |
AgentCore Service-Linked Role Check
Details and remediationDetails (previous run) Service-linked role 'AWSServiceRoleForBedrockAgentCoreNetwork' does not exist. VPC configuration for AgentCore Runtimes will fail without this role. Details (current run)
Service-linked role 'AWSServiceRoleForBedrockAgentCoreNetwork' exists. Resolution
No action required |
Medium | ✓ Resolved Failed → Passed |
123456789012 |
us-east-1 |
AC-14 |
AgentCore Identity Token Vault CMK Encryption
|
High | ✓ Resolved Failed → Passed |
123456789012 |
us-east-1 |
AG-28 |
Agentic AI Identity Token Vault Protection
Details and remediationDetails (previous run) Agentic AI security domain: Agent Identity & Access. Agent credentials stored in the Identity token vault should use customer-controlled encryption where enhanced key control is required. Source check AC-14: AgentCore token vault 'default' uses a service-managed or AWS-owned key. Details (current run)
Agentic AI security domain: Agent Identity & Access. Agent credentials stored in the Identity token vault should use customer-controlled encryption where enhanced key control is required. Source check AC-14: AgentCore token vault 'default' uses a customer-managed KMS key. Resolution
Configure the AgentCore Identity token vault with a customer-managed KMS key. |
High | ✓ Resolved Failed → Passed |
123456789012 |
us-east-1 |
OW-02 |
OWASP LLM02: AgentCore Token Vault CMK Encryption
Details and remediationDetails (previous run) OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check AC-14: AgentCore token vault 'default' uses a service-managed or AWS-owned key. Details (current run)
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check AC-14: AgentCore token vault 'default' uses a customer-managed KMS key. Resolution
Configure the AgentCore Identity token vault with a customer-managed KMS key to protect stored credentials and tokens. |
High | ✓ Resolved Failed → Passed |
123456789012 |
us-west-2 |
BR-37 |
Bedrock Account Data Retention
|
High | ○ No longer reported Failed → Not present |
123456789012 |
us-west-2 |
OW-02 |
OWASP LLM02: Bedrock Data Retention Boundary
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check BR-37: Bedrock account data retention is inherit; this does not establish an explicit account-level zero-data-retention setting. Resolution
Configure Bedrock account data retention as none and disable provider data sharing when prompts or responses may contain sensitive information. |
High | ○ No longer reported Failed → Not present |
123456789012 |
us-east-2 |
SM-26 |
GuardDuty AI Protection
|
High | ? No longer assessed Failed → N/A |
123456789012 |
us-east-2 |
OW-01 |
OWASP LLM01: GuardDuty AI Protection
Details and remediationDetails (previous run) OWASP category: LLM01:2025 Prompt Injection. Source check SM-26: GuardDuty is enabled, but the AI Protection detector feature is not enabled. Details (current run)
OWASP category: LLM01:2025 Prompt Injection. Source check SM-26: GuardDuty AI Protection status could not be read: AccessDeniedException. Resolution
Enable the GuardDuty AI_PROTECTION detector feature to detect supported direct prompt-injection activity. |
High | ? No longer assessed Failed → N/A |
123456789012 |
us-east-2 |
OW-10 |
OWASP LLM10: GuardDuty AI Protection
Details and remediationDetails (previous run) OWASP category: LLM10:2025 Unbounded Consumption. Source check SM-26: GuardDuty is enabled, but the AI Protection detector feature is not enabled. Details (current run)
OWASP category: LLM10:2025 Unbounded Consumption. Source check SM-26: GuardDuty AI Protection status could not be read: AccessDeniedException. Resolution
Enable the GuardDuty AI_PROTECTION detector feature to detect supported anomalous model invocation and cost-harvesting activity. |
High | ? No longer assessed Failed → N/A |
123456789012 |
Global |
BR-01 |
AmazonBedrockFullAccess role check
|
High | – Not failing Passed → Passed |
123456789012 |
us-east-1 |
BR-02 |
Amazon Bedrock private connectivity check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-04 |
Bedrock Model Invocation Logging Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-05 |
Bedrock Guardrails Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-06 |
Bedrock CloudTrail Logging Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-07 |
Bedrock Prompt Management Check
Details and remediationDetails
Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-08 |
Bedrock Agent IAM Roles Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-09 |
Bedrock Knowledge Base Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-10 |
Bedrock Guardrail IAM Enforcement Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-11 |
Bedrock Custom Model Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-12 |
Bedrock Invocation Log Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-13 |
Bedrock Flows Guardrails Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-16 |
Guardrail Tier Validation Check
|
Medium | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-17 |
Custom Model Customer-Managed KMS Encryption Check
|
High | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-18 |
Model Evaluation Implementation Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-19 |
Prompt Flow Validation Check
|
Medium | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Check
|
High | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-21 |
Agent Action Group IAM Least Privilege Check
|
High | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-22 |
Model Invocation Throttling Limits Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-23 |
Guardrail Content Filter Coverage Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-24 |
Automated Reasoning Policy Implementation Check
|
Medium | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-25 |
RAG Evaluation Jobs Check
|
Low | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-26 |
Guardrail Sensitive Information Filter Check
|
High | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-27 |
Guardrail Contextual Grounding Check
|
Medium | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-28 |
Agent Guardrail Association Check
|
High | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-29 |
Agent Idle Session TTL Check
|
Low | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-30 |
Imported Model Customer-Managed KMS Encryption Check
|
High | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-31 |
Batch Inference Output Encryption Check
|
Medium | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-32 |
Bedrock CloudWatch Alarm Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-33 |
Amazon Inspector Lambda Code Scanning Check
|
Medium | – Not failing Passed → Passed |
123456789012 |
us-east-1 |
BR-34 |
Guardrail Prompt Attack Filter
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-35 |
Guardrail Image Content Filter Coverage
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-36 |
Application Inference Profile Governance
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-38 |
Automated Reasoning Policy CMK Encryption
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-39 |
Marketplace Model Endpoint VPC Configuration
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
BR-40 |
Marketplace Model Endpoint CMK Encryption
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-02 |
Amazon Bedrock private connectivity check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-04 |
Bedrock Model Invocation Logging Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-05 |
Bedrock Guardrails Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-06 |
Bedrock CloudTrail Logging Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-07 |
Bedrock Prompt Management Check
Details and remediationDetails
Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-08 |
Bedrock Agent IAM Roles Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-09 |
Bedrock Knowledge Base Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-10 |
Bedrock Guardrail IAM Enforcement Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-11 |
Bedrock Custom Model Encryption Check
|
Low | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-12 |
Bedrock Invocation Log Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-13 |
Bedrock Flows Guardrails Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-16 |
Guardrail Tier Validation Check
|
Medium | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-17 |
Custom Model Customer-Managed KMS Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-18 |
Model Evaluation Implementation Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-19 |
Prompt Flow Validation Check
|
Medium | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Check
|
High | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-21 |
Agent Action Group IAM Least Privilege Check
|
High | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-22 |
Model Invocation Throttling Limits Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-23 |
Guardrail Content Filter Coverage Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-24 |
Automated Reasoning Policy Implementation Check
|
Medium | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-25 |
RAG Evaluation Jobs Check
|
Low | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-26 |
Guardrail Sensitive Information Filter Check
|
High | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-27 |
Guardrail Contextual Grounding Check
|
Medium | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-28 |
Agent Guardrail Association Check
|
High | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-29 |
Agent Idle Session TTL Check
|
Low | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-30 |
Imported Model Customer-Managed KMS Encryption Check
|
High | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-31 |
Batch Inference Output Encryption Check
|
Medium | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-32 |
Bedrock CloudWatch Alarm Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-33 |
Amazon Inspector Lambda Code Scanning Check
Details and remediationDetails
No Lambda functions with Bedrock indicators were found in us-east-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
No action required. If Bedrock-calling Lambda functions exist, ensure their function name, ARN, description, handler, role, or environment variables contain a Bedrock identifier that the assessment can detect, or evaluate Inspector coverage manually. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-34 |
Guardrail Prompt Attack Filter
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-35 |
Guardrail Image Content Filter Coverage
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-36 |
Application Inference Profile Governance
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-38 |
Automated Reasoning Policy CMK Encryption
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-39 |
Marketplace Model Endpoint VPC Configuration
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
BR-40 |
Marketplace Model Endpoint CMK Encryption
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-02 |
Amazon Bedrock private connectivity check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-04 |
Bedrock Model Invocation Logging Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-05 |
Bedrock Guardrails Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-06 |
Bedrock CloudTrail Logging Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-07 |
Bedrock Prompt Management Check
Details and remediationDetails
Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-08 |
Bedrock Agent IAM Roles Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-09 |
Bedrock Knowledge Base Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-10 |
Bedrock Guardrail IAM Enforcement Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-11 |
Bedrock Custom Model Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-12 |
Bedrock Invocation Log Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-13 |
Bedrock Flows Guardrails Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-16 |
Guardrail Tier Validation Check
|
Medium | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-17 |
Custom Model Customer-Managed KMS Encryption Check
|
High | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-18 |
Model Evaluation Implementation Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-19 |
Prompt Flow Validation Check
|
Medium | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Check
|
High | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-21 |
Agent Action Group IAM Least Privilege Check
|
High | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-22 |
Model Invocation Throttling Limits Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-23 |
Guardrail Content Filter Coverage Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-24 |
Automated Reasoning Policy Implementation Check
|
Medium | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-25 |
RAG Evaluation Jobs Check
|
Low | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-26 |
Guardrail Sensitive Information Filter Check
|
High | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-27 |
Guardrail Contextual Grounding Check
|
Medium | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-28 |
Agent Guardrail Association Check
|
High | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-29 |
Agent Idle Session TTL Check
|
Low | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-30 |
Imported Model Customer-Managed KMS Encryption Check
|
High | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-31 |
Batch Inference Output Encryption Check
|
Medium | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-32 |
Bedrock CloudWatch Alarm Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-33 |
Amazon Inspector Lambda Code Scanning Check
Details and remediationDetails
No Lambda functions with Bedrock indicators were found in us-west-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
No action required. If Bedrock-calling Lambda functions exist, ensure their function name, ARN, description, handler, role, or environment variables contain a Bedrock identifier that the assessment can detect, or evaluate Inspector coverage manually. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-34 |
Guardrail Prompt Attack Filter
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-35 |
Guardrail Image Content Filter Coverage
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-36 |
Application Inference Profile Governance
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-38 |
Automated Reasoning Policy CMK Encryption
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-39 |
Marketplace Model Endpoint VPC Configuration
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
BR-40 |
Marketplace Model Endpoint CMK Encryption
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
SM-02 |
SageMaker IAM Permissions Check
|
High | – Not failing Passed → Passed |
123456789012 |
us-east-1 |
SM-01 |
SageMaker Internet Access Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
SM-02 |
SageMaker SSO Configuration Check
|
Medium | – Not failing Passed → Passed |
123456789012 |
us-east-1 |
SM-03 |
Data Protection Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
SM-05 |
SageMaker Feature Store Issue
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
SM-05 |
SageMaker Model Registry Issue
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
SM-05 |
SageMaker Pipelines Issue
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
SM-06 |
SageMaker Clarify No Clarify Usage
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
SM-07 |
SageMaker Model Monitor No Model Monitoring
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
SM-08 |
Model Registry Registry Not Used
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
SM-09 |
SageMaker Notebook Root Access Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
SM-10 |
SageMaker Notebook VPC Deployment Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
SM-11 |
SageMaker Model Network Isolation Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
SM-12 |
SageMaker Endpoint Instance Count Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
SM-13 |
SageMaker Monitoring Network Isolation Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
SM-14 |
SageMaker Model Repository Access Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
SM-15 |
SageMaker Feature Store Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
SM-16 |
SageMaker Data Quality Job Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
SM-17 |
SageMaker Processing Job Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
SM-18 |
SageMaker Transform Job Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
SM-19 |
SageMaker Hyperparameter Tuning Job Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
SM-20 |
SageMaker Compilation Job Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
SM-21 |
SageMaker AutoML Job Network Isolation Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
SM-22 |
Model Approval Workflow Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
SM-23 |
Model Drift Detection Check
|
Medium | – Not failing Passed → Passed |
123456789012 |
us-east-1 |
SM-24 |
A/B Testing and Shadow Deployment Check
|
Low | – Not failing Passed → Passed |
123456789012 |
us-east-1 |
SM-25 |
ML Lineage Tracking - Experiments Not Used
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
SM-27 |
HyperPod EBS CMK Encryption
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
SM-28 |
HyperPod VPC Configuration
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
SM-30 |
Model Package Group Resource Policy Exposure
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
SM-01 |
SageMaker Internet Access Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
SM-02 |
SageMaker SSO Configuration Check
|
Medium | – Not failing Passed → Passed |
123456789012 |
us-east-2 |
SM-03 |
Data Protection Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
SM-04 |
GuardDuty Enabled
|
Medium | – Not failing Passed → Passed |
123456789012 |
us-east-2 |
SM-05 |
SageMaker Feature Store Issue
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
SM-05 |
SageMaker Model Registry Issue
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
SM-05 |
SageMaker Pipelines Issue
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
SM-06 |
SageMaker Clarify No Clarify Usage
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
SM-07 |
SageMaker Model Monitor No Model Monitoring
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
SM-08 |
Model Registry Registry Not Used
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
SM-09 |
SageMaker Notebook Root Access Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
SM-10 |
SageMaker Notebook VPC Deployment Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
SM-11 |
SageMaker Model Network Isolation Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
SM-12 |
SageMaker Endpoint Instance Count Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
SM-13 |
SageMaker Monitoring Network Isolation Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
SM-14 |
SageMaker Model Repository Access Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
SM-15 |
SageMaker Feature Store Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
SM-16 |
SageMaker Data Quality Job Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
SM-17 |
SageMaker Processing Job Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
SM-18 |
SageMaker Transform Job Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
SM-19 |
SageMaker Hyperparameter Tuning Job Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
SM-20 |
SageMaker Compilation Job Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
SM-21 |
SageMaker AutoML Job Network Isolation Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
SM-22 |
Model Approval Workflow Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
SM-23 |
Model Drift Detection Check
|
Medium | – Not failing Passed → Passed |
123456789012 |
us-east-2 |
SM-24 |
A/B Testing and Shadow Deployment Check
|
Low | – Not failing Passed → Passed |
123456789012 |
us-east-2 |
SM-25 |
ML Lineage Tracking - Experiments Not Used
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
SM-27 |
HyperPod EBS CMK Encryption
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
SM-28 |
HyperPod VPC Configuration
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
SM-30 |
Model Package Group Resource Policy Exposure
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
SM-01 |
SageMaker Internet Access Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
SM-02 |
SageMaker SSO Configuration Check
|
Medium | – Not failing Passed → Passed |
123456789012 |
us-west-2 |
SM-03 |
Data Protection Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
SM-04 |
GuardDuty Enabled
|
Medium | – Not failing Passed → Passed |
123456789012 |
us-west-2 |
SM-05 |
SageMaker Feature Store Issue
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
SM-05 |
SageMaker Model Registry Issue
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
SM-05 |
SageMaker Pipelines Issue
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
SM-06 |
SageMaker Clarify No Clarify Usage
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
SM-07 |
SageMaker Model Monitor No Model Monitoring
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
SM-08 |
Model Registry Registry Not Used
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
SM-09 |
SageMaker Notebook Root Access Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
SM-10 |
SageMaker Notebook VPC Deployment Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
SM-11 |
SageMaker Model Network Isolation Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
SM-12 |
SageMaker Endpoint Instance Count Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
SM-13 |
SageMaker Monitoring Network Isolation Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
SM-14 |
SageMaker Model Repository Access Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
SM-15 |
SageMaker Feature Store Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
SM-16 |
SageMaker Data Quality Job Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
SM-17 |
SageMaker Processing Job Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
SM-18 |
SageMaker Transform Job Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
SM-19 |
SageMaker Hyperparameter Tuning Job Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
SM-20 |
SageMaker Compilation Job Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
SM-21 |
SageMaker AutoML Job Network Isolation Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
SM-22 |
Model Approval Workflow Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
SM-23 |
Model Drift Detection Check
|
Medium | – Not failing Passed → Passed |
123456789012 |
us-west-2 |
SM-24 |
A/B Testing and Shadow Deployment Check
|
Low | – Not failing Passed → Passed |
123456789012 |
us-west-2 |
SM-25 |
ML Lineage Tracking - Experiments Not Used
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
SM-27 |
HyperPod EBS CMK Encryption
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
SM-28 |
HyperPod VPC Configuration
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
SM-30 |
Model Package Group Resource Policy Exposure
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
AC-02 |
AgentCore IAM Full Access Check
|
High | – Not failing Passed → Passed |
123456789012 |
Global |
AC-03 |
AgentCore Unused Permissions
Details and remediationDetails
The following principals have AgentCore permissions but have never accessed the service: role 'AIMLSecurityMemberRole', role 'AwsSecurityAudit', role 'AWSServiceRoleForSupport', role 'cdk-hnb659fds-lookup-role-123456789012-us-east-1', role 'cdk-hnb659fds-lookup-role-123456789012-us-east-2', role 'CloudSecAuditRole', role 'CloudSeerTrustedServiceRole', role 'EpoxyAccessRole', role 'IibsAdminAccess-DO-NOT-DELETE', role 'InternalAuditInternal', role 'Nova-DO-NOT-DELETE', role 'ScoutSuiteRole' Resolution
Review and remove unused AgentCore permissions following least privilege principle |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AC-01 |
AgentCore VPC Configuration Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AC-04 |
AgentCore Observability Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AC-05 |
AgentCore Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AC-06 |
AgentCore Browser Session Recording
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AC-07 |
AgentCore Memory Configuration Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AC-08 |
AgentCore VPC Endpoints Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AC-10 |
AgentCore Resource-Based Policies Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AC-11 |
AgentCore Policy Engine Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AC-12 |
AgentCore Gateway Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AC-13 |
AgentCore Gateway Configuration Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AC-15 |
AgentCore Code Interpreter Network Isolation
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AC-16 |
AgentCore Custom Browser Network Isolation
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AC-01 |
AgentCore VPC Configuration Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AC-04 |
AgentCore Observability Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AC-05 |
AgentCore Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AC-06 |
AgentCore Browser Session Recording
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AC-07 |
AgentCore Memory Configuration Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AC-08 |
AgentCore VPC Endpoints Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AC-10 |
AgentCore Resource-Based Policies Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AC-11 |
AgentCore Policy Engine Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AC-12 |
AgentCore Gateway Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AC-13 |
AgentCore Gateway Configuration Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AC-15 |
AgentCore Code Interpreter Network Isolation
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AC-16 |
AgentCore Custom Browser Network Isolation
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AC-01 |
AgentCore VPC Configuration Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AC-04 |
AgentCore Observability Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AC-05 |
AgentCore Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AC-06 |
AgentCore Browser Session Recording
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AC-07 |
AgentCore Memory Configuration Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AC-08 |
AgentCore VPC Endpoints Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AC-10 |
AgentCore Resource-Based Policies Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AC-11 |
AgentCore Policy Engine Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AC-12 |
AgentCore Gateway Encryption Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AC-13 |
AgentCore Gateway Configuration Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AC-15 |
AgentCore Code Interpreter Network Isolation
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AC-16 |
AgentCore Custom Browser Network Isolation
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AR-03 |
AWS Agent Registry Publication Approval Governance
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AR-04 |
AWS Agent Registry Discovery Authorization
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AR-05 |
AWS Agent Registry Customer-Managed KMS Encryption
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AR-06 |
AWS Agent Registry Organization Auto-Detection
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AR-07 |
AWS Agent Registry Record Lifecycle Governance
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AR-08 |
AWS Agent Registry Record Provenance
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AR-03 |
AWS Agent Registry Publication Approval Governance Incomplete
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AR-04 |
AWS Agent Registry Discovery Authorization Incomplete
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AR-05 |
AWS Agent Registry Customer-Managed KMS Encryption Incomplete
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AR-06 |
AWS Agent Registry Organization Auto-Detection Incomplete
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AR-07 |
AWS Agent Registry Record Lifecycle Governance Incomplete
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AR-08 |
AWS Agent Registry Record Provenance Incomplete
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AR-03 |
AWS Agent Registry Publication Approval Governance
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AR-04 |
AWS Agent Registry Discovery Authorization
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AR-05 |
AWS Agent Registry Customer-Managed KMS Encryption
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AR-06 |
AWS Agent Registry Organization Auto-Detection
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AR-07 |
AWS Agent Registry Record Lifecycle Governance
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AR-08 |
AWS Agent Registry Record Provenance
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
AG-16 |
Agentic AI AgentCore Least Privilege
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Over-permissive AgentCore principals can let agents or operators bypass intended autonomy and tool boundaries. Source check AC-02: No roles with overly permissive AgentCore access found Resolution
Replace full-access AgentCore permissions with least-privilege IAM policies scoped to required resources and actions. |
High | – Not failing Passed → Passed |
123456789012 |
Global |
AG-17 |
Agentic AI Stale AgentCore Access
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Unused AgentCore permissions increase the blast radius of compromised principals. Source check AC-03: The following principals have AgentCore permissions but have never accessed the service: role 'AIMLSecurityMemberRole', role 'AwsSecurityAudit', role 'AWSServiceRoleForSupport', role 'cdk-hnb659fds-lookup-role-123456789012-us-east-1', role 'cdk-hnb659fds-lookup-role-123456789012-us-east-2', role 'CloudSecAuditRole', role 'CloudSeerTrustedServiceRole', role 'EpoxyAccessRole', role 'IibsAdminAccess-DO-NOT-DELETE', role 'InternalAuditInternal', role 'Nova-DO-NOT-DELETE', role 'ScoutSuiteRole' Resolution
Remove or restrict stale AgentCore permissions for principals that no longer need access. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-01 |
Agentic AI Agent Guardrail Association
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region Resolution
Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-02 |
Agentic AI Harmful Content Guardrail Coverage
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-03 |
Agentic AI Sensitive Information Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: No Bedrock guardrails configured in this region Resolution
Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-04 |
Agentic AI Automated Reasoning Guardrails
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: No Bedrock guardrails configured in this region Resolution
Configure automated reasoning policies on guardrails where formal response validation is required. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-05 |
Agentic AI Grounding Controls
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: No Bedrock guardrails configured in this region Resolution
Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-06 |
Agentic AI Tool Execution Least Privilege
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region Resolution
Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-07 |
Agentic AI Model Invocation Logging
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-08 |
Agentic AI API Audit Trail
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage Resolution
Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-10 |
Agentic AI Adversarial Evaluation Coverage
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs Resolution
Configure model or application evaluations that include adversarial, safety, and security-relevant test cases. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-11 |
Agentic AI Prompt Flow Validation
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region Resolution
Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-12 |
Agentic AI Invocation Abuse Controls
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas Resolution
Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-13 |
Agentic AI Session Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region Resolution
Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-14 |
Agentic AI Operational Abuse Alarms
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms Resolution
Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-19 |
Agentic AI Memory Data Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found Resolution
Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-20 |
Agentic AI Private AgentCore Connectivity
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found Resolution
Create required VPC endpoints for AgentCore services and validate endpoint availability. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-21 |
Agentic AI Resource Policy Boundary
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies Resolution
Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-22 |
Agentic AI Policy Engine Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found Resolution
Configure policy engines with customer-managed KMS keys where enhanced key control is required. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-23 |
Agentic AI Gateway Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found Resolution
Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-24 |
Agentic AI Gateway Inbound Authorization
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-25 |
Agentic AI Gateway Tool Policy Enforcement
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-26 |
Agentic AI Gateway Error Detail Exposure
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-27 |
Agentic AI Gateway WAF Protection
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-29 |
Agentic AI Code Interpreter Isolation
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent-executed code should run inside an explicit VPC boundary with controlled network paths. Source check AC-15: No custom AgentCore Code Interpreters found Resolution
Configure custom AgentCore Code Interpreters in VPC mode with approved subnets and security groups. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-30 |
Agentic AI Prompt Attack Protection
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agents should prevent prompt attacks before untrusted input can redirect planning or tool use. Source check BR-34: No Bedrock guardrails configured in this region Resolution
Enable a preventive PROMPT_ATTACK input filter on each guardrail and use Standard tier where prompt-leakage protection is required. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-31 |
Agentic AI Browser Tool Isolation
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Browser tools can reach external systems and should use explicit private network boundaries. Source check AC-16: No custom AgentCore browsers found Resolution
Configure custom AgentCore browsers in VPC mode with approved subnets and security groups. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-33 |
Agentic AI Registry Publication Approval Governance
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry approval workflows control which agents, tools, and skills become discoverable to consumers. Source check AR-03: No AWS Agent Registry registries found. Resolution
Require manual review for registry publication where organizational policy does not permit automatic approval. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-34 |
Agentic AI Registry Discovery Authorization
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry discovery authorization requires review against intended callers and effective access boundaries. Source check AR-04: No AWS Agent Registry registries found. Resolution
Review effective IAM access or compare custom JWT audiences, clients, scopes, and claims with approved registry consumers. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-35 |
Agentic AI Registry Metadata Encryption
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Registry records can contain agent, tool, endpoint, and ownership metadata that benefits from customer-controlled encryption. Source check AR-05: No AWS Agent Registry registries found. Resolution
Create the registry with a customer-managed KMS key when organizational policy requires customer-controlled encryption. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-36 |
Agentic AI Organization Discovery Coverage
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Organization-wide auto-detection provides visibility into unmanaged agent resources. Source check AR-06: No AWS Agent Registry registries found. Resolution
Enable organization-scoped registry auto-detection where centralized discovery is required. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-37 |
Agentic AI Registry Record Lifecycle Governance
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry lifecycle states provide operational visibility but do not independently prove a security control. Source check AR-07: No AWS Agent Registry registries found. Resolution
Review failed or unknown record lifecycle states operationally. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
AG-38 |
Agentic AI Registry Record Provenance
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Consumers need attributable record origin and source lineage to understand which account and resource produced an entry. Source check AR-08: No AWS Agent Registry registries found. Resolution
Ensure records retain creator attribution and auto-detected records retain source provenance. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-01 |
Agentic AI Agent Guardrail Association
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region Resolution
Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-02 |
Agentic AI Harmful Content Guardrail Coverage
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-03 |
Agentic AI Sensitive Information Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: No Bedrock guardrails configured in this region Resolution
Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-04 |
Agentic AI Automated Reasoning Guardrails
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: No Bedrock guardrails configured in this region Resolution
Configure automated reasoning policies on guardrails where formal response validation is required. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-05 |
Agentic AI Grounding Controls
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: No Bedrock guardrails configured in this region Resolution
Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-06 |
Agentic AI Tool Execution Least Privilege
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region Resolution
Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-07 |
Agentic AI Model Invocation Logging
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-08 |
Agentic AI API Audit Trail
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage Resolution
Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-10 |
Agentic AI Adversarial Evaluation Coverage
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs Resolution
Configure model or application evaluations that include adversarial, safety, and security-relevant test cases. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-11 |
Agentic AI Prompt Flow Validation
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region Resolution
Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-12 |
Agentic AI Invocation Abuse Controls
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas Resolution
Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-13 |
Agentic AI Session Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region Resolution
Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-14 |
Agentic AI Operational Abuse Alarms
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms Resolution
Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-19 |
Agentic AI Memory Data Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found Resolution
Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-20 |
Agentic AI Private AgentCore Connectivity
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found Resolution
Create required VPC endpoints for AgentCore services and validate endpoint availability. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-21 |
Agentic AI Resource Policy Boundary
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies Resolution
Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-22 |
Agentic AI Policy Engine Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found Resolution
Configure policy engines with customer-managed KMS keys where enhanced key control is required. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-23 |
Agentic AI Gateway Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found Resolution
Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-24 |
Agentic AI Gateway Inbound Authorization
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-25 |
Agentic AI Gateway Tool Policy Enforcement
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-26 |
Agentic AI Gateway Error Detail Exposure
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-27 |
Agentic AI Gateway WAF Protection
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-29 |
Agentic AI Code Interpreter Isolation
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent-executed code should run inside an explicit VPC boundary with controlled network paths. Source check AC-15: No custom AgentCore Code Interpreters found Resolution
Configure custom AgentCore Code Interpreters in VPC mode with approved subnets and security groups. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-30 |
Agentic AI Prompt Attack Protection
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agents should prevent prompt attacks before untrusted input can redirect planning or tool use. Source check BR-34: No Bedrock guardrails configured in this region Resolution
Enable a preventive PROMPT_ATTACK input filter on each guardrail and use Standard tier where prompt-leakage protection is required. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-31 |
Agentic AI Browser Tool Isolation
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Browser tools can reach external systems and should use explicit private network boundaries. Source check AC-16: No custom AgentCore browsers found Resolution
Configure custom AgentCore browsers in VPC mode with approved subnets and security groups. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-33 |
Agentic AI Registry Publication Approval Governance
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry approval workflows control which agents, tools, and skills become discoverable to consumers. Source check AR-03: Assessment could not enumerate AWS Agent Registry registries: AccessDeniedException (Unauthorized access). Resolution
Require manual review for registry publication where organizational policy does not permit automatic approval. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-34 |
Agentic AI Registry Discovery Authorization
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry discovery authorization requires review against intended callers and effective access boundaries. Source check AR-04: Assessment could not enumerate AWS Agent Registry registries: AccessDeniedException (Unauthorized access). Resolution
Review effective IAM access or compare custom JWT audiences, clients, scopes, and claims with approved registry consumers. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-35 |
Agentic AI Registry Metadata Encryption
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Registry records can contain agent, tool, endpoint, and ownership metadata that benefits from customer-controlled encryption. Source check AR-05: Assessment could not enumerate AWS Agent Registry registries: AccessDeniedException (Unauthorized access). Resolution
Create the registry with a customer-managed KMS key when organizational policy requires customer-controlled encryption. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-36 |
Agentic AI Organization Discovery Coverage
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Organization-wide auto-detection provides visibility into unmanaged agent resources. Source check AR-06: Assessment could not enumerate AWS Agent Registry registries: AccessDeniedException (Unauthorized access). Resolution
Enable organization-scoped registry auto-detection where centralized discovery is required. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-37 |
Agentic AI Registry Record Lifecycle Governance
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry lifecycle states provide operational visibility but do not independently prove a security control. Source check AR-07: Assessment could not enumerate AWS Agent Registry registries: AccessDeniedException (Unauthorized access). Resolution
Review failed or unknown record lifecycle states operationally. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
AG-38 |
Agentic AI Registry Record Provenance
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Consumers need attributable record origin and source lineage to understand which account and resource produced an entry. Source check AR-08: Assessment could not enumerate AWS Agent Registry registries: AccessDeniedException (Unauthorized access). Resolution
Ensure records retain creator attribution and auto-detected records retain source provenance. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-01 |
Agentic AI Agent Guardrail Association
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region Resolution
Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-02 |
Agentic AI Harmful Content Guardrail Coverage
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-03 |
Agentic AI Sensitive Information Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: No Bedrock guardrails configured in this region Resolution
Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-04 |
Agentic AI Automated Reasoning Guardrails
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: No Bedrock guardrails configured in this region Resolution
Configure automated reasoning policies on guardrails where formal response validation is required. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-05 |
Agentic AI Grounding Controls
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: No Bedrock guardrails configured in this region Resolution
Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-06 |
Agentic AI Tool Execution Least Privilege
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region Resolution
Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-07 |
Agentic AI Model Invocation Logging
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-08 |
Agentic AI API Audit Trail
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage Resolution
Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-10 |
Agentic AI Adversarial Evaluation Coverage
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs Resolution
Configure model or application evaluations that include adversarial, safety, and security-relevant test cases. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-11 |
Agentic AI Prompt Flow Validation
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region Resolution
Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-12 |
Agentic AI Invocation Abuse Controls
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas Resolution
Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-13 |
Agentic AI Session Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region Resolution
Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-14 |
Agentic AI Operational Abuse Alarms
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms Resolution
Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-19 |
Agentic AI Memory Data Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found Resolution
Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-20 |
Agentic AI Private AgentCore Connectivity
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found Resolution
Create required VPC endpoints for AgentCore services and validate endpoint availability. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-21 |
Agentic AI Resource Policy Boundary
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies Resolution
Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-22 |
Agentic AI Policy Engine Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found Resolution
Configure policy engines with customer-managed KMS keys where enhanced key control is required. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-23 |
Agentic AI Gateway Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found Resolution
Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-24 |
Agentic AI Gateway Inbound Authorization
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-25 |
Agentic AI Gateway Tool Policy Enforcement
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-26 |
Agentic AI Gateway Error Detail Exposure
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-27 |
Agentic AI Gateway WAF Protection
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-29 |
Agentic AI Code Interpreter Isolation
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent-executed code should run inside an explicit VPC boundary with controlled network paths. Source check AC-15: No custom AgentCore Code Interpreters found Resolution
Configure custom AgentCore Code Interpreters in VPC mode with approved subnets and security groups. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-30 |
Agentic AI Prompt Attack Protection
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agents should prevent prompt attacks before untrusted input can redirect planning or tool use. Source check BR-34: No Bedrock guardrails configured in this region Resolution
Enable a preventive PROMPT_ATTACK input filter on each guardrail and use Standard tier where prompt-leakage protection is required. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-31 |
Agentic AI Browser Tool Isolation
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Browser tools can reach external systems and should use explicit private network boundaries. Source check AC-16: No custom AgentCore browsers found Resolution
Configure custom AgentCore browsers in VPC mode with approved subnets and security groups. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-33 |
Agentic AI Registry Publication Approval Governance
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry approval workflows control which agents, tools, and skills become discoverable to consumers. Source check AR-03: No AWS Agent Registry registries found. Resolution
Require manual review for registry publication where organizational policy does not permit automatic approval. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-34 |
Agentic AI Registry Discovery Authorization
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry discovery authorization requires review against intended callers and effective access boundaries. Source check AR-04: No AWS Agent Registry registries found. Resolution
Review effective IAM access or compare custom JWT audiences, clients, scopes, and claims with approved registry consumers. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-35 |
Agentic AI Registry Metadata Encryption
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Registry records can contain agent, tool, endpoint, and ownership metadata that benefits from customer-controlled encryption. Source check AR-05: No AWS Agent Registry registries found. Resolution
Create the registry with a customer-managed KMS key when organizational policy requires customer-controlled encryption. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-36 |
Agentic AI Organization Discovery Coverage
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Organization-wide auto-detection provides visibility into unmanaged agent resources. Source check AR-06: No AWS Agent Registry registries found. Resolution
Enable organization-scoped registry auto-detection where centralized discovery is required. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-37 |
Agentic AI Registry Record Lifecycle Governance
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry lifecycle states provide operational visibility but do not independently prove a security control. Source check AR-07: No AWS Agent Registry registries found. Resolution
Review failed or unknown record lifecycle states operationally. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
AG-38 |
Agentic AI Registry Record Provenance
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Consumers need attributable record origin and source lineage to understand which account and resource produced an entry. Source check AR-08: No AWS Agent Registry registries found. Resolution
Ensure records retain creator attribution and auto-detected records retain source provenance. |
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-02 |
No API Gateway Usage Plans Found
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-03 |
Bedrock Token Quotas Customized
|
Medium | – Not failing Passed → Passed |
123456789012 |
Global |
FS-07 |
Agent Action Boundary Check
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-08 |
No AgentCore Runtimes Found
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-10 |
Human-in-the-Loop Check — No Agent Workflows Found
Details and remediationDetails
No Step Functions state machines with agent/approval naming found. Verify that high-risk agent actions (e.g., fund transfers, account changes) have human approval gates. Resolution
Implement Step Functions .waitForTaskToken patterns for high-risk agent actions. Route approval requests to human reviewers via SNS/SES/Slack. |
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-13 |
Model Provenance Tags Present
|
Medium | – Not failing Passed → Passed |
123456789012 |
Global |
FS-14 |
Model Governance Config Rules Present
|
Medium | – Not failing Passed → Passed |
123456789012 |
Global |
FS-16 |
ECR Image Scanning Covered by Inspector Enhanced Scanning
Details and remediationDetails
Amazon Inspector enhanced scanning for ECR is ENABLED account-wide, so all 2 repository(ies) are continuously scanned. 1 repository(ies) do not set scan-on-push (cdk-hnb659fds-container-assets-123456789012-us-east-1), which is expected when enhanced scanning supersedes basic scanning. Resolution
No action required while Inspector enhanced scanning stays enabled. If it is disabled, enable scan-on-push per repository. |
High | – Not failing Passed → Passed |
123456789012 |
Global |
FS-20 |
No SageMaker Feature Groups Found
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-21 |
No Training Data Buckets Identified
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-24 |
No Knowledge Bases Found
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-25 |
No OpenSearch Serverless Collections Found
Details and remediationDetails
No OpenSearch Serverless collections exist in this region, so there is no OpenSearch vector-store data at rest to encrypt. If Bedrock Knowledge Bases use a different vector store (S3 Vectors, Aurora, Pinecone), verify its encryption separately. Resolution
If you adopt OpenSearch Serverless as a Bedrock KB vector store, create an encryption policy specifying a customer-managed KMS key before creating the collection. |
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-27 |
No Guardrails — Contextual Grounding Not Applicable
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-28 |
No Guardrails — Topic Policy Not Applicable
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-29 |
ADVISORY: Compliance Disclaimer — Manual Review Required
Details and remediationDetails
Application-level compliance disclaimers cannot be verified via AWS APIs. Manual review required to confirm GenAI outputs include required regulatory disclosures. Resolution
1. Implement post-processing to append required disclaimers to GenAI outputs. 2. Use Bedrock Guardrails word filters to block outputs that omit required disclosures. 3. Document disclaimer requirements in the AI use case register. 4. Test disclaimer presence in QA/UAT before production deployment. |
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-30 |
ADVISORY: Compliance Dataset Coverage — Manual Review Required
Details and remediationDetails
Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation jobs include compliance-specific datasets (fair lending/ECOA, Fair Housing Act, UDAP/UDAAP, AML/KYC edge cases). Whether any evaluation jobs exist at all is assessed by FS-15. Resolution
Run Bedrock Model Evaluation with compliance-specific datasets: - Fair lending test cases (ECOA, Fair Housing Act) - UDAP/UDAAP unfair/deceptive practice scenarios - AML/KYC edge cases |
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-31 |
No Knowledge Bases Found
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-32 |
ADVISORY: Source Attribution — Manual Review Required
Details and remediationDetails
Source attribution in GenAI responses cannot be verified via AWS APIs. Manual review required to confirm responses include citations. Resolution
1. Use Bedrock RetrieveAndGenerate with citations enabled. 2. Include source document references in response post-processing. 3. Test citation accuracy in QA before production deployment. 4. Consider Bedrock Guardrails grounding checks to validate response accuracy. |
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-33 |
No Knowledge Bases Found
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-34 |
Legacy Foundation Models Available in Region
Details and remediationDetails
Legacy/deprecated foundation models are available in this account/region: anthropic.claude-sonnet-4-28186377-v1:0, twelvelabs.marengo-embed-2-7-v1:0, anthropic.claude-opus-4-1-08608513-v1:0, amazon.nova-premier-v1:0:8k, amazon.nova-premier-v1:0:20k, amazon.nova-premier-v1:0:1000k, amazon.nova-premier-v1:0:mm, amazon.nova-premier-v1:0, amazon.nova-canvas-v1:0, amazon.nova-reel-v1:0. This API reports model *availability*, not actual usage — it cannot determine which models your applications invoke. Legacy models have older training-data cutoffs and may produce outdated information if used. Review whether any are in active use. Resolution
1. Identify which (if any) of these legacy models your applications invoke (e.g., via CloudTrail InvokeModel events or application config). 2. Migrate active usage to current model versions. 3. Document training-data cutoff dates for all models in use. 4. Add data-currency disclaimers to outputs from models with old cutoffs. |
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-35 |
ADVISORY: Harmful-Content Test Coverage — Manual Review Required
Details and remediationDetails
Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation/FMEval jobs include harmful-content datasets (toxicity, hate speech, violence/self-harm). Whether any evaluation jobs exist at all is assessed by FS-15. Resolution
Run Bedrock Model Evaluation or FMEval with harmful content datasets: - Toxicity detection - Hate speech classification - Violence/self-harm content |
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-36 |
No Guardrails — Content Filters Not Applicable
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-37 |
ADVISORY: User Feedback Mechanism — Manual Review Required
Details and remediationDetails
User feedback mechanisms for harmful outputs cannot be verified via AWS APIs. Manual review required. Resolution
1. Implement thumbs-up/down or flag-for-review UI in GenAI applications. 2. Route flagged outputs to human reviewers via SQS/SNS. 3. Log feedback to DynamoDB/S3 for model improvement. 4. Define SLAs for reviewing flagged content. |
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-38 |
No Guardrails — Word Filters Not Applicable
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-40 |
ADVISORY: Bias Dataset Coverage — Manual Review Required
Details and remediationDetails
Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation jobs include bias/fairness datasets (demographic parity, equal-opportunity, counterfactual fairness) for any GenAI models used in financial decisions (ECOA/Fair Housing). Whether any evaluation jobs exist at all is assessed by FS-15. Resolution
Run Bedrock Model Evaluation with bias test datasets: - Demographic parity test cases - Equal opportunity scenarios - Counterfactual fairness tests |
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-42 |
No SageMaker Model Cards Found
Details and remediationDetails
No SageMaker Model Cards found. If GenAI workloads run on Bedrock rather than SageMaker, model documentation may legitimately live elsewhere; Model Cards are a SageMaker-specific artifact. Resolution
1. For SageMaker models, create a Model Card documenting intended use, out-of-scope uses, training data and bias evaluations. 2. For Bedrock-only estates, record the equivalent documentation in your model-governance system and reference the AWS AI Service Cards. |
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-43 |
Bedrock Invocation Logging Not Enabled
Details and remediationDetails
Bedrock model invocation logging is not enabled, so no invocation logs are being delivered and there is no log content to mask. Prompt and completion content is therefore also unavailable for audit. Resolution
1. Enable Bedrock model invocation logging. 2. If delivering to CloudWatch Logs, attach a data protection policy masking PII to the destination log group. |
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-45 |
No Guardrails — PII Filters Not Applicable
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-46 |
No AI/ML Data Buckets Identified
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-47 |
No Guardrails — Grounding Threshold Not Applicable
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-49 |
ADVISORY: Hallucination Disclaimer — Manual Review Required
Details and remediationDetails
Application-level hallucination disclaimers cannot be verified via AWS APIs. Manual review required. Resolution
1. Add disclaimers to GenAI outputs: 'AI-generated content may contain errors. Verify with authoritative sources before acting.' 2. Implement post-processing to append disclaimers. 3. Test disclaimer presence in QA before production. |
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-51 |
No Guardrails — Prompt Attack Filters Not Applicable
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-52 |
Bedrock Lambda Functions on Current Runtimes
|
Medium | – Not failing Passed → Passed |
123456789012 |
Global |
FS-53 |
No WAF Web ACLs — Injection Rules Not Applicable
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-54 |
ADVISORY: Penetration Testing — Manual Review Required
Details and remediationDetails
Penetration testing evidence cannot be verified via AWS APIs. Manual review required to confirm GenAI applications have been tested. Resolution
1. Conduct penetration testing of GenAI applications at least annually and before major releases. 2. Include AI-specific test cases: prompt injection, jailbreak, indirect (cross-domain) injection, system-prompt leakage, and data-extraction attempts. 3. Consider AWS Security Agent for on-demand, AI-driven penetration testing (GA March 2026; available in US East N. Virginia, US West Oregon, Europe Ireland, Europe Frankfurt, Asia Pacific Sydney, Asia Pacific Tokyo, with cross-account shared-VPC testing via AWS RAM). Open-source tools such as Garak or PyRIT and manual red-teaming are complementary options. Verify current regional availability on the AWS Security Agent page before relying on it. 4. Document findings and remediation for regulatory examination, and tag tested resources with a last-pentest-date for audit trail. 5. For DORA compliance, include GenAI in TLPT (Threat-Led Penetration Testing) scope. |
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-56 |
No WAF ACLs — XSS Prevention Not Applicable
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-57 |
ADVISORY: Output Encoding — Manual Review Required
Details and remediationDetails
Output encoding practices cannot be verified via AWS APIs. Manual code review required. Resolution
1. HTML-encode GenAI outputs before rendering in web UIs. 2. Use parameterized queries when GenAI output is used in database operations. 3. JSON-encode outputs before embedding in JavaScript contexts. 4. Validate output length and format before passing to downstream APIs. |
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-58 |
ADVISORY: Output Schema Validation — Manual Review Required
Details and remediationDetails
Found 0 Lambda function(s) whose names suggest schema/validation handling. Structured-output / JSON-schema validation of GenAI responses is an application-layer control that cannot be verified automatically — manual review required. Resolution
1. Use Bedrock structured output (response schemas) where supported. 2. Implement JSON schema validation on Lambda output processors. 3. Reject malformed outputs and return safe error responses. 4. Log schema validation failures to CloudWatch for monitoring. |
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-59 |
No Guardrails — Topic Allowlist Not Applicable
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-60 |
ADVISORY: Contextual Grounding for Off-Topic Prevention
Details and remediationDetails
Contextual grounding for off-topic prevention is covered by guardrail grounding checks (FS-47) and RAG configuration (FS-48). Additionally verify system prompts explicitly scope the assistant's role. Resolution
1. Include explicit scope instructions in system prompts. 2. Use Bedrock Guardrails relevance grounding filter. 3. Test with off-topic prompts in QA to verify rejection behavior. |
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-61 |
No Knowledge Bases Found
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-62 |
ADVISORY: Data Currency Disclaimer — Manual Review Required
Details and remediationDetails
Data currency disclaimers cannot be verified via AWS APIs. Manual review required. Resolution
1. Add data currency disclaimers to GenAI outputs: 'Information based on data current as of [KB last sync date].' 2. Expose KB last sync timestamp in application responses. 3. Alert users when KB data is older than defined threshold. |
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-63 |
Foundation Model Lifecycle Governance Detected
Details and remediationDetails
12 AWS Config rule(s) with lifecycle- or model-related names were found, indicating some account-side model lifecycle governance: s3-version-lifecycle-policy-check-conformance-pack-v9atrhlyf, s3-version-lifecycle-policy-check-conformance-pack-prqocsazj, securityhub-ecr-private-lifecycle-policy-configured-c72ebd28, securityhub-s3-lifecycle-policy-check-6039fb41, securityhub-s3express-dir-bucket-lifecycle-rules-check-f12f0aa0. Rule names are a heuristic; whether these rules enforce model currency is not assessed. For context, 17 of 122 model(s) offered in this region are marked LEGACY (for example ai21.jamba-1-5-large-v1:0, ai21.jamba-1-5-mini-v1:0, amazon.nova-canvas-v1:0, amazon.nova-premier-v1:0, amazon.nova-premier-v1:0:1000k); this reflects the regional catalogue, not this account's usage. Resolution
Confirm the matched rules genuinely track model currency, and that deprecation notifications are monitored. |
Medium | – Not failing Passed → Passed |
123456789012 |
Global |
FS-65 |
No Knowledge Bases Found
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-66 |
No AgentCore Runtimes Found
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-67 |
No Agent Action-Group Lambda Functions Found
Details and remediationDetails
No Lambda functions matching agent action-group naming patterns found. If agents perform financial transactions, verify transaction-value limits are enforced in the action-group implementation. Resolution
1. Implement transaction-value threshold checks in all agent action-group Lambda functions that initiate financial operations. 2. Use AgentCore Policy Engine to enforce maximum transaction amounts as a policy constraint on tool calls. 3. Reject or escalate to human review any transaction exceeding defined limits. |
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
FS-69 |
Prompt Input Validation Functions Present
Details and remediation |
Medium | – Not failing Passed → Passed |
123456789012 |
us-east-1 |
FS-00 |
Responsible AI GRC — Regional Scope Not Applicable
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
FS-00 |
Responsible AI GRC — Regional Scope Not Applicable
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
FS-00 |
Responsible AI GRC — Regional Scope Not Applicable
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
OW-01 |
OWASP LLM01: Adversarial Testing Evidence
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check FS-54: Penetration testing evidence cannot be verified via AWS APIs. Manual review required to confirm GenAI applications have been tested. Resolution
Track adversarial / red-team penetration test evidence for the GenAI application via resource tags or an equivalent audit trail. |
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
OW-01 |
OWASP LLM01: Bedrock-Calling Lambda Runtimes
|
Medium | – Not failing Passed → Passed |
123456789012 |
Global |
OW-01 |
OWASP LLM01: PROMPT_ATTACK Filter at Standard Tier
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
OW-01 |
OWASP LLM01: Prompt-Input Validation Lambda
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check FS-69: Found 1 Lambda function(s) with input validation/sanitization naming patterns: aiml-security-aiml-sec-123456789012-CleanupBucket. Resolution
Deploy a prompt-input validation Lambda in front of Bedrock invocations to sanitise untrusted input before it reaches the model. |
Medium | – Not failing Passed → Passed |
123456789012 |
Global |
OW-01 |
OWASP LLM01: WAF SQLi & KnownBadInputs Coverage
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
OW-02 |
OWASP LLM02: CloudWatch Log Data Protection Policies
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-43: Bedrock model invocation logging is not enabled, so no invocation logs are being delivered and there is no log content to mask. Prompt and completion content is therefore also unavailable for audit. Resolution
Apply a CloudWatch Logs data protection policy to log groups that receive Bedrock invocation logs. |
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
OW-02 |
OWASP LLM02: Guardrail PII Entities Coverage
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
OW-02 |
OWASP LLM02: S3 Data-Classification Tagging
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-46: No S3 buckets with AI/ML naming found. Resolution
Tag training and knowledge-base S3 buckets with a data-classification tag so downstream automations enforce controls consistent with the sensitivity level. |
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
OW-03 |
OWASP LLM03: Config Rules for Model Onboarding
|
Medium | – Not failing Passed → Passed |
123456789012 |
Global |
OW-03 |
OWASP LLM03: Custom-Model Provenance Tags
|
Medium | – Not failing Passed → Passed |
123456789012 |
Global |
OW-03 |
OWASP LLM03: ECR Image Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check FS-16: Amazon Inspector enhanced scanning for ECR is ENABLED account-wide, so all 2 repository(ies) are continuously scanned. 1 repository(ies) do not set scan-on-push (cdk-hnb659fds-container-assets-123456789012-us-east-1), which is expected when enhanced scanning supersedes basic scanning. Resolution
Enable Amazon Inspector enhanced scanning or scan-on-push on ECR repositories that hold model / agent container images. |
High | – Not failing Passed → Passed |
123456789012 |
Global |
OW-04 |
OWASP LLM04: Feature Store Offline Recovery
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
OW-04 |
OWASP LLM04: SageMaker Model Card Documentation
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check FS-42: No SageMaker Model Cards found. If GenAI workloads run on Bedrock rather than SageMaker, model documentation may legitimately live elsewhere; Model Cards are a SageMaker-specific artifact. Resolution
Create SageMaker Model Cards for production models that document intended use, training data provenance, and bias/fairness evaluations so poisoned or drifted models are detectable against a documented baseline. |
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
OW-04 |
OWASP LLM04: Training-Data Versioning
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
OW-05 |
OWASP LLM05: Output Encoding Libraries
Details and remediationDetails
OWASP category: LLM05:2025 Improper Output Handling. Source check FS-57: Output encoding practices cannot be verified via AWS APIs. Manual code review required. Resolution
Ensure Lambdas that render model output use a well-known output-encoding library appropriate to the downstream sink (HTML, SQL, shell, etc.). |
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
OW-05 |
OWASP LLM05: Step Functions Output Schema Validation
Details and remediationDetails
OWASP category: LLM05:2025 Improper Output Handling. Source check FS-58: Found 0 Lambda function(s) whose names suggest schema/validation handling. Structured-output / JSON-schema validation of GenAI responses is an application-layer control that cannot be verified automatically — manual review required. Resolution
Add explicit schema-validation states in Step Functions workflows that consume model output. |
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
OW-05 |
OWASP LLM05: WAF XSS Protection
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
OW-06 |
OWASP LLM06: Agent Execution Role Least Privilege
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
OW-06 |
OWASP LLM06: Agent Transaction Thresholds
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check FS-67: No Lambda functions matching agent action-group naming patterns found. If agents perform financial transactions, verify transaction-value limits are enforced in the action-group implementation. Resolution
Encode agent transaction thresholds in Cedar policies or Lambda configuration so per-action limits are enforced. |
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
OW-06 |
OWASP LLM06: AgentCore Gateway Policy Engine
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
OW-06 |
OWASP LLM06: AgentCore IAM Least Privilege
|
High | – Not failing Passed → Passed |
123456789012 |
Global |
OW-06 |
OWASP LLM06: Human-in-the-Loop Callback States
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check FS-10: No Step Functions state machines with agent/approval naming found. Verify that high-risk agent actions (e.g., fund transfers, account changes) have human approval gates. Resolution
Insert Step Functions .waitForTaskToken callback states before any high-risk agent-triggered action. |
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
OW-08 |
OWASP LLM08: KB Metadata Filtering
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
OW-08 |
OWASP LLM08: OpenSearch Serverless Encryption
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-25: No OpenSearch Serverless collections exist in this region, so there is no OpenSearch vector-store data at rest to encrypt. If Bedrock Knowledge Bases use a different vector store (S3 Vectors, Aurora, Pinecone), verify its encryption separately. Resolution
Use a customer-managed KMS key on the OpenSearch Serverless encryption policy for the vector collection. |
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
OW-09 |
OWASP LLM09: Grounding Filter Threshold
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
OW-09 |
OWASP LLM09: KB S3 Data-Source Integrity
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
OW-09 |
OWASP LLM09: Knowledge-Base Ingestion Freshness
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
OW-09 |
OWASP LLM09: SageMaker Model Card Documentation
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check FS-42: No SageMaker Model Cards found. If GenAI workloads run on Bedrock rather than SageMaker, model documentation may legitimately live elsewhere; Model Cards are a SageMaker-specific artifact. Resolution
Document each production model's intended use, known limitations, and evaluation results in a SageMaker Model Card so misinformation risks tied to model behaviour are traceable to a reviewed system card. |
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
OW-09 |
OWASP LLM09: Source Attribution
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check FS-32: Source attribution in GenAI responses cannot be verified via AWS APIs. Manual review required to confirm responses include citations. Resolution
Return citations in RetrieveAndGenerate responses so end users can verify grounding. |
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
OW-10 |
OWASP LLM10: API Gateway Usage Plans
|
Informational | – Not failing N/A → N/A |
123456789012 |
Global |
OW-10 |
OWASP LLM10: Bedrock TPM/RPM Quotas Customised
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-03: Found 266 Bedrock token-based quota(s); at least one applied value exceeds the AWS default, indicating quotas have been reviewed and raised. Resolution
Customise Bedrock service quotas above the account default so consumption is explicitly bounded. |
Medium | – Not failing Passed → Passed |
123456789012 |
us-east-1 |
OW-01 |
OWASP LLM01: Contextual Grounding Guardrail
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-01 |
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-01 |
OWASP LLM01: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-01 |
OWASP LLM01: Preventive Prompt Attack Filter
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-02 |
OWASP LLM02: Automated Reasoning Policy Encryption
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-02 |
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-02 |
OWASP LLM02: HyperPod Volume CMK Encryption
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-02 |
OWASP LLM02: Marketplace Endpoint CMK Encryption
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: No SageMaker resources found to check for data protection Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-02 |
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-03 |
OWASP LLM03: HyperPod VPC Boundary
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-03 |
OWASP LLM03: Imported-Model KMS Provenance
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-03 |
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check BR-33: Amazon Inspector Lambda standard scanning and Lambda code scanning are both ENABLED in us-east-1. Detected 1 Lambda function(s) with Bedrock indicators: aiml-security-aiml-sec-123456789012-BedrockAssessment. Resolution
Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain. |
Medium | – Not failing Passed → Passed |
123456789012 |
us-east-1 |
OW-03 |
OWASP LLM03: Marketplace Endpoint VPC Isolation
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-03 |
OWASP LLM03: Model Registry Resource Policy Boundary
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker AutoML Network Isolation
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Container Repository Access
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Internet Exposure
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-01: No SageMaker notebook instances or domains found to check Resolution
Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Model Network Isolation
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Notebook VPC Deployment
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-04 |
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation |
Medium | – Not failing Passed → Passed |
123456789012 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-06 |
OWASP LLM06: Agent Action-Group Least Privilege
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-06 |
OWASP LLM06: Agent Idle Session TTL
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-06 |
OWASP LLM06: AgentCore Resource-Based Policies
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-06 |
OWASP LLM06: Bedrock Agent Guardrail Association
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-06 |
OWASP LLM06: Browser Tool Network Isolation
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-06 |
OWASP LLM06: Code Interpreter Network Isolation
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-07 |
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-07 |
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-07 |
OWASP LLM07: Model Invocation Logging
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-09 |
OWASP LLM09: Contextual Grounding for Faithfulness
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-09 |
OWASP LLM09: Model Evaluation Jobs
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Clarify Evaluation
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation |
Medium | – Not failing Passed → Passed |
123456789012 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Model Monitor Coverage
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-10 |
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-10 |
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-10 |
OWASP LLM10: Service Quota Throttling Limits
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-1 |
OW-11 |
OWASP LLM07: System Prompt Embedded in Lambda Env Var
|
Medium | – Not failing Passed → Passed |
123456789012 |
us-east-1 |
OW-12 |
OWASP LLM07: System-Prompt-Disclosure Denied Topic
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-01 |
OWASP LLM01: Contextual Grounding Guardrail
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-01 |
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-01 |
OWASP LLM01: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-01 |
OWASP LLM01: Preventive Prompt Attack Filter
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-02 |
OWASP LLM02: Automated Reasoning Policy Encryption
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-02 |
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-02 |
OWASP LLM02: HyperPod Volume CMK Encryption
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-02 |
OWASP LLM02: Marketplace Endpoint CMK Encryption
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: No SageMaker resources found to check for data protection Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-02 |
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-03 |
OWASP LLM03: HyperPod VPC Boundary
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-03 |
OWASP LLM03: Imported-Model KMS Provenance
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-03 |
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check BR-33: No Lambda functions with Bedrock indicators were found in us-east-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-03 |
OWASP LLM03: Marketplace Endpoint VPC Isolation
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-03 |
OWASP LLM03: Model Registry Resource Policy Boundary
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker AutoML Network Isolation
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker Container Repository Access
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker Internet Exposure
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-01: No SageMaker notebook instances or domains found to check Resolution
Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker Model Network Isolation
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker Notebook VPC Deployment
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-04 |
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation |
Medium | – Not failing Passed → Passed |
123456789012 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-06 |
OWASP LLM06: Agent Action-Group Least Privilege
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-06 |
OWASP LLM06: Agent Idle Session TTL
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-06 |
OWASP LLM06: AgentCore Resource-Based Policies
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-06 |
OWASP LLM06: Bedrock Agent Guardrail Association
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-06 |
OWASP LLM06: Browser Tool Network Isolation
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-06 |
OWASP LLM06: Code Interpreter Network Isolation
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-07 |
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-07 |
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-07 |
OWASP LLM07: Model Invocation Logging
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-09 |
OWASP LLM09: Contextual Grounding for Faithfulness
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-09 |
OWASP LLM09: Model Evaluation Jobs
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Clarify Evaluation
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation |
Medium | – Not failing Passed → Passed |
123456789012 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Model Monitor Coverage
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-10 |
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-10 |
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-10 |
OWASP LLM10: Service Quota Throttling Limits
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-east-2 |
OW-11 |
OWASP LLM07: System Prompt Embedded in Lambda Env Var
|
Medium | – Not failing Passed → Passed |
123456789012 |
us-east-2 |
OW-12 |
OWASP LLM07: System-Prompt-Disclosure Denied Topic
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-01 |
OWASP LLM01: Contextual Grounding Guardrail
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-01 |
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-01 |
OWASP LLM01: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-01 |
OWASP LLM01: Preventive Prompt Attack Filter
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-02 |
OWASP LLM02: Automated Reasoning Policy Encryption
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-02 |
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-02 |
OWASP LLM02: HyperPod Volume CMK Encryption
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-02 |
OWASP LLM02: Marketplace Endpoint CMK Encryption
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: No SageMaker resources found to check for data protection Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-02 |
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-03 |
OWASP LLM03: HyperPod VPC Boundary
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-03 |
OWASP LLM03: Imported-Model KMS Provenance
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-03 |
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check BR-33: No Lambda functions with Bedrock indicators were found in us-west-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-03 |
OWASP LLM03: Marketplace Endpoint VPC Isolation
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-03 |
OWASP LLM03: Model Registry Resource Policy Boundary
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker AutoML Network Isolation
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker Container Repository Access
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker Internet Exposure
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-01: No SageMaker notebook instances or domains found to check Resolution
Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker Model Network Isolation
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker Notebook VPC Deployment
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-04 |
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation |
Medium | – Not failing Passed → Passed |
123456789012 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-06 |
OWASP LLM06: Agent Action-Group Least Privilege
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-06 |
OWASP LLM06: Agent Idle Session TTL
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-06 |
OWASP LLM06: AgentCore Resource-Based Policies
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-06 |
OWASP LLM06: Bedrock Agent Guardrail Association
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-06 |
OWASP LLM06: Browser Tool Network Isolation
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-06 |
OWASP LLM06: Code Interpreter Network Isolation
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-07 |
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-07 |
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-07 |
OWASP LLM07: Model Invocation Logging
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-09 |
OWASP LLM09: Contextual Grounding for Faithfulness
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-09 |
OWASP LLM09: Model Evaluation Jobs
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Clarify Evaluation
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release. |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation |
Medium | – Not failing Passed → Passed |
123456789012 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Model Monitor Coverage
|
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-10 |
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-10 |
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-10 |
OWASP LLM10: Service Quota Throttling Limits
Details and remediation |
Informational | – Not failing N/A → N/A |
123456789012 |
us-west-2 |
OW-11 |
OWASP LLM07: System Prompt Embedded in Lambda Env Var
|
Medium | – Not failing Passed → Passed |
123456789012 |
us-west-2 |
OW-12 |
OWASP LLM07: System-Prompt-Disclosure Denied Topic
|
Informational | – Not failing N/A → N/A |
Change States
| Change | Meaning |
|---|---|
| ▼ Regressed | Passed in the previous run, Failed now. |
| ✚ New | Failed now; N/A or not present in the previous run. |
| ● Still open | Failed in both runs. |
| ✓ Resolved | Failed in the previous run, Passed now. |
| ○ No longer reported | Failed in the previous run, not present now. |
| ? No longer assessed | Failed in the previous run, N/A now. Not counted as resolved: N/A also covers access-denied and unavailable-region results. |
| – Not failing | No Failed result in either run. Hidden by default. |
How Findings Are Matched
- Rows are grouped by assessment area, Region, and Check ID. The Finding title isn't part of the group, because many checks use one title when they fail and another when they pass.
- Within a group, rows with the same title and identical details are paired, then rows whose details match once day counts and dates are blanked out, then rows with matching details under a different title.
- Two remaining rows are paired if each is its run's only row, in the group or with its title. If both are Failed and their details differ, the row is marked "details changed": one resource may have been fixed and another started failing.
- If one run has several Failed rows and the other a single row that isn't Failed, such as a Passed summary, each Failed row is paired with that row.
- Anything left is unpaired and shows as New or No longer reported.
The previous run is the most recent usable run saved before this one: its results are complete and, in single-account mode, its run record doesn't say it failed. Only services selected, optional modules enabled, and regions scanned in both runs are compared. The changes CSV records which rule paired each row. See docs/ASSESSMENT_HISTORY.md in the repository.