Security Assessment Overview
Priority Recommendations
Severity Legend
View full methodology| Severity | Meaning | Recommended Action |
|---|---|---|
| High | Direct security risk - IAM/access control gaps, missing audit trails, guardrail bypasses that could lead to unauthorized access or data exposure | Remediate within 7 days |
| Medium | Defense-in-depth gaps - encryption, logging, or configuration issues that reduce security posture | Remediate within 30 days |
| Low | Best practice deviations - optimization opportunities that improve security hygiene | Remediate within 90 days |
| Informational | Not applicable, unavailable, no resources found, or advisory-only rows | No action required |
Direct Service Scored Row Results by Severity
Direct Failed Rows by Account
Direct Failed Rows by Region / Scope
Findings by Assessment Area
| Account ID | Region | Check ID | Finding | Severity | Status |
|---|---|---|---|---|---|
111122223333 |
eu-west-1 |
AC-01 |
AgentCore VPC Configuration Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
AC-04 |
AgentCore Observability Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
AC-05 |
AgentCore Encryption Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
AC-06 |
AgentCore Browser Tool Recording Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
AC-07 |
AgentCore Memory Configuration Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
AC-13 |
AgentCore Gateway Configuration Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
AC-08 |
AgentCore VPC Endpoints Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
AC-10 |
AgentCore Resource-Based Policies Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
AC-11 |
AgentCore Policy Engine Encryption Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
AC-12 |
AgentCore Gateway Encryption Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
AG-24 |
Agentic AI Gateway Inbound Authorization
|
Informational | N/A |
111122223333 |
eu-west-1 |
AG-25 |
Agentic AI Gateway Tool Policy Enforcement
|
Informational | N/A |
111122223333 |
eu-west-1 |
AG-26 |
Agentic AI Gateway Error Detail Exposure
|
Informational | N/A |
111122223333 |
eu-west-1 |
AG-27 |
Agentic AI Gateway WAF Protection
|
Informational | N/A |
111122223333 |
eu-west-1 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
Informational | N/A |
111122223333 |
eu-west-1 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Informational | N/A |
111122223333 |
eu-west-1 |
AG-19 |
Agentic AI Memory Data Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found Resolution
Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions. |
Informational | N/A |
111122223333 |
eu-west-1 |
AG-20 |
Agentic AI Private AgentCore Connectivity
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found Resolution
Create required VPC endpoints for AgentCore services and validate endpoint availability. |
Informational | N/A |
111122223333 |
eu-west-1 |
AG-21 |
Agentic AI Resource Policy Boundary
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies Resolution
Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources. |
Informational | N/A |
111122223333 |
eu-west-1 |
AG-22 |
Agentic AI Policy Engine Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found Resolution
Configure policy engines with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
111122223333 |
eu-west-1 |
AG-23 |
Agentic AI Gateway Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found Resolution
Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
111122223333 |
Global |
AC-02 |
AgentCore IAM Full Access Policy
|
High | Failed |
111122223333 |
Global |
AC-02 |
AgentCore IAM Wildcard Permissions
|
High | Failed |
111122223333 |
Global |
AC-03 |
AgentCore Stale Access
Details and remediationDetails
The following principals have not accessed AgentCore in 60+ days: role 'AmazonSageMaker-ExecutionRole-20250525T153161' (208 days), role 'AWSServiceRoleForBedrockAgentCoreRuntimeIdentity' (208 days), role 'CustomerSupportAssistantBedrockAgentCoreRole-us-east-1' (208 days), role 'resco-aiml-security-19304-AgentCoreSecurityAssessme-w773pPsFWNsn' (91 days) Resolution
Review and remove unused AgentCore permissions following least privilege principle |
Medium | Failed |
111122223333 |
Global |
AC-03 |
AgentCore Unused Permissions
Details and remediationDetails
The following principals have AgentCore permissions but have never accessed the service: role 'agentcore-wildrydes_gateway_role_ab3991f6-role', role 'AIMLSecurityMemberRole', role 'AmazonBedrockAgentCoreSDKRuntime-us-east-1-a6ddf3fc76', role 'AmazonBedrockAgentCoreSDKRuntime-us-east-1-ed660add8b', role 'aws-api-mcp-server-execution-role', role 'CloudSeerTrustedServiceRole', role 'CustomerSupportStackInfra-RuntimeAgentCoreRole-N188nLB5RtLO', role 'IDP-AnalyticsProcessorFunctionRole-H3gwkJtNqrqW' Resolution
Review and remove unused AgentCore permissions following least privilege principle |
Informational | N/A |
111122223333 |
Global |
AC-09 |
AgentCore Service-Linked Role Missing
Details and remediationDetails
Service-linked role 'AWSServiceRoleForBedrockAgentCoreNetwork' does not exist. VPC configuration for AgentCore Runtimes will fail without this role. Resolution
The service-linked role is automatically created when you configure VPC for an AgentCore Runtime. Ensure IAM permissions allow service-linked role creation. |
Medium | Failed |
111122223333 |
us-east-1 |
AC-01 |
AgentCore Runtime VPC Configuration
|
High | Failed |
111122223333 |
us-east-1 |
AC-01 |
AgentCore Runtime VPC Configuration
|
High | Failed |
111122223333 |
us-east-1 |
AC-01 |
AgentCore Runtime VPC Configuration
|
High | Failed |
111122223333 |
us-east-1 |
AC-01 |
AgentCore Runtime VPC Configuration
|
High | Failed |
111122223333 |
us-east-1 |
AC-01 |
AgentCore Runtime VPC Configuration
|
High | Failed |
111122223333 |
us-east-1 |
AC-04 |
AgentCore Runtime CloudWatch Logs
|
Medium | Failed |
111122223333 |
us-east-1 |
AC-04 |
AgentCore Runtime X-Ray Tracing
|
Medium | Failed |
111122223333 |
us-east-1 |
AC-04 |
AgentCore Runtime CloudWatch Logs
|
Medium | Failed |
111122223333 |
us-east-1 |
AC-04 |
AgentCore Runtime X-Ray Tracing
|
Medium | Failed |
111122223333 |
us-east-1 |
AC-04 |
AgentCore Runtime CloudWatch Logs
|
Medium | Failed |
111122223333 |
us-east-1 |
AC-04 |
AgentCore Runtime X-Ray Tracing
|
Medium | Failed |
111122223333 |
us-east-1 |
AC-04 |
AgentCore Runtime CloudWatch Logs
|
Medium | Failed |
111122223333 |
us-east-1 |
AC-04 |
AgentCore Runtime X-Ray Tracing
|
Medium | Failed |
111122223333 |
us-east-1 |
AC-04 |
AgentCore Runtime CloudWatch Logs
|
Medium | Failed |
111122223333 |
us-east-1 |
AC-04 |
AgentCore Runtime X-Ray Tracing
|
Medium | Failed |
111122223333 |
us-east-1 |
AC-05 |
AgentCore ECR Repository AWS-Managed Keys
|
Low | Failed |
111122223333 |
us-east-1 |
AC-05 |
AgentCore ECR Repository AWS-Managed Keys
|
Low | Failed |
111122223333 |
us-east-1 |
AC-06 |
AgentCore Runtime Storage Configuration
|
Medium | Failed |
111122223333 |
us-east-1 |
AC-06 |
AgentCore Runtime Storage Configuration
|
Medium | Failed |
111122223333 |
us-east-1 |
AC-06 |
AgentCore Runtime Storage Configuration
|
Medium | Failed |
111122223333 |
us-east-1 |
AC-06 |
AgentCore Runtime Storage Configuration
|
Medium | Failed |
111122223333 |
us-east-1 |
AC-06 |
AgentCore Runtime Storage Configuration
|
Medium | Failed |
111122223333 |
us-east-1 |
AC-07 |
AgentCore Memory Encryption
|
Medium | Failed |
111122223333 |
us-east-1 |
AC-07 |
AgentCore Memory Encryption
|
Medium | Failed |
111122223333 |
us-east-1 |
AC-07 |
AgentCore Memory Encryption
|
Medium | Failed |
111122223333 |
us-east-1 |
AC-13 |
AgentCore Gateway Configuration Check
|
Medium | Passed |
111122223333 |
us-east-1 |
AC-08 |
AgentCore VPC Endpoints Missing
Details and remediationDetails
No AgentCore VPC endpoints found in 4 VPCs. AgentCore API traffic traverses public internet, exposing it to interception. Resolution
Create VPC interface endpoints for AgentCore services: 1. com.amazonaws.region.bedrock-agentcore 2. com.amazonaws.region.bedrock-agentcore-control 3. com.amazonaws.region.bedrock-agentcore-runtime This enables private connectivity via AWS PrivateLink |
High | Failed |
111122223333 |
us-east-1 |
AC-10 |
AgentCore Resource-Based Policies Missing
Details and remediationDetails
The following AgentCore resources do not have resource-based policies: Runtime 'origami_expeditions', Runtime 'neoCyan_Agent', Runtime 'customer_support_agent', Runtime 'cdk_agent_core', Runtime 'awsapimcpserver' and 2 more. Without RBPs, access control relies solely on identity-based policies. Resolution
Attach resource-based policies to AgentCore resources to: 1. Implement defense-in-depth access control 2. Enable cross-account access control 3. Restrict access based on source VPC or IP 4. Implement hierarchical authorization for Agent Runtimes |
High | Failed |
111122223333 |
us-east-1 |
AC-11 |
AgentCore Policy Engine Encryption Check
|
Informational | N/A |
111122223333 |
us-east-1 |
AC-12 |
AgentCore Gateway Encryption Missing
Details and remediationDetails
The following Gateways do not use customer-managed KMS encryption: 'customersupport-gw', 'wildrydes-gateway-ab3991f6'. Gateway configuration data uses AWS-managed keys. Resolution
1. Create gateways with customer-managed KMS keys for additional control 2. AWS-managed keys are single-tenant and region-specific 3. Consider CMK for enhanced audit capabilities and key rotation control |
Low | Failed |
111122223333 |
us-east-1 |
AG-24 |
Agentic AI Gateway Inbound Authorization
|
High | Passed |
111122223333 |
us-east-1 |
AG-25 |
Agentic AI Gateway Tool Policy Enforcement Missing
Details and remediation |
High | Failed |
111122223333 |
us-east-1 |
AG-26 |
Agentic AI Gateway Error Detail Exposure
|
Medium | Passed |
111122223333 |
us-east-1 |
AG-27 |
Agentic AI Gateway WAF Protection Missing
|
Low | Failed |
111122223333 |
us-east-1 |
AG-24 |
Agentic AI Gateway Inbound Authorization
|
High | Passed |
111122223333 |
us-east-1 |
AG-25 |
Agentic AI Gateway Tool Policy Enforcement Missing
Details and remediationDetails
Gateway 'wildrydes-gateway-ab3991f6' (wildrydes-gateway-ab3991f6-jrlh9ok6ya) does not have a policy engine configuration. Tool calls are not evaluated by AgentCore policy enforcement. Resolution
Attach an AgentCore policy engine to the gateway and use ENFORCE mode for production tool authorization. |
High | Failed |
111122223333 |
us-east-1 |
AG-26 |
Agentic AI Gateway Error Detail Exposure
|
Medium | Passed |
111122223333 |
us-east-1 |
AG-27 |
Agentic AI Gateway WAF Protection Missing
|
Low | Failed |
111122223333 |
Global |
AG-16 |
Agentic AI AgentCore Least Privilege
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Over-permissive AgentCore principals can let agents or operators bypass intended autonomy and tool boundaries. Source check AC-02: The following roles have BedrockAgentCoreFullAccess policy: AmazonSageMaker-ExecutionRole-20250525T153161 Resolution
Replace full-access AgentCore permissions with least-privilege IAM policies scoped to required resources and actions. |
High | Failed |
111122223333 |
Global |
AG-16 |
Agentic AI AgentCore Least Privilege
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Over-permissive AgentCore principals can let agents or operators bypass intended autonomy and tool boundaries. Source check AC-02: The following roles have wildcard AgentCore permissions on all resources: agentcore-wildrydes_gateway_role_ab3991f6-role Resolution
Replace full-access AgentCore permissions with least-privilege IAM policies scoped to required resources and actions. |
High | Failed |
111122223333 |
Global |
AG-17 |
Agentic AI Stale AgentCore Access
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Unused AgentCore permissions increase the blast radius of compromised principals. Source check AC-03: The following principals have not accessed AgentCore in 60+ days: role 'AmazonSageMaker-ExecutionRole-20250525T153161' (208 days), role 'AWSServiceRoleForBedrockAgentCoreRuntimeIdentity' (208 days), role 'CustomerSupportAssistantBedrockAgentCoreRole-us-east-1' (208 days), role 'resco-aiml-security-19304-AgentCoreSecurityAssessme-w773pPsFWNsn' (91 days) Resolution
Remove or restrict stale AgentCore permissions for principals that no longer need access. |
Medium | Failed |
111122223333 |
Global |
AG-17 |
Agentic AI Stale AgentCore Access
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Unused AgentCore permissions increase the blast radius of compromised principals. Source check AC-03: The following principals have AgentCore permissions but have never accessed the service: role 'agentcore-wildrydes_gateway_role_ab3991f6-role', role 'AIMLSecurityMemberRole', role 'AmazonBedrockAgentCoreSDKRuntime-us-east-1-a6ddf3fc76', role 'AmazonBedrockAgentCoreSDKRuntime-us-east-1-ed660add8b', role 'aws-api-mcp-server-execution-role', role 'CloudSeerTrustedServiceRole', role 'CustomerSupportStackInfra-RuntimeAgentCoreRole-N188nLB5RtLO', role 'IDP-AnalyticsProcessorFunctionRole-H3gwkJtNqrqW' Resolution
Remove or restrict stale AgentCore permissions for principals that no longer need access. |
Informational | N/A |
111122223333 |
us-east-1 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: Runtime 'origami_expeditions' (origami_expeditions-TR4jDoHXe8) is not configured with VPC. This exposes the runtime to public internet. Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
High | Failed |
111122223333 |
us-east-1 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: Runtime 'neoCyan_Agent' (neoCyan_Agent-yAFXSWFaA3) is not configured with VPC. This exposes the runtime to public internet. Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
High | Failed |
111122223333 |
us-east-1 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: Runtime 'customer_support_agent' (customer_support_agent-ZP4e8z55dP) is not configured with VPC. This exposes the runtime to public internet. Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
High | Failed |
111122223333 |
us-east-1 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: Runtime 'cdk_agent_core' (cdk_agent_core-7FqFlD86LW) is not configured with VPC. This exposes the runtime to public internet. Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
High | Failed |
111122223333 |
us-east-1 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: Runtime 'awsapimcpserver' (awsapimcpserver-mJrqgt37GO) is not configured with VPC. This exposes the runtime to public internet. Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
High | Failed |
111122223333 |
us-east-1 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: Runtime 'origami_expeditions' (origami_expeditions-TR4jDoHXe8) does not have CloudWatch Logs configured Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Medium | Failed |
111122223333 |
us-east-1 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: Runtime 'origami_expeditions' (origami_expeditions-TR4jDoHXe8) does not have X-Ray tracing enabled Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Medium | Failed |
111122223333 |
us-east-1 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: Runtime 'neoCyan_Agent' (neoCyan_Agent-yAFXSWFaA3) does not have CloudWatch Logs configured Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Medium | Failed |
111122223333 |
us-east-1 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: Runtime 'neoCyan_Agent' (neoCyan_Agent-yAFXSWFaA3) does not have X-Ray tracing enabled Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Medium | Failed |
111122223333 |
us-east-1 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: Runtime 'customer_support_agent' (customer_support_agent-ZP4e8z55dP) does not have CloudWatch Logs configured Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Medium | Failed |
111122223333 |
us-east-1 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: Runtime 'customer_support_agent' (customer_support_agent-ZP4e8z55dP) does not have X-Ray tracing enabled Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Medium | Failed |
111122223333 |
us-east-1 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: Runtime 'cdk_agent_core' (cdk_agent_core-7FqFlD86LW) does not have CloudWatch Logs configured Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Medium | Failed |
111122223333 |
us-east-1 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: Runtime 'cdk_agent_core' (cdk_agent_core-7FqFlD86LW) does not have X-Ray tracing enabled Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Medium | Failed |
111122223333 |
us-east-1 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: Runtime 'awsapimcpserver' (awsapimcpserver-mJrqgt37GO) does not have CloudWatch Logs configured Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Medium | Failed |
111122223333 |
us-east-1 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: Runtime 'awsapimcpserver' (awsapimcpserver-mJrqgt37GO) does not have X-Ray tracing enabled Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Medium | Failed |
111122223333 |
us-east-1 |
AG-19 |
Agentic AI Memory Data Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: Memory 'CustomerSupportMemory-x69jBq5GLp' (CustomerSupportMemory-x69jBq5GLp) does not have customer-managed encryption configured Resolution
Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions. |
Medium | Failed |
111122223333 |
us-east-1 |
AG-19 |
Agentic AI Memory Data Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: Memory 'cdk_agent_core_mem-uxfIagADuF' (cdk_agent_core_mem-uxfIagADuF) does not have customer-managed encryption configured Resolution
Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions. |
Medium | Failed |
111122223333 |
us-east-1 |
AG-19 |
Agentic AI Memory Data Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: Memory 'wildrydes_memory_ab3991f6-9FjiHOHjT2' (wildrydes_memory_ab3991f6-9FjiHOHjT2) does not have customer-managed encryption configured Resolution
Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions. |
Medium | Failed |
111122223333 |
us-east-1 |
AG-20 |
Agentic AI Private AgentCore Connectivity
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore VPC endpoints found in 4 VPCs. AgentCore API traffic traverses public internet, exposing it to interception. Resolution
Create required VPC endpoints for AgentCore services and validate endpoint availability. |
High | Failed |
111122223333 |
us-east-1 |
AG-21 |
Agentic AI Resource Policy Boundary
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: The following AgentCore resources do not have resource-based policies: Runtime 'origami_expeditions', Runtime 'neoCyan_Agent', Runtime 'customer_support_agent', Runtime 'cdk_agent_core', Runtime 'awsapimcpserver' and 2 more. Without RBPs, access control relies solely on identity-based policies. Resolution
Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources. |
High | Failed |
111122223333 |
us-east-1 |
AG-22 |
Agentic AI Policy Engine Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found Resolution
Configure policy engines with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
111122223333 |
us-east-1 |
AG-23 |
Agentic AI Gateway Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: The following Gateways do not use customer-managed KMS encryption: 'customersupport-gw', 'wildrydes-gateway-ab3991f6'. Gateway configuration data uses AWS-managed keys. Resolution
Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required. |
Low | Failed |
111122223333 |
us-east-1 |
FS-01 |
AWS Shield Advanced Not Enabled
Details and remediationDetails
AWS Shield Advanced is not subscribed. GenAI API endpoints are vulnerable to volumetric DDoS attacks that can exhaust token quotas and inflate costs. Resolution
1. Subscribe to AWS Shield Advanced for DDoS protection. 2. After subscribing, explicitly add resource protections in the Shield Advanced console for each Bedrock-facing resource (API Gateway stages, ALBs, CloudFront distributions, Route 53 hosted zones). Shield Advanced subscription alone does NOT automatically protect resources — each resource must be individually added to receive protection. 3. Enable Shield Response Team (SRT) access and configure proactive engagement. 4. Alternatively, use AWS Firewall Manager with a Shield Advanced policy to automate resource protection based on tags or resource types. |
Low | Failed |
111122223333 |
us-east-2 |
FS-01 |
AWS Shield Advanced Not Enabled
Details and remediationDetails
AWS Shield Advanced is not subscribed. GenAI API endpoints are vulnerable to volumetric DDoS attacks that can exhaust token quotas and inflate costs. Resolution
1. Subscribe to AWS Shield Advanced for DDoS protection. 2. After subscribing, explicitly add resource protections in the Shield Advanced console for each Bedrock-facing resource (API Gateway stages, ALBs, CloudFront distributions, Route 53 hosted zones). Shield Advanced subscription alone does NOT automatically protect resources — each resource must be individually added to receive protection. 3. Enable Shield Response Team (SRT) access and configure proactive engagement. 4. Alternatively, use AWS Firewall Manager with a Shield Advanced policy to automate resource protection based on tags or resource types. |
Low | Failed |
111122223333 |
us-west-2 |
FS-01 |
AWS Shield Advanced Not Enabled
Details and remediationDetails
AWS Shield Advanced is not subscribed. GenAI API endpoints are vulnerable to volumetric DDoS attacks that can exhaust token quotas and inflate costs. Resolution
1. Subscribe to AWS Shield Advanced for DDoS protection. 2. After subscribing, explicitly add resource protections in the Shield Advanced console for each Bedrock-facing resource (API Gateway stages, ALBs, CloudFront distributions, Route 53 hosted zones). Shield Advanced subscription alone does NOT automatically protect resources — each resource must be individually added to receive protection. 3. Enable Shield Response Team (SRT) access and configure proactive engagement. 4. Alternatively, use AWS Firewall Manager with a Shield Advanced policy to automate resource protection based on tags or resource types. |
Low | Failed |
111122223333 |
us-east-1 |
FS-01 |
No Regional WAF Web ACLs Found
Details and remediationDetails
No AWS WAF regional Web ACLs found. Without WAF, GenAI endpoints lack rate-based rules to block abusive callers. Resolution
1. Create a WAF Web ACL with rate-based rules (e.g., 1000 req/5 min per IP). 2. Associate the ACL with API Gateway stages or ALBs fronting Bedrock. 3. Add AWS Managed Rules for known bad inputs. |
Medium | Failed |
111122223333 |
us-east-2 |
FS-01 |
No Regional WAF Web ACLs Found
Details and remediationDetails
No AWS WAF regional Web ACLs found. Without WAF, GenAI endpoints lack rate-based rules to block abusive callers. Resolution
1. Create a WAF Web ACL with rate-based rules (e.g., 1000 req/5 min per IP). 2. Associate the ACL with API Gateway stages or ALBs fronting Bedrock. 3. Add AWS Managed Rules for known bad inputs. |
Medium | Failed |
111122223333 |
us-west-2 |
FS-01 |
No Regional WAF Web ACLs Found
Details and remediationDetails
No AWS WAF regional Web ACLs found. Without WAF, GenAI endpoints lack rate-based rules to block abusive callers. Resolution
1. Create a WAF Web ACL with rate-based rules (e.g., 1000 req/5 min per IP). 2. Associate the ACL with API Gateway stages or ALBs fronting Bedrock. 3. Add AWS Managed Rules for known bad inputs. |
Medium | Failed |
111122223333 |
us-east-1 |
FS-02 |
API Gateway Usage Plans Missing Throttle
Details and remediation |
Medium | Failed |
111122223333 |
us-east-2 |
FS-02 |
API Gateway Usage Plans Missing Throttle
Details and remediation |
Medium | Failed |
111122223333 |
us-west-2 |
FS-02 |
API Gateway Usage Plans Missing Throttle
Details and remediation |
Medium | Failed |
111122223333 |
us-east-1 |
FS-03 |
Bedrock Token Quotas Customized
|
Medium | Passed |
111122223333 |
us-east-2 |
FS-03 |
Bedrock Token Quotas Customized
|
Medium | Passed |
111122223333 |
us-west-2 |
FS-03 |
Bedrock Token Quotas Customized
|
Medium | Passed |
111122223333 |
us-east-1 |
FS-04 |
No Cost Anomaly Detection Monitors
Details and remediationDetails
No AWS Cost Anomaly Detection monitors found. Unexpected spikes in Bedrock/SageMaker usage (e.g., from prompt injection loops) will go undetected. Resolution
1. Create a Cost Anomaly Detection monitor scoped to AWS/Bedrock and AWS/SageMaker. 2. Configure alert subscriptions (SNS/email) for anomalies above threshold. 3. Set daily spend budgets with AWS Budgets as a secondary control. |
Medium | Failed |
111122223333 |
us-east-2 |
FS-04 |
No Cost Anomaly Detection Monitors
Details and remediationDetails
No AWS Cost Anomaly Detection monitors found. Unexpected spikes in Bedrock/SageMaker usage (e.g., from prompt injection loops) will go undetected. Resolution
1. Create a Cost Anomaly Detection monitor scoped to AWS/Bedrock and AWS/SageMaker. 2. Configure alert subscriptions (SNS/email) for anomalies above threshold. 3. Set daily spend budgets with AWS Budgets as a secondary control. |
Medium | Failed |
111122223333 |
us-west-2 |
FS-04 |
No Cost Anomaly Detection Monitors
Details and remediationDetails
No AWS Cost Anomaly Detection monitors found. Unexpected spikes in Bedrock/SageMaker usage (e.g., from prompt injection loops) will go undetected. Resolution
1. Create a Cost Anomaly Detection monitor scoped to AWS/Bedrock and AWS/SageMaker. 2. Configure alert subscriptions (SNS/email) for anomalies above threshold. 3. Set daily spend budgets with AWS Budgets as a secondary control. |
Medium | Failed |
111122223333 |
us-east-1 |
FS-05 |
No Bedrock CloudWatch Alarms Found
Details and remediationDetails
No CloudWatch alarms found for Bedrock metrics. Token exhaustion and throttling events will not trigger operational alerts. Resolution
Create CloudWatch alarms for: - AWS/Bedrock InvocationThrottles (threshold > 0) - AWS/Bedrock TokensProcessed (threshold based on quota) - Custom application-level token counters via EMF |
Medium | Failed |
111122223333 |
us-east-2 |
FS-05 |
No Bedrock CloudWatch Alarms Found
Details and remediationDetails
No CloudWatch alarms found for Bedrock metrics. Token exhaustion and throttling events will not trigger operational alerts. Resolution
Create CloudWatch alarms for: - AWS/Bedrock InvocationThrottles (threshold > 0) - AWS/Bedrock TokensProcessed (threshold based on quota) - Custom application-level token counters via EMF |
Medium | Failed |
111122223333 |
us-west-2 |
FS-05 |
No Bedrock CloudWatch Alarms Found
Details and remediationDetails
No CloudWatch alarms found for Bedrock metrics. Token exhaustion and throttling events will not trigger operational alerts. Resolution
Create CloudWatch alarms for: - AWS/Bedrock InvocationThrottles (threshold > 0) - AWS/Bedrock TokensProcessed (threshold based on quota) - Custom application-level token counters via EMF |
Medium | Failed |
111122223333 |
us-east-1 |
FS-06 |
No AI/ML Service Budgets Configured
Details and remediationDetails
No AWS Budgets found scoped to Bedrock or SageMaker. Unbounded GenAI spend can go undetected until the monthly bill. Resolution
1. Create cost budgets for AWS Bedrock and SageMaker with 80%/100% alert thresholds. 2. Add SNS notifications to on-call channels. 3. Consider budget actions to apply IAM deny policies when thresholds are breached. |
Medium | Failed |
111122223333 |
us-east-2 |
FS-06 |
No AI/ML Service Budgets Configured
Details and remediationDetails
No AWS Budgets found scoped to Bedrock or SageMaker. Unbounded GenAI spend can go undetected until the monthly bill. Resolution
1. Create cost budgets for AWS Bedrock and SageMaker with 80%/100% alert thresholds. 2. Add SNS notifications to on-call channels. 3. Consider budget actions to apply IAM deny policies when thresholds are breached. |
Medium | Failed |
111122223333 |
us-west-2 |
FS-06 |
No AI/ML Service Budgets Configured
Details and remediationDetails
No AWS Budgets found scoped to Bedrock or SageMaker. Unbounded GenAI spend can go undetected until the monthly bill. Resolution
1. Create cost budgets for AWS Bedrock and SageMaker with 80%/100% alert thresholds. 2. Add SNS notifications to on-call channels. 3. Consider budget actions to apply IAM deny policies when thresholds are breached. |
Medium | Failed |
111122223333 |
us-east-1 |
FS-07 |
Agent Action Boundary Check
|
Informational | N/A |
111122223333 |
us-east-2 |
FS-07 |
Agent Action Boundary Check
|
Informational | N/A |
111122223333 |
us-west-2 |
FS-07 |
Agent Action Boundary Check
|
Informational | N/A |
111122223333 |
us-east-1 |
FS-08 |
AgentCore Runtimes Missing Policy Engine
Details and remediationDetails
Runtimes without authorizer configuration: origami_expeditions, neoCyan_Agent, customer_support_agent, cdk_agent_core, awsapimcpserver. Without a policy engine, agents can invoke any registered tool without authorization checks. Resolution
Configure an authorizer (Lambda or Cedar policy store) on each AgentCore runtime to enforce fine-grained tool-call authorization. |
High | Failed |
111122223333 |
us-east-2 |
FS-08 |
AgentCore Runtimes Missing Policy Engine
Details and remediationDetails
Runtimes without authorizer configuration: origami_expeditions, neoCyan_Agent, customer_support_agent, cdk_agent_core, awsapimcpserver. Without a policy engine, agents can invoke any registered tool without authorization checks. Resolution
Configure an authorizer (Lambda or Cedar policy store) on each AgentCore runtime to enforce fine-grained tool-call authorization. |
High | Failed |
111122223333 |
us-west-2 |
FS-08 |
AgentCore Runtimes Missing Policy Engine
Details and remediationDetails
Runtimes without authorizer configuration: origami_expeditions, neoCyan_Agent, customer_support_agent, cdk_agent_core, awsapimcpserver. Without a policy engine, agents can invoke any registered tool without authorization checks. Resolution
Configure an authorizer (Lambda or Cedar policy store) on each AgentCore runtime to enforce fine-grained tool-call authorization. |
High | Failed |
111122223333 |
us-east-1 |
FS-09 |
Agent Lambda Functions Without Concurrency Limits
Details and remediationDetails
Agent-related Lambda functions without reserved concurrency: aiml-security-aiml-security-111122223333-FinServAssessment, resco-aiml-IAMPermissionCaching, aiml-security-aiml-security-111122223333-OWASPAssessment, aiml-security-aiml-security-111122223333-SagemakerAssessment, resco-aiml-CleanupBucket, aiml-security-aiml-security-111122223333-BedrockAssessment, resco-aiml-BedrockAssessment, aiml-security-aiml-security-111122223333-CleanupBucket, aiml-security-aiml-security-111122223333-AgentCoreAssessment, e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk. Unlimited concurrency allows runaway agent loops to exhaust account limits. Resolution
1. Set reserved concurrency on agent Lambda functions. 2. Implement maximum iteration counts in agent orchestration logic. 3. Use Step Functions with MaxConcurrency and timeout states. 4. Add circuit-breaker patterns to agent tool invocations. |
Medium | Failed |
111122223333 |
us-east-2 |
FS-09 |
Agent Lambda Functions Without Concurrency Limits
Details and remediationDetails
Agent-related Lambda functions without reserved concurrency: aiml-security-aiml-security-111122223333-FinServAssessment, resco-aiml-IAMPermissionCaching, aiml-security-aiml-security-111122223333-OWASPAssessment, aiml-security-aiml-security-111122223333-SagemakerAssessment, resco-aiml-CleanupBucket, aiml-security-aiml-security-111122223333-BedrockAssessment, resco-aiml-BedrockAssessment, aiml-security-aiml-security-111122223333-CleanupBucket, aiml-security-aiml-security-111122223333-AgentCoreAssessment, e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk. Unlimited concurrency allows runaway agent loops to exhaust account limits. Resolution
1. Set reserved concurrency on agent Lambda functions. 2. Implement maximum iteration counts in agent orchestration logic. 3. Use Step Functions with MaxConcurrency and timeout states. 4. Add circuit-breaker patterns to agent tool invocations. |
Medium | Failed |
111122223333 |
us-west-2 |
FS-09 |
Agent Lambda Functions Without Concurrency Limits
Details and remediationDetails
Agent-related Lambda functions without reserved concurrency: aiml-security-aiml-security-111122223333-FinServAssessment, resco-aiml-IAMPermissionCaching, aiml-security-aiml-security-111122223333-OWASPAssessment, aiml-security-aiml-security-111122223333-SagemakerAssessment, resco-aiml-CleanupBucket, aiml-security-aiml-security-111122223333-BedrockAssessment, resco-aiml-BedrockAssessment, aiml-security-aiml-security-111122223333-CleanupBucket, aiml-security-aiml-security-111122223333-AgentCoreAssessment, e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk. Unlimited concurrency allows runaway agent loops to exhaust account limits. Resolution
1. Set reserved concurrency on agent Lambda functions. 2. Implement maximum iteration counts in agent orchestration logic. 3. Use Step Functions with MaxConcurrency and timeout states. 4. Add circuit-breaker patterns to agent tool invocations. |
Medium | Failed |
111122223333 |
us-east-1 |
FS-10 |
Human-in-the-Loop Check — No Agent Workflows Found
Details and remediationDetails
No Step Functions state machines with agent/approval naming found. Verify that high-risk agent actions (e.g., fund transfers, account changes) have human approval gates. Resolution
Implement Step Functions .waitForTaskToken patterns for high-risk agent actions. Route approval requests to human reviewers via SNS/SES/Slack. |
Informational | N/A |
111122223333 |
us-east-2 |
FS-10 |
Human-in-the-Loop Check — No Agent Workflows Found
Details and remediationDetails
No Step Functions state machines with agent/approval naming found. Verify that high-risk agent actions (e.g., fund transfers, account changes) have human approval gates. Resolution
Implement Step Functions .waitForTaskToken patterns for high-risk agent actions. Route approval requests to human reviewers via SNS/SES/Slack. |
Informational | N/A |
111122223333 |
us-west-2 |
FS-10 |
Human-in-the-Loop Check — No Agent Workflows Found
Details and remediationDetails
No Step Functions state machines with agent/approval naming found. Verify that high-risk agent actions (e.g., fund transfers, account changes) have human approval gates. Resolution
Implement Step Functions .waitForTaskToken patterns for high-risk agent actions. Route approval requests to human reviewers via SNS/SES/Slack. |
Informational | N/A |
111122223333 |
us-east-1 |
FS-11 |
No Agent Rate Alarms Found
Details and remediationDetails
No CloudWatch alarms found for agent invocation rates. Looping or runaway agents will not trigger operational alerts. Resolution
Create CloudWatch alarms on: - Bedrock agent invocation counts (threshold based on expected max) - Lambda invocation errors for agent functions - Step Functions execution failures and timeouts |
Medium | Failed |
111122223333 |
us-east-2 |
FS-11 |
No Agent Rate Alarms Found
Details and remediationDetails
No CloudWatch alarms found for agent invocation rates. Looping or runaway agents will not trigger operational alerts. Resolution
Create CloudWatch alarms on: - Bedrock agent invocation counts (threshold based on expected max) - Lambda invocation errors for agent functions - Step Functions execution failures and timeouts |
Medium | Failed |
111122223333 |
us-west-2 |
FS-11 |
No Agent Rate Alarms Found
Details and remediationDetails
No CloudWatch alarms found for agent invocation rates. Looping or runaway agents will not trigger operational alerts. Resolution
Create CloudWatch alarms on: - Bedrock agent invocation counts (threshold based on expected max) - Lambda invocation errors for agent functions - Step Functions execution failures and timeouts |
Medium | Failed |
111122223333 |
us-east-1 |
FS-12 |
No Bedrock-Scoped SCPs Found
Details and remediationDetails
No Service Control Policies reference Bedrock. Without SCPs, any account in the organization can access any Bedrock model, including unapproved third-party models. Resolution
1. Create an SCP that denies bedrock:InvokeModel for model IDs not on the approved list. 2. Use bedrock:ModelId condition key to allowlist approved models. 3. Maintain a model inventory and update the SCP when models are approved/retired. |
High | Failed |
111122223333 |
us-east-2 |
FS-12 |
No Bedrock-Scoped SCPs Found
Details and remediationDetails
No Service Control Policies reference Bedrock. Without SCPs, any account in the organization can access any Bedrock model, including unapproved third-party models. Resolution
1. Create an SCP that denies bedrock:InvokeModel for model IDs not on the approved list. 2. Use bedrock:ModelId condition key to allowlist approved models. 3. Maintain a model inventory and update the SCP when models are approved/retired. |
High | Failed |
111122223333 |
us-west-2 |
FS-12 |
No Bedrock-Scoped SCPs Found
Details and remediationDetails
No Service Control Policies reference Bedrock. Without SCPs, any account in the organization can access any Bedrock model, including unapproved third-party models. Resolution
1. Create an SCP that denies bedrock:InvokeModel for model IDs not on the approved list. 2. Use bedrock:ModelId condition key to allowlist approved models. 3. Maintain a model inventory and update the SCP when models are approved/retired. |
High | Failed |
111122223333 |
us-east-1 |
FS-13 |
Model Provenance Tags Present
|
Medium | Passed |
111122223333 |
us-east-2 |
FS-13 |
Model Provenance Tags Present
|
Medium | Passed |
111122223333 |
us-west-2 |
FS-13 |
Model Provenance Tags Present
|
Medium | Passed |
111122223333 |
us-east-1 |
FS-14 |
Model Governance Config Rules Present
|
Medium | Passed |
111122223333 |
us-east-2 |
FS-14 |
Model Governance Config Rules Present
|
Medium | Passed |
111122223333 |
us-west-2 |
FS-14 |
Model Governance Config Rules Present
|
Medium | Passed |
111122223333 |
us-east-1 |
FS-15 |
No Bedrock Evaluation Jobs Found
Details and remediationDetails
No Bedrock Model Evaluation jobs found. Models have not been evaluated for adversarial robustness. FinServ model-risk management (SR 11-7) expects documented model validation/evaluation. Resolution
1. Run Bedrock Model Evaluation with adversarial/red-team datasets. 2. Use FMEval library for automated robustness testing. 3. Schedule periodic re-evaluation after model updates. |
Medium | Failed |
111122223333 |
us-east-2 |
FS-15 |
No Bedrock Evaluation Jobs Found
Details and remediationDetails
No Bedrock Model Evaluation jobs found. Models have not been evaluated for adversarial robustness. FinServ model-risk management (SR 11-7) expects documented model validation/evaluation. Resolution
1. Run Bedrock Model Evaluation with adversarial/red-team datasets. 2. Use FMEval library for automated robustness testing. 3. Schedule periodic re-evaluation after model updates. |
Medium | Failed |
111122223333 |
us-west-2 |
FS-15 |
No Bedrock Evaluation Jobs Found
Details and remediationDetails
No Bedrock Model Evaluation jobs found. Models have not been evaluated for adversarial robustness. FinServ model-risk management (SR 11-7) expects documented model validation/evaluation. Resolution
1. Run Bedrock Model Evaluation with adversarial/red-team datasets. 2. Use FMEval library for automated robustness testing. 3. Schedule periodic re-evaluation after model updates. |
Medium | Failed |
111122223333 |
us-east-1 |
FS-16 |
ECR Repositories Without Image Scanning
Details and remediationDetails
4 ECR repo(s) without scan-on-push: mlexplorationrepo, cdk-hnb659fds-container-assets-111122223333-us-east-1, bedrock-agentcore-customer_support_agent, bedrock-agentcore-origami_expeditions. Resolution
Enable scan-on-push for all ECR repositories containing model containers. Consider enabling Enhanced Scanning (Inspector) for CVE detection. |
High | Failed |
111122223333 |
us-east-2 |
FS-16 |
ECR Repositories Without Image Scanning
Details and remediationDetails
4 ECR repo(s) without scan-on-push: mlexplorationrepo, cdk-hnb659fds-container-assets-111122223333-us-east-1, bedrock-agentcore-customer_support_agent, bedrock-agentcore-origami_expeditions. Resolution
Enable scan-on-push for all ECR repositories containing model containers. Consider enabling Enhanced Scanning (Inspector) for CVE detection. |
High | Failed |
111122223333 |
us-west-2 |
FS-16 |
ECR Repositories Without Image Scanning
Details and remediationDetails
4 ECR repo(s) without scan-on-push: mlexplorationrepo, cdk-hnb659fds-container-assets-111122223333-us-east-1, bedrock-agentcore-customer_support_agent, bedrock-agentcore-origami_expeditions. Resolution
Enable scan-on-push for all ECR repositories containing model containers. Consider enabling Enhanced Scanning (Inspector) for CVE detection. |
High | Failed |
111122223333 |
us-east-1 |
FS-20 |
No SageMaker Feature Groups Found
|
Informational | N/A |
111122223333 |
us-east-2 |
FS-20 |
No SageMaker Feature Groups Found
|
Informational | N/A |
111122223333 |
us-west-2 |
FS-20 |
No SageMaker Feature Groups Found
|
Informational | N/A |
111122223333 |
us-east-1 |
FS-21 |
Training Data Buckets Without Versioning
Details and remediationDetails
13 training data bucket(s) without versioning: ancbedrocklogging, bedrock-agentcore-codebuild-sources-111122223333-us-east-1, bedrock-bda-us-east-1-dda43109-6557-48bb-993d-3f97126b64b4, bedrock-bda-us-east-1-logging-00719114-debd-4487-85d1-09cbc3fc8, bedrock-kb-bucket-f736570b, bedrock-video-generation-us-east-1-h5ltpm, fsi-genai-workshop-bedrock-datasources-111122223333-us-west-2, knowledgebase-bedrock-agent-agasthik, llmevaluationpromptfoo-bedrockkb-cozhbzbrcmd2, sagemaker-studio-111122223333-huo1mvme4t. Resolution
Enable S3 versioning on all training data buckets. Consider enabling MFA Delete for additional protection against poisoning. |
High | Failed |
111122223333 |
us-east-2 |
FS-21 |
Training Data Buckets Without Versioning
Details and remediationDetails
13 training data bucket(s) without versioning: ancbedrocklogging, bedrock-agentcore-codebuild-sources-111122223333-us-east-1, bedrock-bda-us-east-1-dda43109-6557-48bb-993d-3f97126b64b4, bedrock-bda-us-east-1-logging-00719114-debd-4487-85d1-09cbc3fc8, bedrock-kb-bucket-f736570b, bedrock-video-generation-us-east-1-h5ltpm, fsi-genai-workshop-bedrock-datasources-111122223333-us-west-2, knowledgebase-bedrock-agent-agasthik, llmevaluationpromptfoo-bedrockkb-cozhbzbrcmd2, sagemaker-studio-111122223333-huo1mvme4t. Resolution
Enable S3 versioning on all training data buckets. Consider enabling MFA Delete for additional protection against poisoning. |
High | Failed |
111122223333 |
us-west-2 |
FS-21 |
Training Data Buckets Without Versioning
Details and remediationDetails
13 training data bucket(s) without versioning: ancbedrocklogging, bedrock-agentcore-codebuild-sources-111122223333-us-east-1, bedrock-bda-us-east-1-dda43109-6557-48bb-993d-3f97126b64b4, bedrock-bda-us-east-1-logging-00719114-debd-4487-85d1-09cbc3fc8, bedrock-kb-bucket-f736570b, bedrock-video-generation-us-east-1-h5ltpm, fsi-genai-workshop-bedrock-datasources-111122223333-us-west-2, knowledgebase-bedrock-agent-agasthik, llmevaluationpromptfoo-bedrockkb-cozhbzbrcmd2, sagemaker-studio-111122223333-huo1mvme4t. Resolution
Enable S3 versioning on all training data buckets. Consider enabling MFA Delete for additional protection against poisoning. |
High | Failed |
111122223333 |
us-east-1 |
FS-22 |
Overly Permissive Knowledge Base IAM Roles
Details and remediationDetails
829 role(s) with wildcard KB permissions: - Role '111122223333-us-east-1-kb-setup-function-role' allows 'bedrock:CreateKnowledgeBase' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role '111122223333-us-east-1-kb-setup-function-role' allows 'bedrock:CreateDataSource' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'Admin' allows '*' - Role 'agentcore-wildrydes_gateway_role_ab3991f6-role' allows 'bedrock:*' - Role 'AgentCoreEvalsSDK-us-east-1-d04ba7b68b' allows 'bedrock:InvokeModel' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'AgentCoreEvalsSDK-us-east-1-d04ba7b68b' allows 'bedrock:InvokeModelWithResponseStream' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'Agentic-AI-MCP-Strands-SDK-Works-VSCodeInstanceRole-NCTUnlnRBFO6' allows '*' - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:ListGuardrails' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:GetGuardrail' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:ListModelInvocationJobs' on Resource '*' (no ARN scoping to specific Knowledge Bases) Resolution
Replace wildcard bedrock:* with specific actions such as bedrock:Retrieve, bedrock:RetrieveAndGenerate. Scope resources to specific Knowledge Base ARNs. |
High | Failed |
111122223333 |
us-east-2 |
FS-22 |
Overly Permissive Knowledge Base IAM Roles
Details and remediationDetails
829 role(s) with wildcard KB permissions: - Role '111122223333-us-east-1-kb-setup-function-role' allows 'bedrock:CreateKnowledgeBase' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role '111122223333-us-east-1-kb-setup-function-role' allows 'bedrock:CreateDataSource' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'Admin' allows '*' - Role 'agentcore-wildrydes_gateway_role_ab3991f6-role' allows 'bedrock:*' - Role 'AgentCoreEvalsSDK-us-east-1-d04ba7b68b' allows 'bedrock:InvokeModel' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'AgentCoreEvalsSDK-us-east-1-d04ba7b68b' allows 'bedrock:InvokeModelWithResponseStream' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'Agentic-AI-MCP-Strands-SDK-Works-VSCodeInstanceRole-NCTUnlnRBFO6' allows '*' - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:ListGuardrails' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:GetGuardrail' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:ListModelInvocationJobs' on Resource '*' (no ARN scoping to specific Knowledge Bases) Resolution
Replace wildcard bedrock:* with specific actions such as bedrock:Retrieve, bedrock:RetrieveAndGenerate. Scope resources to specific Knowledge Base ARNs. |
High | Failed |
111122223333 |
us-west-2 |
FS-22 |
Overly Permissive Knowledge Base IAM Roles
Details and remediationDetails
829 role(s) with wildcard KB permissions: - Role '111122223333-us-east-1-kb-setup-function-role' allows 'bedrock:CreateKnowledgeBase' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role '111122223333-us-east-1-kb-setup-function-role' allows 'bedrock:CreateDataSource' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'Admin' allows '*' - Role 'agentcore-wildrydes_gateway_role_ab3991f6-role' allows 'bedrock:*' - Role 'AgentCoreEvalsSDK-us-east-1-d04ba7b68b' allows 'bedrock:InvokeModel' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'AgentCoreEvalsSDK-us-east-1-d04ba7b68b' allows 'bedrock:InvokeModelWithResponseStream' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'Agentic-AI-MCP-Strands-SDK-Works-VSCodeInstanceRole-NCTUnlnRBFO6' allows '*' - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:ListGuardrails' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:GetGuardrail' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:ListModelInvocationJobs' on Resource '*' (no ARN scoping to specific Knowledge Bases) Resolution
Replace wildcard bedrock:* with specific actions such as bedrock:Retrieve, bedrock:RetrieveAndGenerate. Scope resources to specific Knowledge Base ARNs. |
High | Failed |
111122223333 |
us-east-1 |
FS-24 |
ADVISORY: Knowledge Base Metadata Filtering — Manual Review Required
Details and remediationDetails
Found 3 Knowledge Base(s). Tenant-isolation metadata filtering is a design pattern that cannot be verified via API — manual review required. Verify that metadata attributes (e.g., tenantId, classification) are indexed and that Retrieve calls include RetrievalFilter conditions for tenant isolation. Resolution
1. Add metadata fields (tenantId, dataClassification) to KB data sources. 2. Pass RetrievalFilter in all Retrieve/RetrieveAndGenerate calls. 3. Validate filters in integration tests to prevent cross-tenant data leakage. |
Informational | N/A |
111122223333 |
us-east-2 |
FS-24 |
ADVISORY: Knowledge Base Metadata Filtering — Manual Review Required
Details and remediationDetails
Found 3 Knowledge Base(s). Tenant-isolation metadata filtering is a design pattern that cannot be verified via API — manual review required. Verify that metadata attributes (e.g., tenantId, classification) are indexed and that Retrieve calls include RetrievalFilter conditions for tenant isolation. Resolution
1. Add metadata fields (tenantId, dataClassification) to KB data sources. 2. Pass RetrievalFilter in all Retrieve/RetrieveAndGenerate calls. 3. Validate filters in integration tests to prevent cross-tenant data leakage. |
Informational | N/A |
111122223333 |
us-west-2 |
FS-24 |
ADVISORY: Knowledge Base Metadata Filtering — Manual Review Required
Details and remediationDetails
Found 3 Knowledge Base(s). Tenant-isolation metadata filtering is a design pattern that cannot be verified via API — manual review required. Verify that metadata attributes (e.g., tenantId, classification) are indexed and that Retrieve calls include RetrievalFilter conditions for tenant isolation. Resolution
1. Add metadata fields (tenantId, dataClassification) to KB data sources. 2. Pass RetrievalFilter in all Retrieve/RetrieveAndGenerate calls. 3. Validate filters in integration tests to prevent cross-tenant data leakage. |
Informational | N/A |
111122223333 |
us-east-1 |
FS-25 |
OpenSearch Serverless Encryption Policies Present
|
High | Passed |
111122223333 |
us-east-2 |
FS-25 |
OpenSearch Serverless Encryption Policies Present
|
High | Passed |
111122223333 |
us-west-2 |
FS-25 |
OpenSearch Serverless Encryption Policies Present
|
High | Passed |
111122223333 |
us-east-1 |
FS-26 |
OpenSearch Serverless Collections Not VPC-Restricted
|
High | Failed |
111122223333 |
us-east-2 |
FS-26 |
OpenSearch Serverless Collections Not VPC-Restricted
|
High | Failed |
111122223333 |
us-west-2 |
FS-26 |
OpenSearch Serverless Collections Not VPC-Restricted
|
High | Failed |
111122223333 |
us-east-1 |
FS-27 |
Contextual Grounding Enabled on Guardrails
|
High | Passed |
111122223333 |
us-east-2 |
FS-27 |
Contextual Grounding Enabled on Guardrails
|
High | Passed |
111122223333 |
us-west-2 |
FS-27 |
Contextual Grounding Enabled on Guardrails
|
High | Passed |
111122223333 |
us-east-1 |
FS-27 |
No Automated Reasoning Policies Found
Details and remediationDetails
No Bedrock Automated Reasoning policies have been created. ARC (GA August 2025) uses formal verification to guarantee that GenAI outputs comply with authored business rules — e.g., loan criteria, regulatory thresholds, policy constraints. Without ARC policies, factual accuracy of outputs is not formally verified, only heuristically filtered by contextual grounding thresholds. Resolution
1. In the Amazon Bedrock console → Guardrails → Automated Reasoning, create a policy document encoding your FinServ business rules (e.g., eligibility criteria, rate limits, regulatory thresholds). 2. Associate the ARC policy with your guardrail (automatedReasoningPolicy.policies field in CreateGuardrail/UpdateGuardrail). 3. Set confidenceThreshold on the policy to control strictness. 4. ARC requires cross-Region inference — ensure your guardrail has a guardrailProfileArn configured (crossRegionDetails in GetGuardrail response). 5. Reference: AWS Announcement — Automated Reasoning checks GA (August 2025). |
Medium | Failed |
111122223333 |
us-east-2 |
FS-27 |
No Automated Reasoning Policies Found
Details and remediationDetails
No Bedrock Automated Reasoning policies have been created. ARC (GA August 2025) uses formal verification to guarantee that GenAI outputs comply with authored business rules — e.g., loan criteria, regulatory thresholds, policy constraints. Without ARC policies, factual accuracy of outputs is not formally verified, only heuristically filtered by contextual grounding thresholds. Resolution
1. In the Amazon Bedrock console → Guardrails → Automated Reasoning, create a policy document encoding your FinServ business rules (e.g., eligibility criteria, rate limits, regulatory thresholds). 2. Associate the ARC policy with your guardrail (automatedReasoningPolicy.policies field in CreateGuardrail/UpdateGuardrail). 3. Set confidenceThreshold on the policy to control strictness. 4. ARC requires cross-Region inference — ensure your guardrail has a guardrailProfileArn configured (crossRegionDetails in GetGuardrail response). 5. Reference: AWS Announcement — Automated Reasoning checks GA (August 2025). |
Medium | Failed |
111122223333 |
us-west-2 |
FS-27 |
No Automated Reasoning Policies Found
Details and remediationDetails
No Bedrock Automated Reasoning policies have been created. ARC (GA August 2025) uses formal verification to guarantee that GenAI outputs comply with authored business rules — e.g., loan criteria, regulatory thresholds, policy constraints. Without ARC policies, factual accuracy of outputs is not formally verified, only heuristically filtered by contextual grounding thresholds. Resolution
1. In the Amazon Bedrock console → Guardrails → Automated Reasoning, create a policy document encoding your FinServ business rules (e.g., eligibility criteria, rate limits, regulatory thresholds). 2. Associate the ARC policy with your guardrail (automatedReasoningPolicy.policies field in CreateGuardrail/UpdateGuardrail). 3. Set confidenceThreshold on the policy to control strictness. 4. ARC requires cross-Region inference — ensure your guardrail has a guardrailProfileArn configured (crossRegionDetails in GetGuardrail response). 5. Reference: AWS Announcement — Automated Reasoning checks GA (August 2025). |
Medium | Failed |
111122223333 |
us-east-1 |
FS-28 |
Denied Topics Configured on CLASSIC Tier
Details and remediationDetails
Guardrails with topic policies: nist-ai-rmf-guardrail. The following use the CLASSIC tier: nist-ai-rmf-guardrail. CLASSIC tier supports English, French, and Spanish only. The STANDARD tier (GA June 2025) provides broader language support and improved detection for denied topics. Resolution
Verify topics cover regulated financial advice categories. For multilingual FinServ deployments, consider upgrading denied topics to the STANDARD tier (set topicsTierConfig.tierName=STANDARD via UpdateGuardrail; requires a cross-region inference profile on the guardrail). When authoring denied-topic policies, use existing compliance materials as the source: employee policies, training materials, procedure documents, and incident reports (PDF §1.2.1 Practical guidance). |
High | Passed |
111122223333 |
us-east-2 |
FS-28 |
Denied Topics Configured on CLASSIC Tier
Details and remediationDetails
Guardrails with topic policies: nist-ai-rmf-guardrail. The following use the CLASSIC tier: nist-ai-rmf-guardrail. CLASSIC tier supports English, French, and Spanish only. The STANDARD tier (GA June 2025) provides broader language support and improved detection for denied topics. Resolution
Verify topics cover regulated financial advice categories. For multilingual FinServ deployments, consider upgrading denied topics to the STANDARD tier (set topicsTierConfig.tierName=STANDARD via UpdateGuardrail; requires a cross-region inference profile on the guardrail). When authoring denied-topic policies, use existing compliance materials as the source: employee policies, training materials, procedure documents, and incident reports (PDF §1.2.1 Practical guidance). |
High | Passed |
111122223333 |
us-west-2 |
FS-28 |
Denied Topics Configured on CLASSIC Tier
Details and remediationDetails
Guardrails with topic policies: nist-ai-rmf-guardrail. The following use the CLASSIC tier: nist-ai-rmf-guardrail. CLASSIC tier supports English, French, and Spanish only. The STANDARD tier (GA June 2025) provides broader language support and improved detection for denied topics. Resolution
Verify topics cover regulated financial advice categories. For multilingual FinServ deployments, consider upgrading denied topics to the STANDARD tier (set topicsTierConfig.tierName=STANDARD via UpdateGuardrail; requires a cross-region inference profile on the guardrail). When authoring denied-topic policies, use existing compliance materials as the source: employee policies, training materials, procedure documents, and incident reports (PDF §1.2.1 Practical guidance). |
High | Passed |
111122223333 |
us-east-1 |
FS-29 |
ADVISORY: Compliance Disclaimer — Manual Review Required
Details and remediationDetails
Application-level compliance disclaimers cannot be verified via AWS APIs. Manual review required to confirm GenAI outputs include required regulatory disclosures. Resolution
1. Implement post-processing to append required disclaimers to GenAI outputs. 2. Use Bedrock Guardrails word filters to block outputs that omit required disclosures. 3. Document disclaimer requirements in the AI use case register. 4. Test disclaimer presence in QA/UAT before production deployment. |
Informational | N/A |
111122223333 |
us-east-2 |
FS-29 |
ADVISORY: Compliance Disclaimer — Manual Review Required
Details and remediationDetails
Application-level compliance disclaimers cannot be verified via AWS APIs. Manual review required to confirm GenAI outputs include required regulatory disclosures. Resolution
1. Implement post-processing to append required disclaimers to GenAI outputs. 2. Use Bedrock Guardrails word filters to block outputs that omit required disclosures. 3. Document disclaimer requirements in the AI use case register. 4. Test disclaimer presence in QA/UAT before production deployment. |
Informational | N/A |
111122223333 |
us-west-2 |
FS-29 |
ADVISORY: Compliance Disclaimer — Manual Review Required
Details and remediationDetails
Application-level compliance disclaimers cannot be verified via AWS APIs. Manual review required to confirm GenAI outputs include required regulatory disclosures. Resolution
1. Implement post-processing to append required disclaimers to GenAI outputs. 2. Use Bedrock Guardrails word filters to block outputs that omit required disclosures. 3. Document disclaimer requirements in the AI use case register. 4. Test disclaimer presence in QA/UAT before production deployment. |
Informational | N/A |
111122223333 |
us-east-1 |
FS-30 |
ADVISORY: Compliance Dataset Coverage — Manual Review Required
Details and remediationDetails
Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation jobs include compliance-specific datasets (fair lending/ECOA, Fair Housing Act, UDAP/UDAAP, AML/KYC edge cases). Whether any evaluation jobs exist at all is assessed by FS-15. Resolution
Run Bedrock Model Evaluation with compliance-specific datasets: - Fair lending test cases (ECOA, Fair Housing Act) - UDAP/UDAAP unfair/deceptive practice scenarios - AML/KYC edge cases |
Informational | N/A |
111122223333 |
us-east-2 |
FS-30 |
ADVISORY: Compliance Dataset Coverage — Manual Review Required
Details and remediationDetails
Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation jobs include compliance-specific datasets (fair lending/ECOA, Fair Housing Act, UDAP/UDAAP, AML/KYC edge cases). Whether any evaluation jobs exist at all is assessed by FS-15. Resolution
Run Bedrock Model Evaluation with compliance-specific datasets: - Fair lending test cases (ECOA, Fair Housing Act) - UDAP/UDAAP unfair/deceptive practice scenarios - AML/KYC edge cases |
Informational | N/A |
111122223333 |
us-west-2 |
FS-30 |
ADVISORY: Compliance Dataset Coverage — Manual Review Required
Details and remediationDetails
Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation jobs include compliance-specific datasets (fair lending/ECOA, Fair Housing Act, UDAP/UDAAP, AML/KYC edge cases). Whether any evaluation jobs exist at all is assessed by FS-15. Resolution
Run Bedrock Model Evaluation with compliance-specific datasets: - Fair lending test cases (ECOA, Fair Housing Act) - UDAP/UDAAP unfair/deceptive practice scenarios - AML/KYC edge cases |
Informational | N/A |
111122223333 |
us-east-1 |
FS-31 |
Knowledge Base Data Sources Past Review Threshold
Details and remediationDetails
2 data source(s) not synced in >7 days (a configurable review threshold, NOT an AWS-mandated limit): - KB 'knowledge-base-semiconductors' source 'knowledge-base-quick-start-qpvuv-data-source' last synced 731 days ago - KB '111122223333-us-east-1-kb' source '111122223333-us-east-1-kb-datasource' last synced 209 days ago Confirm this age is acceptable for each data source's currency requirement — slow-changing reference data may legitimately sync infrequently. Resolution
1. Define the maximum acceptable data age per use case (e.g., intraday for market data, daily for product terms, weekly/monthly for regulatory guidance) and adjust the review threshold to match. 2. Configure automated sync (EventBridge Scheduler → StartIngestionJob) at that cadence — see FS-61. 3. Set CloudWatch alarms on sync job failures. |
Medium | Failed |
111122223333 |
us-east-2 |
FS-31 |
Knowledge Base Data Sources Past Review Threshold
Details and remediationDetails
2 data source(s) not synced in >7 days (a configurable review threshold, NOT an AWS-mandated limit): - KB 'knowledge-base-semiconductors' source 'knowledge-base-quick-start-qpvuv-data-source' last synced 731 days ago - KB '111122223333-us-east-1-kb' source '111122223333-us-east-1-kb-datasource' last synced 209 days ago Confirm this age is acceptable for each data source's currency requirement — slow-changing reference data may legitimately sync infrequently. Resolution
1. Define the maximum acceptable data age per use case (e.g., intraday for market data, daily for product terms, weekly/monthly for regulatory guidance) and adjust the review threshold to match. 2. Configure automated sync (EventBridge Scheduler → StartIngestionJob) at that cadence — see FS-61. 3. Set CloudWatch alarms on sync job failures. |
Medium | Failed |
111122223333 |
us-west-2 |
FS-31 |
Knowledge Base Data Sources Past Review Threshold
Details and remediationDetails
2 data source(s) not synced in >7 days (a configurable review threshold, NOT an AWS-mandated limit): - KB 'knowledge-base-semiconductors' source 'knowledge-base-quick-start-qpvuv-data-source' last synced 731 days ago - KB '111122223333-us-east-1-kb' source '111122223333-us-east-1-kb-datasource' last synced 209 days ago Confirm this age is acceptable for each data source's currency requirement — slow-changing reference data may legitimately sync infrequently. Resolution
1. Define the maximum acceptable data age per use case (e.g., intraday for market data, daily for product terms, weekly/monthly for regulatory guidance) and adjust the review threshold to match. 2. Configure automated sync (EventBridge Scheduler → StartIngestionJob) at that cadence — see FS-61. 3. Set CloudWatch alarms on sync job failures. |
Medium | Failed |
111122223333 |
us-east-1 |
FS-32 |
ADVISORY: Source Attribution — Manual Review Required
Details and remediationDetails
Source attribution in GenAI responses cannot be verified via AWS APIs. Manual review required to confirm responses include citations. Resolution
1. Use Bedrock RetrieveAndGenerate with citations enabled. 2. Include source document references in response post-processing. 3. Test citation accuracy in QA before production deployment. 4. Consider Bedrock Guardrails grounding checks to validate response accuracy. |
Informational | N/A |
111122223333 |
us-east-2 |
FS-32 |
ADVISORY: Source Attribution — Manual Review Required
Details and remediationDetails
Source attribution in GenAI responses cannot be verified via AWS APIs. Manual review required to confirm responses include citations. Resolution
1. Use Bedrock RetrieveAndGenerate with citations enabled. 2. Include source document references in response post-processing. 3. Test citation accuracy in QA before production deployment. 4. Consider Bedrock Guardrails grounding checks to validate response accuracy. |
Informational | N/A |
111122223333 |
us-west-2 |
FS-32 |
ADVISORY: Source Attribution — Manual Review Required
Details and remediationDetails
Source attribution in GenAI responses cannot be verified via AWS APIs. Manual review required to confirm responses include citations. Resolution
1. Use Bedrock RetrieveAndGenerate with citations enabled. 2. Include source document references in response post-processing. 3. Test citation accuracy in QA before production deployment. 4. Consider Bedrock Guardrails grounding checks to validate response accuracy. |
Informational | N/A |
111122223333 |
us-east-1 |
FS-33 |
KB Data Source Buckets Without Versioning
|
Medium | Failed |
111122223333 |
us-east-2 |
FS-33 |
KB Data Source Buckets Without Versioning
|
Medium | Failed |
111122223333 |
us-west-2 |
FS-33 |
KB Data Source Buckets Without Versioning
|
Medium | Failed |
111122223333 |
us-east-1 |
FS-34 |
Legacy Foundation Models Available in Region
Details and remediationDetails
Legacy/deprecated foundation models are available in this account/region: anthropic.claude-sonnet-4-20250514-v1:0, twelvelabs.marengo-embed-2-7-v1:0, anthropic.claude-opus-4-1-20250805-v1:0, amazon.nova-premier-v1:0:8k, amazon.nova-premier-v1:0:20k, amazon.nova-premier-v1:0:1000k, amazon.nova-premier-v1:0:mm, amazon.nova-premier-v1:0, amazon.nova-canvas-v1:0, amazon.nova-reel-v1:0. This API reports model *availability*, not actual usage — it cannot determine which models your applications invoke. Legacy models have older training-data cutoffs and may produce outdated information if used. Review whether any are in active use. Resolution
1. Identify which (if any) of these legacy models your applications invoke (e.g., via CloudTrail InvokeModel events or application config). 2. Migrate active usage to current model versions. 3. Document training-data cutoff dates for all models in use. 4. Add data-currency disclaimers to outputs from models with old cutoffs. |
Informational | N/A |
111122223333 |
us-east-2 |
FS-34 |
Legacy Foundation Models Available in Region
Details and remediationDetails
Legacy/deprecated foundation models are available in this account/region: anthropic.claude-sonnet-4-20250514-v1:0, twelvelabs.marengo-embed-2-7-v1:0, anthropic.claude-opus-4-1-20250805-v1:0, amazon.nova-premier-v1:0:8k, amazon.nova-premier-v1:0:20k, amazon.nova-premier-v1:0:1000k, amazon.nova-premier-v1:0:mm, amazon.nova-premier-v1:0, amazon.nova-canvas-v1:0, amazon.nova-reel-v1:0. This API reports model *availability*, not actual usage — it cannot determine which models your applications invoke. Legacy models have older training-data cutoffs and may produce outdated information if used. Review whether any are in active use. Resolution
1. Identify which (if any) of these legacy models your applications invoke (e.g., via CloudTrail InvokeModel events or application config). 2. Migrate active usage to current model versions. 3. Document training-data cutoff dates for all models in use. 4. Add data-currency disclaimers to outputs from models with old cutoffs. |
Informational | N/A |
111122223333 |
us-west-2 |
FS-34 |
Legacy Foundation Models Available in Region
Details and remediationDetails
Legacy/deprecated foundation models are available in this account/region: anthropic.claude-sonnet-4-20250514-v1:0, twelvelabs.marengo-embed-2-7-v1:0, anthropic.claude-opus-4-1-20250805-v1:0, amazon.nova-premier-v1:0:8k, amazon.nova-premier-v1:0:20k, amazon.nova-premier-v1:0:1000k, amazon.nova-premier-v1:0:mm, amazon.nova-premier-v1:0, amazon.nova-canvas-v1:0, amazon.nova-reel-v1:0. This API reports model *availability*, not actual usage — it cannot determine which models your applications invoke. Legacy models have older training-data cutoffs and may produce outdated information if used. Review whether any are in active use. Resolution
1. Identify which (if any) of these legacy models your applications invoke (e.g., via CloudTrail InvokeModel events or application config). 2. Migrate active usage to current model versions. 3. Document training-data cutoff dates for all models in use. 4. Add data-currency disclaimers to outputs from models with old cutoffs. |
Informational | N/A |
111122223333 |
us-east-1 |
FS-35 |
ADVISORY: Harmful-Content Test Coverage — Manual Review Required
Details and remediationDetails
Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation/FMEval jobs include harmful-content datasets (toxicity, hate speech, violence/self-harm). Whether any evaluation jobs exist at all is assessed by FS-15. Resolution
Run Bedrock Model Evaluation or FMEval with harmful content datasets: - Toxicity detection - Hate speech classification - Violence/self-harm content |
Informational | N/A |
111122223333 |
us-east-2 |
FS-35 |
ADVISORY: Harmful-Content Test Coverage — Manual Review Required
Details and remediationDetails
Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation/FMEval jobs include harmful-content datasets (toxicity, hate speech, violence/self-harm). Whether any evaluation jobs exist at all is assessed by FS-15. Resolution
Run Bedrock Model Evaluation or FMEval with harmful content datasets: - Toxicity detection - Hate speech classification - Violence/self-harm content |
Informational | N/A |
111122223333 |
us-west-2 |
FS-35 |
ADVISORY: Harmful-Content Test Coverage — Manual Review Required
Details and remediationDetails
Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation/FMEval jobs include harmful-content datasets (toxicity, hate speech, violence/self-harm). Whether any evaluation jobs exist at all is assessed by FS-15. Resolution
Run Bedrock Model Evaluation or FMEval with harmful content datasets: - Toxicity detection - Hate speech classification - Violence/self-harm content |
Informational | N/A |
111122223333 |
us-east-1 |
FS-36 |
Guardrail Content Filters on CLASSIC Tier
Details and remediationDetails
Guardrails with content filters: nist-ai-rmf-guardrail. The following use the CLASSIC tier: nist-ai-rmf-guardrail. CLASSIC tier supports English, French, and Spanish only. The STANDARD tier (GA June 2025) provides improved contextual understanding, typographical error detection, 60+ language support, and better prompt-attack classification (distinguishes jailbreaks from prompt injection). Resolution
Consider upgrading to STANDARD tier content filters for FinServ workloads that handle multiple languages or require higher detection accuracy. STANDARD tier requires cross-region inference (crossRegionDetails.guardrailProfileArn on the guardrail). To upgrade: update the guardrail's contentPolicy.filtersConfig.contentFiltersTierConfig with tierName=STANDARD and configure a guardrail cross-region profile. |
High | Passed |
111122223333 |
us-east-2 |
FS-36 |
Guardrail Content Filters on CLASSIC Tier
Details and remediationDetails
Guardrails with content filters: nist-ai-rmf-guardrail. The following use the CLASSIC tier: nist-ai-rmf-guardrail. CLASSIC tier supports English, French, and Spanish only. The STANDARD tier (GA June 2025) provides improved contextual understanding, typographical error detection, 60+ language support, and better prompt-attack classification (distinguishes jailbreaks from prompt injection). Resolution
Consider upgrading to STANDARD tier content filters for FinServ workloads that handle multiple languages or require higher detection accuracy. STANDARD tier requires cross-region inference (crossRegionDetails.guardrailProfileArn on the guardrail). To upgrade: update the guardrail's contentPolicy.filtersConfig.contentFiltersTierConfig with tierName=STANDARD and configure a guardrail cross-region profile. |
High | Passed |
111122223333 |
us-west-2 |
FS-36 |
Guardrail Content Filters on CLASSIC Tier
Details and remediationDetails
Guardrails with content filters: nist-ai-rmf-guardrail. The following use the CLASSIC tier: nist-ai-rmf-guardrail. CLASSIC tier supports English, French, and Spanish only. The STANDARD tier (GA June 2025) provides improved contextual understanding, typographical error detection, 60+ language support, and better prompt-attack classification (distinguishes jailbreaks from prompt injection). Resolution
Consider upgrading to STANDARD tier content filters for FinServ workloads that handle multiple languages or require higher detection accuracy. STANDARD tier requires cross-region inference (crossRegionDetails.guardrailProfileArn on the guardrail). To upgrade: update the guardrail's contentPolicy.filtersConfig.contentFiltersTierConfig with tierName=STANDARD and configure a guardrail cross-region profile. |
High | Passed |
111122223333 |
us-east-1 |
FS-37 |
ADVISORY: User Feedback Mechanism — Manual Review Required
Details and remediationDetails
User feedback mechanisms for harmful outputs cannot be verified via AWS APIs. Manual review required. Resolution
1. Implement thumbs-up/down or flag-for-review UI in GenAI applications. 2. Route flagged outputs to human reviewers via SQS/SNS. 3. Log feedback to DynamoDB/S3 for model improvement. 4. Define SLAs for reviewing flagged content. |
Informational | N/A |
111122223333 |
us-east-2 |
FS-37 |
ADVISORY: User Feedback Mechanism — Manual Review Required
Details and remediationDetails
User feedback mechanisms for harmful outputs cannot be verified via AWS APIs. Manual review required. Resolution
1. Implement thumbs-up/down or flag-for-review UI in GenAI applications. 2. Route flagged outputs to human reviewers via SQS/SNS. 3. Log feedback to DynamoDB/S3 for model improvement. 4. Define SLAs for reviewing flagged content. |
Informational | N/A |
111122223333 |
us-west-2 |
FS-37 |
ADVISORY: User Feedback Mechanism — Manual Review Required
Details and remediationDetails
User feedback mechanisms for harmful outputs cannot be verified via AWS APIs. Manual review required. Resolution
1. Implement thumbs-up/down or flag-for-review UI in GenAI applications. 2. Route flagged outputs to human reviewers via SQS/SNS. 3. Log feedback to DynamoDB/S3 for model improvement. 4. Define SLAs for reviewing flagged content. |
Informational | N/A |
111122223333 |
us-east-1 |
FS-38 |
No Guardrails With Word Filters
Details and remediationDetails
Found 1 guardrail(s) but none have word/phrase filters. Profanity and prohibited financial terms may appear in outputs. Resolution
Add word filters to guardrails: - Enable AWS managed profanity list - Add custom denylist for prohibited financial terms - Add allowlist for required regulatory language |
Medium | Failed |
111122223333 |
us-east-2 |
FS-38 |
No Guardrails With Word Filters
Details and remediationDetails
Found 1 guardrail(s) but none have word/phrase filters. Profanity and prohibited financial terms may appear in outputs. Resolution
Add word filters to guardrails: - Enable AWS managed profanity list - Add custom denylist for prohibited financial terms - Add allowlist for required regulatory language |
Medium | Failed |
111122223333 |
us-west-2 |
FS-38 |
No Guardrails With Word Filters
Details and remediationDetails
Found 1 guardrail(s) but none have word/phrase filters. Profanity and prohibited financial terms may appear in outputs. Resolution
Add word filters to guardrails: - Enable AWS managed profanity list - Add custom denylist for prohibited financial terms - Add allowlist for required regulatory language |
Medium | Failed |
111122223333 |
us-east-1 |
FS-39 |
No SageMaker Clarify Bias Monitoring
Details and remediationDetails
No SageMaker Clarify model bias monitoring schedules found. Models making financial decisions (credit, insurance) may exhibit discriminatory bias without detection. Resolution
1. Configure SageMaker Clarify bias detection for all models making credit, insurance, or employment decisions. 2. Define protected attributes (age, gender, race proxies). 3. Set bias metric thresholds and alert on violations. 4. Document bias testing results for regulatory examination. |
High | Failed |
111122223333 |
us-east-2 |
FS-39 |
No SageMaker Clarify Bias Monitoring
Details and remediationDetails
No SageMaker Clarify model bias monitoring schedules found. Models making financial decisions (credit, insurance) may exhibit discriminatory bias without detection. Resolution
1. Configure SageMaker Clarify bias detection for all models making credit, insurance, or employment decisions. 2. Define protected attributes (age, gender, race proxies). 3. Set bias metric thresholds and alert on violations. 4. Document bias testing results for regulatory examination. |
High | Failed |
111122223333 |
us-west-2 |
FS-39 |
No SageMaker Clarify Bias Monitoring
Details and remediationDetails
No SageMaker Clarify model bias monitoring schedules found. Models making financial decisions (credit, insurance) may exhibit discriminatory bias without detection. Resolution
1. Configure SageMaker Clarify bias detection for all models making credit, insurance, or employment decisions. 2. Define protected attributes (age, gender, race proxies). 3. Set bias metric thresholds and alert on violations. 4. Document bias testing results for regulatory examination. |
High | Failed |
111122223333 |
us-east-1 |
FS-40 |
ADVISORY: Bias Dataset Coverage — Manual Review Required
Details and remediationDetails
Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation jobs include bias/fairness datasets (demographic parity, equal-opportunity, counterfactual fairness) for any GenAI models used in financial decisions (ECOA/Fair Housing). Whether any evaluation jobs exist at all is assessed by FS-15. Resolution
Run Bedrock Model Evaluation with bias test datasets: - Demographic parity test cases - Equal opportunity scenarios - Counterfactual fairness tests |
Informational | N/A |
111122223333 |
us-east-2 |
FS-40 |
ADVISORY: Bias Dataset Coverage — Manual Review Required
Details and remediationDetails
Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation jobs include bias/fairness datasets (demographic parity, equal-opportunity, counterfactual fairness) for any GenAI models used in financial decisions (ECOA/Fair Housing). Whether any evaluation jobs exist at all is assessed by FS-15. Resolution
Run Bedrock Model Evaluation with bias test datasets: - Demographic parity test cases - Equal opportunity scenarios - Counterfactual fairness tests |
Informational | N/A |
111122223333 |
us-west-2 |
FS-40 |
ADVISORY: Bias Dataset Coverage — Manual Review Required
Details and remediationDetails
Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation jobs include bias/fairness datasets (demographic parity, equal-opportunity, counterfactual fairness) for any GenAI models used in financial decisions (ECOA/Fair Housing). Whether any evaluation jobs exist at all is assessed by FS-15. Resolution
Run Bedrock Model Evaluation with bias test datasets: - Demographic parity test cases - Equal opportunity scenarios - Counterfactual fairness tests |
Informational | N/A |
111122223333 |
us-east-1 |
FS-41 |
No SageMaker Clarify Explainability Monitoring
Details and remediationDetails
No SageMaker Clarify explainability monitoring found. Models making adverse financial decisions may not provide required explanations (ECOA adverse action notices). Resolution
1. Configure SageMaker Clarify explainability for credit/lending models. 2. Generate SHAP values for feature importance. 3. Map top features to human-readable adverse action reason codes. 4. Store explanations for regulatory examination. |
High | Failed |
111122223333 |
us-east-2 |
FS-41 |
No SageMaker Clarify Explainability Monitoring
Details and remediationDetails
No SageMaker Clarify explainability monitoring found. Models making adverse financial decisions may not provide required explanations (ECOA adverse action notices). Resolution
1. Configure SageMaker Clarify explainability for credit/lending models. 2. Generate SHAP values for feature importance. 3. Map top features to human-readable adverse action reason codes. 4. Store explanations for regulatory examination. |
High | Failed |
111122223333 |
us-west-2 |
FS-41 |
No SageMaker Clarify Explainability Monitoring
Details and remediationDetails
No SageMaker Clarify explainability monitoring found. Models making adverse financial decisions may not provide required explanations (ECOA adverse action notices). Resolution
1. Configure SageMaker Clarify explainability for credit/lending models. 2. Generate SHAP values for feature importance. 3. Map top features to human-readable adverse action reason codes. 4. Store explanations for regulatory examination. |
High | Failed |
111122223333 |
us-east-1 |
FS-42 |
No SageMaker Model Cards Found
Details and remediationDetails
No SageMaker Model Cards found. Production AI models lack documented intended use, limitations, and bias evaluations. Resolution
1. Create SageMaker Model Cards for all production models. 2. Document: intended use, out-of-scope uses, training data, bias evaluations. 3. Include regulatory compliance attestations. 4. Review and update cards at each model version release. |
Medium | Failed |
111122223333 |
us-east-2 |
FS-42 |
No SageMaker Model Cards Found
Details and remediationDetails
No SageMaker Model Cards found. Production AI models lack documented intended use, limitations, and bias evaluations. Resolution
1. Create SageMaker Model Cards for all production models. 2. Document: intended use, out-of-scope uses, training data, bias evaluations. 3. Include regulatory compliance attestations. 4. Review and update cards at each model version release. |
Medium | Failed |
111122223333 |
us-west-2 |
FS-42 |
No SageMaker Model Cards Found
Details and remediationDetails
No SageMaker Model Cards found. Production AI models lack documented intended use, limitations, and bias evaluations. Resolution
1. Create SageMaker Model Cards for all production models. 2. Document: intended use, out-of-scope uses, training data, bias evaluations. 3. Include regulatory compliance attestations. 4. Review and update cards at each model version release. |
Medium | Failed |
111122223333 |
us-east-1 |
FS-43 |
No CloudWatch Logs Data Protection Policies
Details and remediationDetails
No CloudWatch Logs data protection policies found. PII (SSN, account numbers, credit card numbers) in Bedrock invocation logs may be stored in plaintext. Resolution
1. Create CloudWatch Logs data protection policies to mask PII. 2. Enable masking for: SSN, credit card numbers, bank account numbers, email. 3. Apply policies to Bedrock invocation log groups. 4. Test masking with synthetic PII before production deployment. |
High | Failed |
111122223333 |
us-east-2 |
FS-43 |
No CloudWatch Logs Data Protection Policies
Details and remediationDetails
No CloudWatch Logs data protection policies found. PII (SSN, account numbers, credit card numbers) in Bedrock invocation logs may be stored in plaintext. Resolution
1. Create CloudWatch Logs data protection policies to mask PII. 2. Enable masking for: SSN, credit card numbers, bank account numbers, email. 3. Apply policies to Bedrock invocation log groups. 4. Test masking with synthetic PII before production deployment. |
High | Failed |
111122223333 |
us-west-2 |
FS-43 |
No CloudWatch Logs Data Protection Policies
Details and remediationDetails
No CloudWatch Logs data protection policies found. PII (SSN, account numbers, credit card numbers) in Bedrock invocation logs may be stored in plaintext. Resolution
1. Create CloudWatch Logs data protection policies to mask PII. 2. Enable masking for: SSN, credit card numbers, bank account numbers, email. 3. Apply policies to Bedrock invocation log groups. 4. Test masking with synthetic PII before production deployment. |
High | Failed |
111122223333 |
us-east-1 |
FS-44 |
Amazon Macie Enabled
|
High | Passed |
111122223333 |
us-east-2 |
FS-44 |
Amazon Macie Enabled
|
High | Passed |
111122223333 |
us-west-2 |
FS-44 |
Amazon Macie Enabled
|
High | Passed |
111122223333 |
us-east-1 |
FS-45 |
Guardrail PII Filters Configured
|
High | Passed |
111122223333 |
us-east-2 |
FS-45 |
Guardrail PII Filters Configured
|
High | Passed |
111122223333 |
us-west-2 |
FS-45 |
Guardrail PII Filters Configured
|
High | Passed |
111122223333 |
us-east-1 |
FS-46 |
AI/ML Buckets Without Data Classification Tags
Details and remediationDetails
18 AI/ML bucket(s) without data-classification tags: 111122223333-us-east-1-kb-data-bucket, ancbedrocklogging, ancknowledgebase, aws-streaming-data-solut-outputaccesslogsbucket8b-1o7m0kb4bafm4, bedrock-agentcore-codebuild-sources-111122223333-us-east-1, bedrock-bda-us-east-1-dda43109-6557-48bb-993d-3f97126b64b4, bedrock-bda-us-east-1-logging-00719114-debd-4487-85d1-09cbc3fc8, bedrock-kb-bucket-f736570b, bedrock-video-generation-us-east-1-h5ltpm, create-customer-resources-kb-bucket-111122223333. Resolution
Tag all AI/ML data buckets with 'data-classification' key. Values: Public, Internal, Confidential, Restricted. Enforce via SCP or AWS Config rule. |
Medium | Failed |
111122223333 |
us-east-2 |
FS-46 |
AI/ML Buckets Without Data Classification Tags
Details and remediationDetails
18 AI/ML bucket(s) without data-classification tags: 111122223333-us-east-1-kb-data-bucket, ancbedrocklogging, ancknowledgebase, aws-streaming-data-solut-outputaccesslogsbucket8b-1o7m0kb4bafm4, bedrock-agentcore-codebuild-sources-111122223333-us-east-1, bedrock-bda-us-east-1-dda43109-6557-48bb-993d-3f97126b64b4, bedrock-bda-us-east-1-logging-00719114-debd-4487-85d1-09cbc3fc8, bedrock-kb-bucket-f736570b, bedrock-video-generation-us-east-1-h5ltpm, create-customer-resources-kb-bucket-111122223333. Resolution
Tag all AI/ML data buckets with 'data-classification' key. Values: Public, Internal, Confidential, Restricted. Enforce via SCP or AWS Config rule. |
Medium | Failed |
111122223333 |
us-west-2 |
FS-46 |
AI/ML Buckets Without Data Classification Tags
Details and remediationDetails
18 AI/ML bucket(s) without data-classification tags: 111122223333-us-east-1-kb-data-bucket, ancbedrocklogging, ancknowledgebase, aws-streaming-data-solut-outputaccesslogsbucket8b-1o7m0kb4bafm4, bedrock-agentcore-codebuild-sources-111122223333-us-east-1, bedrock-bda-us-east-1-dda43109-6557-48bb-993d-3f97126b64b4, bedrock-bda-us-east-1-logging-00719114-debd-4487-85d1-09cbc3fc8, bedrock-kb-bucket-f736570b, bedrock-video-generation-us-east-1-h5ltpm, create-customer-resources-kb-bucket-111122223333. Resolution
Tag all AI/ML data buckets with 'data-classification' key. Values: Public, Internal, Confidential, Restricted. Enforce via SCP or AWS Config rule. |
Medium | Failed |
111122223333 |
us-east-1 |
FS-47 |
Guardrail Grounding Thresholds Appropriate
|
High | Passed |
111122223333 |
us-east-2 |
FS-47 |
Guardrail Grounding Thresholds Appropriate
|
High | Passed |
111122223333 |
us-west-2 |
FS-47 |
Guardrail Grounding Thresholds Appropriate
|
High | Passed |
111122223333 |
us-east-1 |
FS-48 |
Active Knowledge Bases for RAG Present
|
Medium | Passed |
111122223333 |
us-east-2 |
FS-48 |
Active Knowledge Bases for RAG Present
|
Medium | Passed |
111122223333 |
us-west-2 |
FS-48 |
Active Knowledge Bases for RAG Present
|
Medium | Passed |
111122223333 |
us-east-1 |
FS-49 |
ADVISORY: Hallucination Disclaimer — Manual Review Required
Details and remediationDetails
Application-level hallucination disclaimers cannot be verified via AWS APIs. Manual review required. Resolution
1. Add disclaimers to GenAI outputs: 'AI-generated content may contain errors. Verify with authoritative sources before acting.' 2. Implement post-processing to append disclaimers. 3. Test disclaimer presence in QA before production. |
Informational | N/A |
111122223333 |
us-east-2 |
FS-49 |
ADVISORY: Hallucination Disclaimer — Manual Review Required
Details and remediationDetails
Application-level hallucination disclaimers cannot be verified via AWS APIs. Manual review required. Resolution
1. Add disclaimers to GenAI outputs: 'AI-generated content may contain errors. Verify with authoritative sources before acting.' 2. Implement post-processing to append disclaimers. 3. Test disclaimer presence in QA before production. |
Informational | N/A |
111122223333 |
us-west-2 |
FS-49 |
ADVISORY: Hallucination Disclaimer — Manual Review Required
Details and remediationDetails
Application-level hallucination disclaimers cannot be verified via AWS APIs. Manual review required. Resolution
1. Add disclaimers to GenAI outputs: 'AI-generated content may contain errors. Verify with authoritative sources before acting.' 2. Implement post-processing to append disclaimers. 3. Test disclaimer presence in QA before production. |
Informational | N/A |
111122223333 |
us-east-1 |
FS-50 |
Relevance Grounding Filters Present
|
Medium | Passed |
111122223333 |
us-east-2 |
FS-50 |
Relevance Grounding Filters Present
|
Medium | Passed |
111122223333 |
us-west-2 |
FS-50 |
Relevance Grounding Filters Present
|
Medium | Passed |
111122223333 |
us-east-1 |
FS-51 |
No Guardrails With Prompt Attack Filters
Details and remediationDetails
Found 1 guardrail(s) but none have PROMPT_ATTACK filters. Prompt injection attacks may bypass system prompts and access controls. Resolution
1. Enable PROMPT_ATTACK content filter in Bedrock Guardrails. 2. Set input filter strength to HIGH. 3. Use input tags (<amazon-bedrock-guardrails-guardContent_xyz>) to differentiate user inputs from developer-provided prompts — required for PROMPT_ATTACK filters to work correctly with InvokeModel/InvokeModelWithResponseStream. 4. Consider STANDARD tier (GA June 2025) for better jailbreak vs. injection classification and broader language support. 5. Implement application-level input sanitization as defense-in-depth. |
High | Failed |
111122223333 |
us-east-2 |
FS-51 |
No Guardrails With Prompt Attack Filters
Details and remediationDetails
Found 1 guardrail(s) but none have PROMPT_ATTACK filters. Prompt injection attacks may bypass system prompts and access controls. Resolution
1. Enable PROMPT_ATTACK content filter in Bedrock Guardrails. 2. Set input filter strength to HIGH. 3. Use input tags (<amazon-bedrock-guardrails-guardContent_xyz>) to differentiate user inputs from developer-provided prompts — required for PROMPT_ATTACK filters to work correctly with InvokeModel/InvokeModelWithResponseStream. 4. Consider STANDARD tier (GA June 2025) for better jailbreak vs. injection classification and broader language support. 5. Implement application-level input sanitization as defense-in-depth. |
High | Failed |
111122223333 |
us-west-2 |
FS-51 |
No Guardrails With Prompt Attack Filters
Details and remediationDetails
Found 1 guardrail(s) but none have PROMPT_ATTACK filters. Prompt injection attacks may bypass system prompts and access controls. Resolution
1. Enable PROMPT_ATTACK content filter in Bedrock Guardrails. 2. Set input filter strength to HIGH. 3. Use input tags (<amazon-bedrock-guardrails-guardContent_xyz>) to differentiate user inputs from developer-provided prompts — required for PROMPT_ATTACK filters to work correctly with InvokeModel/InvokeModelWithResponseStream. 4. Consider STANDARD tier (GA June 2025) for better jailbreak vs. injection classification and broader language support. 5. Implement application-level input sanitization as defense-in-depth. |
High | Failed |
111122223333 |
us-east-1 |
FS-52 |
Bedrock Lambda Functions on Deprecated Runtimes
Details and remediationDetails
Functions on deprecated runtimes: e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk, e2ebedrockrag-OSSInfraSta-OSSIndexCreationProvider-g56en9UzRjII. Deprecated runtimes may use outdated boto3/SDK versions lacking security patches. Resolution
1. Upgrade Lambda functions to a supported runtime — Python 3.12+, Node.js 22.x or 24.x, Java 21+, or .NET 8+. 2. Update boto3 to the latest version in Lambda layers (pin the version in requirements.txt and redeploy). 3. Enable Lambda runtime management controls for automatic minor-version updates (runtimeManagementConfig.updateRuntimeOn = 'Auto'). 4. Refer to https://docs.aws.amazon.com/lambda/latest/dg/lambda-runtimes.html for the authoritative list of supported and deprecated runtimes. |
Medium | Failed |
111122223333 |
us-east-2 |
FS-52 |
Bedrock Lambda Functions on Deprecated Runtimes
Details and remediationDetails
Functions on deprecated runtimes: e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk, e2ebedrockrag-OSSInfraSta-OSSIndexCreationProvider-g56en9UzRjII. Deprecated runtimes may use outdated boto3/SDK versions lacking security patches. Resolution
1. Upgrade Lambda functions to a supported runtime — Python 3.12+, Node.js 22.x or 24.x, Java 21+, or .NET 8+. 2. Update boto3 to the latest version in Lambda layers (pin the version in requirements.txt and redeploy). 3. Enable Lambda runtime management controls for automatic minor-version updates (runtimeManagementConfig.updateRuntimeOn = 'Auto'). 4. Refer to https://docs.aws.amazon.com/lambda/latest/dg/lambda-runtimes.html for the authoritative list of supported and deprecated runtimes. |
Medium | Failed |
111122223333 |
us-west-2 |
FS-52 |
Bedrock Lambda Functions on Deprecated Runtimes
Details and remediationDetails
Functions on deprecated runtimes: e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk, e2ebedrockrag-OSSInfraSta-OSSIndexCreationProvider-g56en9UzRjII. Deprecated runtimes may use outdated boto3/SDK versions lacking security patches. Resolution
1. Upgrade Lambda functions to a supported runtime — Python 3.12+, Node.js 22.x or 24.x, Java 21+, or .NET 8+. 2. Update boto3 to the latest version in Lambda layers (pin the version in requirements.txt and redeploy). 3. Enable Lambda runtime management controls for automatic minor-version updates (runtimeManagementConfig.updateRuntimeOn = 'Auto'). 4. Refer to https://docs.aws.amazon.com/lambda/latest/dg/lambda-runtimes.html for the authoritative list of supported and deprecated runtimes. |
Medium | Failed |
111122223333 |
us-east-1 |
FS-53 |
No WAF Web ACLs — Injection Rules Not Applicable
|
Informational | N/A |
111122223333 |
us-east-2 |
FS-53 |
No WAF Web ACLs — Injection Rules Not Applicable
|
Informational | N/A |
111122223333 |
us-west-2 |
FS-53 |
No WAF Web ACLs — Injection Rules Not Applicable
|
Informational | N/A |
111122223333 |
us-east-1 |
FS-54 |
ADVISORY: Penetration Testing — Manual Review Required
Details and remediationDetails
Penetration testing evidence cannot be verified via AWS APIs. Manual review required to confirm GenAI applications have been tested. Resolution
1. Conduct penetration testing of GenAI applications at least annually and before major releases. 2. Include AI-specific test cases: prompt injection, jailbreak, indirect (cross-domain) injection, system-prompt leakage, and data-extraction attempts. 3. Consider AWS Security Agent for on-demand, AI-driven penetration testing (GA March 2026; available in US East N. Virginia, US West Oregon, Europe Ireland, Europe Frankfurt, Asia Pacific Sydney, Asia Pacific Tokyo, with cross-account shared-VPC testing via AWS RAM). Open-source tools such as Garak or PyRIT and manual red-teaming are complementary options. Verify current regional availability on the AWS Security Agent page before relying on it. 4. Document findings and remediation for regulatory examination, and tag tested resources with a last-pentest-date for audit trail. 5. For DORA compliance, include GenAI in TLPT (Threat-Led Penetration Testing) scope. |
Informational | N/A |
111122223333 |
us-east-2 |
FS-54 |
ADVISORY: Penetration Testing — Manual Review Required
Details and remediationDetails
Penetration testing evidence cannot be verified via AWS APIs. Manual review required to confirm GenAI applications have been tested. Resolution
1. Conduct penetration testing of GenAI applications at least annually and before major releases. 2. Include AI-specific test cases: prompt injection, jailbreak, indirect (cross-domain) injection, system-prompt leakage, and data-extraction attempts. 3. Consider AWS Security Agent for on-demand, AI-driven penetration testing (GA March 2026; available in US East N. Virginia, US West Oregon, Europe Ireland, Europe Frankfurt, Asia Pacific Sydney, Asia Pacific Tokyo, with cross-account shared-VPC testing via AWS RAM). Open-source tools such as Garak or PyRIT and manual red-teaming are complementary options. Verify current regional availability on the AWS Security Agent page before relying on it. 4. Document findings and remediation for regulatory examination, and tag tested resources with a last-pentest-date for audit trail. 5. For DORA compliance, include GenAI in TLPT (Threat-Led Penetration Testing) scope. |
Informational | N/A |
111122223333 |
us-west-2 |
FS-54 |
ADVISORY: Penetration Testing — Manual Review Required
Details and remediationDetails
Penetration testing evidence cannot be verified via AWS APIs. Manual review required to confirm GenAI applications have been tested. Resolution
1. Conduct penetration testing of GenAI applications at least annually and before major releases. 2. Include AI-specific test cases: prompt injection, jailbreak, indirect (cross-domain) injection, system-prompt leakage, and data-extraction attempts. 3. Consider AWS Security Agent for on-demand, AI-driven penetration testing (GA March 2026; available in US East N. Virginia, US West Oregon, Europe Ireland, Europe Frankfurt, Asia Pacific Sydney, Asia Pacific Tokyo, with cross-account shared-VPC testing via AWS RAM). Open-source tools such as Garak or PyRIT and manual red-teaming are complementary options. Verify current regional availability on the AWS Security Agent page before relying on it. 4. Document findings and remediation for regulatory examination, and tag tested resources with a last-pentest-date for audit trail. 5. For DORA compliance, include GenAI in TLPT (Threat-Led Penetration Testing) scope. |
Informational | N/A |
111122223333 |
us-east-1 |
FS-55 |
No Output Validation Functions Found
Details and remediationDetails
No Lambda functions with output validation/sanitization naming found. GenAI outputs may be passed directly to downstream systems without validation. Resolution
1. Implement output validation Lambda functions in GenAI pipelines. 2. Validate output schema, length, and content before downstream use. 3. Sanitize outputs before rendering in web UIs (XSS prevention). 4. Encode outputs appropriately for the target context (HTML, SQL, JSON). |
Medium | Failed |
111122223333 |
us-east-2 |
FS-55 |
No Output Validation Functions Found
Details and remediationDetails
No Lambda functions with output validation/sanitization naming found. GenAI outputs may be passed directly to downstream systems without validation. Resolution
1. Implement output validation Lambda functions in GenAI pipelines. 2. Validate output schema, length, and content before downstream use. 3. Sanitize outputs before rendering in web UIs (XSS prevention). 4. Encode outputs appropriately for the target context (HTML, SQL, JSON). |
Medium | Failed |
111122223333 |
us-west-2 |
FS-55 |
No Output Validation Functions Found
Details and remediationDetails
No Lambda functions with output validation/sanitization naming found. GenAI outputs may be passed directly to downstream systems without validation. Resolution
1. Implement output validation Lambda functions in GenAI pipelines. 2. Validate output schema, length, and content before downstream use. 3. Sanitize outputs before rendering in web UIs (XSS prevention). 4. Encode outputs appropriately for the target context (HTML, SQL, JSON). |
Medium | Failed |
111122223333 |
us-east-1 |
FS-56 |
No WAF ACLs — XSS Prevention Not Applicable
|
Informational | N/A |
111122223333 |
us-east-2 |
FS-56 |
No WAF ACLs — XSS Prevention Not Applicable
|
Informational | N/A |
111122223333 |
us-west-2 |
FS-56 |
No WAF ACLs — XSS Prevention Not Applicable
|
Informational | N/A |
111122223333 |
us-east-1 |
FS-57 |
ADVISORY: Output Encoding — Manual Review Required
Details and remediationDetails
Output encoding practices cannot be verified via AWS APIs. Manual code review required. Resolution
1. HTML-encode GenAI outputs before rendering in web UIs. 2. Use parameterized queries when GenAI output is used in database operations. 3. JSON-encode outputs before embedding in JavaScript contexts. 4. Validate output length and format before passing to downstream APIs. |
Informational | N/A |
111122223333 |
us-east-2 |
FS-57 |
ADVISORY: Output Encoding — Manual Review Required
Details and remediationDetails
Output encoding practices cannot be verified via AWS APIs. Manual code review required. Resolution
1. HTML-encode GenAI outputs before rendering in web UIs. 2. Use parameterized queries when GenAI output is used in database operations. 3. JSON-encode outputs before embedding in JavaScript contexts. 4. Validate output length and format before passing to downstream APIs. |
Informational | N/A |
111122223333 |
us-west-2 |
FS-57 |
ADVISORY: Output Encoding — Manual Review Required
Details and remediationDetails
Output encoding practices cannot be verified via AWS APIs. Manual code review required. Resolution
1. HTML-encode GenAI outputs before rendering in web UIs. 2. Use parameterized queries when GenAI output is used in database operations. 3. JSON-encode outputs before embedding in JavaScript contexts. 4. Validate output length and format before passing to downstream APIs. |
Informational | N/A |
111122223333 |
us-east-1 |
FS-58 |
ADVISORY: Output Schema Validation — Manual Review Required
Details and remediationDetails
Found 0 Lambda function(s) whose names suggest schema/validation handling. Structured-output / JSON-schema validation of GenAI responses is an application-layer control that cannot be verified automatically — manual review required. Resolution
1. Use Bedrock structured output (response schemas) where supported. 2. Implement JSON schema validation on Lambda output processors. 3. Reject malformed outputs and return safe error responses. 4. Log schema validation failures to CloudWatch for monitoring. |
Informational | N/A |
111122223333 |
us-east-2 |
FS-58 |
ADVISORY: Output Schema Validation — Manual Review Required
Details and remediationDetails
Found 0 Lambda function(s) whose names suggest schema/validation handling. Structured-output / JSON-schema validation of GenAI responses is an application-layer control that cannot be verified automatically — manual review required. Resolution
1. Use Bedrock structured output (response schemas) where supported. 2. Implement JSON schema validation on Lambda output processors. 3. Reject malformed outputs and return safe error responses. 4. Log schema validation failures to CloudWatch for monitoring. |
Informational | N/A |
111122223333 |
us-west-2 |
FS-58 |
ADVISORY: Output Schema Validation — Manual Review Required
Details and remediationDetails
Found 0 Lambda function(s) whose names suggest schema/validation handling. Structured-output / JSON-schema validation of GenAI responses is an application-layer control that cannot be verified automatically — manual review required. Resolution
1. Use Bedrock structured output (response schemas) where supported. 2. Implement JSON schema validation on Lambda output processors. 3. Reject malformed outputs and return safe error responses. 4. Log schema validation failures to CloudWatch for monitoring. |
Informational | N/A |
111122223333 |
us-east-1 |
FS-59 |
Topic Restrictions Configured on CLASSIC Tier
Details and remediationDetails
Guardrails with topic policies: nist-ai-rmf-guardrail. The following use the CLASSIC tier: nist-ai-rmf-guardrail. CLASSIC tier supports English, French, and Spanish only; the STANDARD tier (GA June 2025) adds broader language support for off-topic detection. Resolution
For multilingual FinServ deployments, consider upgrading denied topics to the STANDARD tier (topicsTierConfig.tierName=STANDARD via UpdateGuardrail; requires a cross-region inference profile). |
Medium | Passed |
111122223333 |
us-east-2 |
FS-59 |
Topic Restrictions Configured on CLASSIC Tier
Details and remediationDetails
Guardrails with topic policies: nist-ai-rmf-guardrail. The following use the CLASSIC tier: nist-ai-rmf-guardrail. CLASSIC tier supports English, French, and Spanish only; the STANDARD tier (GA June 2025) adds broader language support for off-topic detection. Resolution
For multilingual FinServ deployments, consider upgrading denied topics to the STANDARD tier (topicsTierConfig.tierName=STANDARD via UpdateGuardrail; requires a cross-region inference profile). |
Medium | Passed |
111122223333 |
us-west-2 |
FS-59 |
Topic Restrictions Configured on CLASSIC Tier
Details and remediationDetails
Guardrails with topic policies: nist-ai-rmf-guardrail. The following use the CLASSIC tier: nist-ai-rmf-guardrail. CLASSIC tier supports English, French, and Spanish only; the STANDARD tier (GA June 2025) adds broader language support for off-topic detection. Resolution
For multilingual FinServ deployments, consider upgrading denied topics to the STANDARD tier (topicsTierConfig.tierName=STANDARD via UpdateGuardrail; requires a cross-region inference profile). |
Medium | Passed |
111122223333 |
us-east-1 |
FS-60 |
ADVISORY: Contextual Grounding for Off-Topic Prevention
Details and remediationDetails
Contextual grounding for off-topic prevention is covered by guardrail grounding checks (FS-47) and RAG configuration (FS-48). Additionally verify system prompts explicitly scope the assistant's role. Resolution
1. Include explicit scope instructions in system prompts. 2. Use Bedrock Guardrails relevance grounding filter. 3. Test with off-topic prompts in QA to verify rejection behavior. |
Informational | N/A |
111122223333 |
us-east-2 |
FS-60 |
ADVISORY: Contextual Grounding for Off-Topic Prevention
Details and remediationDetails
Contextual grounding for off-topic prevention is covered by guardrail grounding checks (FS-47) and RAG configuration (FS-48). Additionally verify system prompts explicitly scope the assistant's role. Resolution
1. Include explicit scope instructions in system prompts. 2. Use Bedrock Guardrails relevance grounding filter. 3. Test with off-topic prompts in QA to verify rejection behavior. |
Informational | N/A |
111122223333 |
us-west-2 |
FS-60 |
ADVISORY: Contextual Grounding for Off-Topic Prevention
Details and remediationDetails
Contextual grounding for off-topic prevention is covered by guardrail grounding checks (FS-47) and RAG configuration (FS-48). Additionally verify system prompts explicitly scope the assistant's role. Resolution
1. Include explicit scope instructions in system prompts. 2. Use Bedrock Guardrails relevance grounding filter. 3. Test with off-topic prompts in QA to verify rejection behavior. |
Informational | N/A |
111122223333 |
us-east-1 |
FS-61 |
No Automated KB Sync Schedules Detected
Details and remediationDetails
Found 3 Knowledge Base(s) but no EventBridge Scheduler schedules or EventBridge rules with 'bedrock'/'knowledge' naming were found. Note: this check uses a name/target heuristic — sync automation with other naming conventions, AWS Step Functions-based orchestration, or native Bedrock API-triggered syncs (StartIngestionJob called directly) will not be detected. Verify sync automation manually if applicable. Resolution
1. Use EventBridge Scheduler (the AWS-recommended approach) to create a recurring schedule (e.g., rate(1 day) or a cron expression) that triggers a Lambda function calling the Bedrock StartIngestionJob API for each data source. Classic EventBridge scheduled rules also work but are a legacy feature. 2. As of December 2024, Bedrock Knowledge Bases supports custom connectors and streaming data ingestion — use direct document ingestion (KnowledgeBaseDocuments API) for real-time updates without a full S3 sync. 3. Set sync frequency based on data currency requirements (e.g., hourly for market data, daily for regulatory guidance). 4. Configure CloudWatch alarms or SNS notifications on IngestionJob FAILED status for sync failure alerting. |
Medium | Failed |
111122223333 |
us-east-2 |
FS-61 |
No Automated KB Sync Schedules Detected
Details and remediationDetails
Found 3 Knowledge Base(s) but no EventBridge Scheduler schedules or EventBridge rules with 'bedrock'/'knowledge' naming were found. Note: this check uses a name/target heuristic — sync automation with other naming conventions, AWS Step Functions-based orchestration, or native Bedrock API-triggered syncs (StartIngestionJob called directly) will not be detected. Verify sync automation manually if applicable. Resolution
1. Use EventBridge Scheduler (the AWS-recommended approach) to create a recurring schedule (e.g., rate(1 day) or a cron expression) that triggers a Lambda function calling the Bedrock StartIngestionJob API for each data source. Classic EventBridge scheduled rules also work but are a legacy feature. 2. As of December 2024, Bedrock Knowledge Bases supports custom connectors and streaming data ingestion — use direct document ingestion (KnowledgeBaseDocuments API) for real-time updates without a full S3 sync. 3. Set sync frequency based on data currency requirements (e.g., hourly for market data, daily for regulatory guidance). 4. Configure CloudWatch alarms or SNS notifications on IngestionJob FAILED status for sync failure alerting. |
Medium | Failed |
111122223333 |
us-west-2 |
FS-61 |
No Automated KB Sync Schedules Detected
Details and remediationDetails
Found 3 Knowledge Base(s) but no EventBridge Scheduler schedules or EventBridge rules with 'bedrock'/'knowledge' naming were found. Note: this check uses a name/target heuristic — sync automation with other naming conventions, AWS Step Functions-based orchestration, or native Bedrock API-triggered syncs (StartIngestionJob called directly) will not be detected. Verify sync automation manually if applicable. Resolution
1. Use EventBridge Scheduler (the AWS-recommended approach) to create a recurring schedule (e.g., rate(1 day) or a cron expression) that triggers a Lambda function calling the Bedrock StartIngestionJob API for each data source. Classic EventBridge scheduled rules also work but are a legacy feature. 2. As of December 2024, Bedrock Knowledge Bases supports custom connectors and streaming data ingestion — use direct document ingestion (KnowledgeBaseDocuments API) for real-time updates without a full S3 sync. 3. Set sync frequency based on data currency requirements (e.g., hourly for market data, daily for regulatory guidance). 4. Configure CloudWatch alarms or SNS notifications on IngestionJob FAILED status for sync failure alerting. |
Medium | Failed |
111122223333 |
us-east-1 |
FS-62 |
ADVISORY: Data Currency Disclaimer — Manual Review Required
Details and remediationDetails
Data currency disclaimers cannot be verified via AWS APIs. Manual review required. Resolution
1. Add data currency disclaimers to GenAI outputs: 'Information based on data current as of [KB last sync date].' 2. Expose KB last sync timestamp in application responses. 3. Alert users when KB data is older than defined threshold. |
Informational | N/A |
111122223333 |
us-east-2 |
FS-62 |
ADVISORY: Data Currency Disclaimer — Manual Review Required
Details and remediationDetails
Data currency disclaimers cannot be verified via AWS APIs. Manual review required. Resolution
1. Add data currency disclaimers to GenAI outputs: 'Information based on data current as of [KB last sync date].' 2. Expose KB last sync timestamp in application responses. 3. Alert users when KB data is older than defined threshold. |
Informational | N/A |
111122223333 |
us-west-2 |
FS-62 |
ADVISORY: Data Currency Disclaimer — Manual Review Required
Details and remediationDetails
Data currency disclaimers cannot be verified via AWS APIs. Manual review required. Resolution
1. Add data currency disclaimers to GenAI outputs: 'Information based on data current as of [KB last sync date].' 2. Expose KB last sync timestamp in application responses. 3. Alert users when KB data is older than defined threshold. |
Informational | N/A |
111122223333 |
us-east-1 |
FS-63 |
Foundation Model Lifecycle Management
|
Medium | Passed |
111122223333 |
us-east-2 |
FS-63 |
Foundation Model Lifecycle Management
|
Medium | Passed |
111122223333 |
us-west-2 |
FS-63 |
Foundation Model Lifecycle Management
|
Medium | Passed |
111122223333 |
us-east-1 |
FS-65 |
KB Data Source Buckets Missing S3 Event Notifications
Details and remediationDetails
The following KB data-source S3 buckets have no event notifications configured. Unauthorized document modifications will not be detected in real time: - semiconductor-demo-9999 - 111122223333-us-east-1-kb-data-bucket Resolution
1. Enable Amazon EventBridge notifications on each KB data-source S3 bucket. 2. Create an EventBridge rule to route s3:ObjectCreated, s3:ObjectRemoved, and s3:ObjectModified events to an SNS topic or Lambda for alerting. 3. Integrate alerts into your security incident response workflow. |
Medium | Failed |
111122223333 |
us-east-2 |
FS-65 |
KB Data Source Buckets Missing S3 Event Notifications
Details and remediationDetails
The following KB data-source S3 buckets have no event notifications configured. Unauthorized document modifications will not be detected in real time: - semiconductor-demo-9999 - 111122223333-us-east-1-kb-data-bucket Resolution
1. Enable Amazon EventBridge notifications on each KB data-source S3 bucket. 2. Create an EventBridge rule to route s3:ObjectCreated, s3:ObjectRemoved, and s3:ObjectModified events to an SNS topic or Lambda for alerting. 3. Integrate alerts into your security incident response workflow. |
Medium | Failed |
111122223333 |
us-west-2 |
FS-65 |
KB Data Source Buckets Missing S3 Event Notifications
Details and remediationDetails
The following KB data-source S3 buckets have no event notifications configured. Unauthorized document modifications will not be detected in real time: - semiconductor-demo-9999 - 111122223333-us-east-1-kb-data-bucket Resolution
1. Enable Amazon EventBridge notifications on each KB data-source S3 bucket. 2. Create an EventBridge rule to route s3:ObjectCreated, s3:ObjectRemoved, and s3:ObjectModified events to an SNS topic or Lambda for alerting. 3. Integrate alerts into your security incident response workflow. |
Medium | Failed |
111122223333 |
us-east-1 |
FS-66 |
AgentCore Runtimes Missing End-User Identity Propagation
Details and remediationDetails
The following runtimes have no JWT or IAM authorizer configured for end-user identity propagation. Tool calls are authorized only by the agent execution role, not the originating user: - origami_expeditions - neoCyan_Agent - customer_support_agent - cdk_agent_core - awsapimcpserver Resolution
1. Configure a custom JWT authorizer or IAM authorizer on each AgentCore runtime. 2. Propagate the end-user's identity token to downstream tool services. 3. Ensure tool services validate the propagated identity before executing actions. 4. Do not expose propagated identity tokens to unauthorized third parties. |
High | Failed |
111122223333 |
us-east-2 |
FS-66 |
AgentCore Runtimes Missing End-User Identity Propagation
Details and remediationDetails
The following runtimes have no JWT or IAM authorizer configured for end-user identity propagation. Tool calls are authorized only by the agent execution role, not the originating user: - origami_expeditions - neoCyan_Agent - customer_support_agent - cdk_agent_core - awsapimcpserver Resolution
1. Configure a custom JWT authorizer or IAM authorizer on each AgentCore runtime. 2. Propagate the end-user's identity token to downstream tool services. 3. Ensure tool services validate the propagated identity before executing actions. 4. Do not expose propagated identity tokens to unauthorized third parties. |
High | Failed |
111122223333 |
us-west-2 |
FS-66 |
AgentCore Runtimes Missing End-User Identity Propagation
Details and remediationDetails
The following runtimes have no JWT or IAM authorizer configured for end-user identity propagation. Tool calls are authorized only by the agent execution role, not the originating user: - origami_expeditions - neoCyan_Agent - customer_support_agent - cdk_agent_core - awsapimcpserver Resolution
1. Configure a custom JWT authorizer or IAM authorizer on each AgentCore runtime. 2. Propagate the end-user's identity token to downstream tool services. 3. Ensure tool services validate the propagated identity before executing actions. 4. Do not expose propagated identity tokens to unauthorized third parties. |
High | Failed |
111122223333 |
us-east-1 |
FS-67 |
Agent Action-Group Lambdas May Lack Transaction Thresholds
Details and remediationDetails
The following agent action-group Lambda functions have no environment variables whose names suggest transaction-value threshold configuration (this is a best-effort heuristic — a threshold enforced in code or in an AgentCore Policy Engine rule would not be detected here, so treat this as a prompt for manual verification rather than a definitive gap). Without explicit limits, agents could initiate unbounded financial transactions: - aiml-security-aiml-security-111122223333-FinServAssessment - aiml-security-aiml-security-111122223333-BedrockAssessment - resco-aiml-BedrockAssessment - aiml-security-aiml-security-111122223333-AgentCoreAssessment - e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk - e2ebedrockrag-OSSInfraSta-OSSIndexCreationProvider-g56en9UzRjII - resco-aiml-AgentCoreAssessment Resolution
1. Add transaction-value threshold environment variables (e.g., MAX_TRANSACTION_AMOUNT) to each agent action-group Lambda. 2. Implement threshold enforcement logic in the Lambda handler. 3. Configure AgentCore Policy Engine rules to cap financial transaction amounts. 4. Route transactions exceeding thresholds to a human-in-the-loop approval step. |
High | Failed |
111122223333 |
us-east-2 |
FS-67 |
Agent Action-Group Lambdas May Lack Transaction Thresholds
Details and remediationDetails
The following agent action-group Lambda functions have no environment variables whose names suggest transaction-value threshold configuration (this is a best-effort heuristic — a threshold enforced in code or in an AgentCore Policy Engine rule would not be detected here, so treat this as a prompt for manual verification rather than a definitive gap). Without explicit limits, agents could initiate unbounded financial transactions: - aiml-security-aiml-security-111122223333-FinServAssessment - aiml-security-aiml-security-111122223333-BedrockAssessment - resco-aiml-BedrockAssessment - aiml-security-aiml-security-111122223333-AgentCoreAssessment - e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk - e2ebedrockrag-OSSInfraSta-OSSIndexCreationProvider-g56en9UzRjII - resco-aiml-AgentCoreAssessment Resolution
1. Add transaction-value threshold environment variables (e.g., MAX_TRANSACTION_AMOUNT) to each agent action-group Lambda. 2. Implement threshold enforcement logic in the Lambda handler. 3. Configure AgentCore Policy Engine rules to cap financial transaction amounts. 4. Route transactions exceeding thresholds to a human-in-the-loop approval step. |
High | Failed |
111122223333 |
us-west-2 |
FS-67 |
Agent Action-Group Lambdas May Lack Transaction Thresholds
Details and remediationDetails
The following agent action-group Lambda functions have no environment variables whose names suggest transaction-value threshold configuration (this is a best-effort heuristic — a threshold enforced in code or in an AgentCore Policy Engine rule would not be detected here, so treat this as a prompt for manual verification rather than a definitive gap). Without explicit limits, agents could initiate unbounded financial transactions: - aiml-security-aiml-security-111122223333-FinServAssessment - aiml-security-aiml-security-111122223333-BedrockAssessment - resco-aiml-BedrockAssessment - aiml-security-aiml-security-111122223333-AgentCoreAssessment - e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk - e2ebedrockrag-OSSInfraSta-OSSIndexCreationProvider-g56en9UzRjII - resco-aiml-AgentCoreAssessment Resolution
1. Add transaction-value threshold environment variables (e.g., MAX_TRANSACTION_AMOUNT) to each agent action-group Lambda. 2. Implement threshold enforcement logic in the Lambda handler. 3. Configure AgentCore Policy Engine rules to cap financial transaction amounts. 4. Route transactions exceeding thresholds to a human-in-the-loop approval step. |
High | Failed |
111122223333 |
us-east-1 |
FS-68 |
API Gateway Request Body Size Limits Not Enforced
Details and remediationDetails
Found 3 REST API(s) and 0 regional WAF Web ACL(s), but none enforce a maximum request-body size. Note: an API Gateway request validator does NOT cap body size (it validates the schema and required params; the REST limit is a fixed 10 MB), and a WAF body SizeConstraint only inspects the first ~16 KB of the body by default. Oversized prompts can exhaust Bedrock token quotas and inflate costs. Resolution
1. Add a maxLength (or maxItems/maxProperties) bound to the request-body JSON-Schema model used by your request validator, so oversized prompts are rejected with a 400. 2. Add a WAF SizeConstraintStatement on the request Body sized within WAF's body-inspection window (default 16 KB; raise via the web ACL AssociationConfig, or set OversizeHandling=MATCH to block bodies beyond the window), and associate the ACL with the API stage. 3. Set the max_tokens parameter in Bedrock API calls to cap output length. 4. Implement client-side token counting before submitting requests. |
Medium | Failed |
111122223333 |
us-east-2 |
FS-68 |
API Gateway Request Body Size Limits Not Enforced
Details and remediationDetails
Found 3 REST API(s) and 0 regional WAF Web ACL(s), but none enforce a maximum request-body size. Note: an API Gateway request validator does NOT cap body size (it validates the schema and required params; the REST limit is a fixed 10 MB), and a WAF body SizeConstraint only inspects the first ~16 KB of the body by default. Oversized prompts can exhaust Bedrock token quotas and inflate costs. Resolution
1. Add a maxLength (or maxItems/maxProperties) bound to the request-body JSON-Schema model used by your request validator, so oversized prompts are rejected with a 400. 2. Add a WAF SizeConstraintStatement on the request Body sized within WAF's body-inspection window (default 16 KB; raise via the web ACL AssociationConfig, or set OversizeHandling=MATCH to block bodies beyond the window), and associate the ACL with the API stage. 3. Set the max_tokens parameter in Bedrock API calls to cap output length. 4. Implement client-side token counting before submitting requests. |
Medium | Failed |
111122223333 |
us-west-2 |
FS-68 |
API Gateway Request Body Size Limits Not Enforced
Details and remediationDetails
Found 3 REST API(s) and 0 regional WAF Web ACL(s), but none enforce a maximum request-body size. Note: an API Gateway request validator does NOT cap body size (it validates the schema and required params; the REST limit is a fixed 10 MB), and a WAF body SizeConstraint only inspects the first ~16 KB of the body by default. Oversized prompts can exhaust Bedrock token quotas and inflate costs. Resolution
1. Add a maxLength (or maxItems/maxProperties) bound to the request-body JSON-Schema model used by your request validator, so oversized prompts are rejected with a 400. 2. Add a WAF SizeConstraintStatement on the request Body sized within WAF's body-inspection window (default 16 KB; raise via the web ACL AssociationConfig, or set OversizeHandling=MATCH to block bodies beyond the window), and associate the ACL with the API stage. 3. Set the max_tokens parameter in Bedrock API calls to cap output length. 4. Implement client-side token counting before submitting requests. |
Medium | Failed |
111122223333 |
us-east-1 |
FS-69 |
Prompt Input Validation Functions Present
Details and remediationDetails
Found 3 Lambda function(s) with input validation/sanitization naming patterns: resco-aiml-CleanupBucket, visa-bulletin-tracker-prod-cleanup, aiml-security-aiml-security-111122223333-CleanupBucket. Resolution
Review these functions to confirm they cover: special-character stripping, format validation, size limits, and injection-sequence detection. |
Medium | Passed |
111122223333 |
us-east-2 |
FS-69 |
Prompt Input Validation Functions Present
Details and remediationDetails
Found 3 Lambda function(s) with input validation/sanitization naming patterns: resco-aiml-CleanupBucket, visa-bulletin-tracker-prod-cleanup, aiml-security-aiml-security-111122223333-CleanupBucket. Resolution
Review these functions to confirm they cover: special-character stripping, format validation, size limits, and injection-sequence detection. |
Medium | Passed |
111122223333 |
us-west-2 |
FS-69 |
Prompt Input Validation Functions Present
Details and remediationDetails
Found 3 Lambda function(s) with input validation/sanitization naming patterns: resco-aiml-CleanupBucket, visa-bulletin-tracker-prod-cleanup, aiml-security-aiml-security-111122223333-CleanupBucket. Resolution
Review these functions to confirm they cover: special-character stripping, format validation, size limits, and injection-sequence detection. |
Medium | Passed |
111122223333 |
eu-west-1 |
FS-00 |
FinServ Regional Scope Not Applicable
|
Informational | N/A |
111122223333 |
us-east-2 |
AC-01 |
AgentCore VPC Configuration Check
|
Informational | N/A |
111122223333 |
us-east-2 |
AC-04 |
AgentCore Observability Check
|
Informational | N/A |
111122223333 |
us-east-2 |
AC-05 |
AgentCore Encryption Check
|
Informational | N/A |
111122223333 |
us-east-2 |
AC-06 |
AgentCore Browser Tool Recording Check
|
Informational | N/A |
111122223333 |
us-east-2 |
AC-07 |
AgentCore Memory Configuration Check
|
Informational | N/A |
111122223333 |
us-east-2 |
AC-13 |
AgentCore Gateway Configuration Check
|
Informational | N/A |
111122223333 |
us-east-2 |
AC-08 |
AgentCore VPC Endpoints Check
|
Informational | N/A |
111122223333 |
us-east-2 |
AC-10 |
AgentCore Resource-Based Policies Check
|
Informational | N/A |
111122223333 |
us-east-2 |
AC-11 |
AgentCore Policy Engine Encryption Check
|
Informational | N/A |
111122223333 |
us-east-2 |
AC-12 |
AgentCore Gateway Encryption Check
|
Informational | N/A |
111122223333 |
us-east-2 |
AG-24 |
Agentic AI Gateway Inbound Authorization
|
Informational | N/A |
111122223333 |
us-east-2 |
AG-25 |
Agentic AI Gateway Tool Policy Enforcement
|
Informational | N/A |
111122223333 |
us-east-2 |
AG-26 |
Agentic AI Gateway Error Detail Exposure
|
Informational | N/A |
111122223333 |
us-east-2 |
AG-27 |
Agentic AI Gateway WAF Protection
|
Informational | N/A |
111122223333 |
us-east-2 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-19 |
Agentic AI Memory Data Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found Resolution
Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-20 |
Agentic AI Private AgentCore Connectivity
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found Resolution
Create required VPC endpoints for AgentCore services and validate endpoint availability. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-21 |
Agentic AI Resource Policy Boundary
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies Resolution
Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-22 |
Agentic AI Policy Engine Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found Resolution
Configure policy engines with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-23 |
Agentic AI Gateway Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found Resolution
Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
111122223333 |
us-west-2 |
AC-01 |
AgentCore VPC Configuration Check
|
Informational | N/A |
111122223333 |
us-west-2 |
AC-04 |
AgentCore Observability Check
|
Informational | N/A |
111122223333 |
us-west-2 |
AC-05 |
AgentCore Encryption Check
|
Informational | N/A |
111122223333 |
us-west-2 |
AC-06 |
AgentCore Browser Tool Recording Check
|
Informational | N/A |
111122223333 |
us-west-2 |
AC-07 |
AgentCore Memory Configuration Check
|
Informational | N/A |
111122223333 |
us-west-2 |
AC-13 |
AgentCore Gateway Configuration Check
|
Medium | Passed |
111122223333 |
us-west-2 |
AC-08 |
AgentCore VPC Endpoints Check
|
Informational | N/A |
111122223333 |
us-west-2 |
AC-10 |
AgentCore Resource-Based Policies Missing
Details and remediationDetails
The following AgentCore resources do not have resource-based policies: Gateway 'aws-news-mcp'. Without RBPs, access control relies solely on identity-based policies. Resolution
Attach resource-based policies to AgentCore resources to: 1. Implement defense-in-depth access control 2. Enable cross-account access control 3. Restrict access based on source VPC or IP 4. Implement hierarchical authorization for Agent Runtimes |
High | Failed |
111122223333 |
us-west-2 |
AC-11 |
AgentCore Policy Engine Encryption Check
|
Informational | N/A |
111122223333 |
us-west-2 |
AC-12 |
AgentCore Gateway Encryption Missing
Details and remediationDetails
The following Gateways do not use customer-managed KMS encryption: 'aws-news-mcp'. Gateway configuration data uses AWS-managed keys. Resolution
1. Create gateways with customer-managed KMS keys for additional control 2. AWS-managed keys are single-tenant and region-specific 3. Consider CMK for enhanced audit capabilities and key rotation control |
Low | Failed |
111122223333 |
us-west-2 |
AG-24 |
Agentic AI Gateway Inbound Authorization
|
High | Passed |
111122223333 |
us-west-2 |
AG-25 |
Agentic AI Gateway Tool Policy Enforcement Missing
Details and remediation |
High | Failed |
111122223333 |
us-west-2 |
AG-26 |
Agentic AI Gateway Error Detail Exposure
|
Medium | Passed |
111122223333 |
us-west-2 |
AG-27 |
Agentic AI Gateway WAF Protection Missing
|
Low | Failed |
111122223333 |
us-west-2 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
Informational | N/A |
111122223333 |
us-west-2 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Informational | N/A |
111122223333 |
us-west-2 |
AG-19 |
Agentic AI Memory Data Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found Resolution
Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions. |
Informational | N/A |
111122223333 |
us-west-2 |
AG-20 |
Agentic AI Private AgentCore Connectivity
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found Resolution
Create required VPC endpoints for AgentCore services and validate endpoint availability. |
Informational | N/A |
111122223333 |
us-west-2 |
AG-21 |
Agentic AI Resource Policy Boundary
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: The following AgentCore resources do not have resource-based policies: Gateway 'aws-news-mcp'. Without RBPs, access control relies solely on identity-based policies. Resolution
Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources. |
High | Failed |
111122223333 |
us-west-2 |
AG-22 |
Agentic AI Policy Engine Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found Resolution
Configure policy engines with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
111122223333 |
us-west-2 |
AG-23 |
Agentic AI Gateway Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: The following Gateways do not use customer-managed KMS encryption: 'aws-news-mcp'. Gateway configuration data uses AWS-managed keys. Resolution
Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required. |
Low | Failed |
111122223333 |
us-east-2 |
OW-01 |
OWASP LLM01: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis. |
Informational | N/A |
111122223333 |
us-east-2 |
OW-07 |
OWASP LLM07: Model Invocation Logging
Details and remediation |
Informational | N/A |
111122223333 |
us-east-2 |
OW-07 |
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident. |
Informational | N/A |
111122223333 |
us-east-2 |
OW-07 |
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-09 |
OWASP LLM09: Model Evaluation Jobs
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-06 |
OWASP LLM06: Agent Action-Group Least Privilege
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-10 |
OWASP LLM10: Service Quota Throttling Limits
Details and remediation |
Informational | N/A |
111122223333 |
us-east-2 |
OW-01 |
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier. |
Informational | N/A |
111122223333 |
us-east-2 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-02 |
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation |
Informational | N/A |
111122223333 |
us-east-2 |
OW-01 |
OWASP LLM01: Contextual Grounding Guardrail
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-04 |
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation |
Informational | N/A |
111122223333 |
us-east-2 |
OW-09 |
OWASP LLM09: Contextual Grounding for Faithfulness
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-06 |
OWASP LLM06: Bedrock Agent Guardrail Association
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-06 |
OWASP LLM06: Agent Idle Session TTL
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-03 |
OWASP LLM03: Imported-Model KMS Provenance
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-10 |
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation |
Informational | N/A |
111122223333 |
us-east-2 |
OW-03 |
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check BR-33: No Lambda functions with Bedrock indicators were found in us-east-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain. |
Informational | N/A |
111122223333 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker Internet Exposure
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-01: No SageMaker notebook instances or domains found to check Resolution
Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths. |
Informational | N/A |
111122223333 |
us-east-2 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: Training Job 'xgboost-2021-12-19-01-07-45-798' - No output encryption configured Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
High | Failed |
111122223333 |
us-east-2 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: Training Job 'xgboost-2021-12-19-01-07-45-798' - Inter-container traffic encryption not enabled Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
Medium | Failed |
111122223333 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Clarify Evaluation
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation |
Informational | N/A |
111122223333 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Model Monitor Coverage
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker Notebook VPC Deployment
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker Model Network Isolation
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-11: Model 'xgboost-2021-12-19-01-25-44-527' does not have network isolation enabled. Model containers can make outbound network calls, potentially exfiltrating data. Resolution
Enable network isolation on SageMaker models so inference containers cannot make unmanaged outbound calls that alter dependencies or exfiltrate model artifacts. |
High | Failed |
111122223333 |
us-east-2 |
OW-10 |
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check SM-11: Model 'xgboost-2021-12-19-01-25-44-527' does not have network isolation enabled. Model containers can make outbound network calls, potentially exfiltrating data. Resolution
Enable SageMaker model network isolation to prevent deployed model containers from making uncontrolled outbound calls that can amplify consumption or abuse downstream services. |
High | Failed |
111122223333 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker Container Repository Access
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-14: Model 'xgboost-2021-12-19-01-25-44-527' uses Platform repository access mode. Container images are pulled from public/external registries, exposing supply chain risks. Resolution
Configure SageMaker models to pull container images from private ECR repositories through VPC repository access instead of platform or public registry paths. |
Medium | Failed |
111122223333 |
us-east-2 |
OW-02 |
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation |
Informational | N/A |
111122223333 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker AutoML Network Isolation
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically. |
Informational | N/A |
111122223333 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release. |
Informational | N/A |
111122223333 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
111122223333 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
111122223333 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain. |
Informational | N/A |
111122223333 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated. |
Informational | N/A |
111122223333 |
us-east-2 |
OW-06 |
OWASP LLM06: AgentCore Resource-Based Policies
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-11 |
OWASP LLM07: System Prompt Embedded in Lambda Env Var
|
Medium | Passed |
111122223333 |
us-east-2 |
OW-12 |
OWASP LLM07: System-Prompt-Disclosure Denied Topic
|
Informational | N/A |
111122223333 |
us-west-2 |
OW-01 |
OWASP LLM01: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: Model invocation logging is not enabled. This limits your ability to track and audit model usage. Resolution
Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis. |
Medium | Failed |
111122223333 |
us-west-2 |
OW-07 |
OWASP LLM07: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-04: Model invocation logging is not enabled. This limits your ability to track and audit model usage. Resolution
Enable Bedrock model invocation logging so prompt-extraction attempts against the system prompt are auditable after the fact. |
Medium | Failed |
111122223333 |
us-west-2 |
OW-07 |
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident. |
Informational | N/A |
111122223333 |
us-west-2 |
OW-07 |
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-16: Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) is using the 'CLASSIC' content-filter tier instead of 'STANDARD'. The STANDARD tier provides more robust content filtering and broader language support than the CLASSIC tier. Resolution
Set guardrail contentPolicy.tier.tierName to STANDARD; Standard tier additionally detects prompt-leakage attacks. |
Medium | Failed |
111122223333 |
us-west-2 |
OW-09 |
OWASP LLM09: Model Evaluation Jobs
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check BR-18: No Bedrock model evaluation jobs found. Model evaluation helps assess toxicity, accuracy, semantic robustness, and other safety metrics before production deployment. Resolution
Run Bedrock model evaluation jobs that include correctness and safety datasets. |
Medium | Failed |
111122223333 |
us-west-2 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: Knowledge base 'knowledge-base-bedrock-agent' (ID: XSPYLN4FQL) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption. |
Informational | N/A |
111122223333 |
us-west-2 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: Knowledge base 'IDP-DOCUMENTBEDROCKKB-CY8N0Q7N4YDT' (ID: SUGAG7RGYD) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption. |
Informational | N/A |
111122223333 |
us-west-2 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: Knowledge base 'promptfoo-rag-workshop-111122223333-kb' (ID: N74ZIKTUFL) uses 'RDS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption. |
Informational | N/A |
111122223333 |
us-west-2 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: Knowledge base 'InvestmentResearchKB' (ID: M1GMUG3BP0) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption. |
Informational | N/A |
111122223333 |
us-west-2 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: Knowledge base 'knowledge-base-quick-start-xtwwd' (ID: ENFHSBBLMV) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption. |
Informational | N/A |
111122223333 |
us-west-2 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: Knowledge base 'kb-s3-vector-store' (ID: 116IXQU5VP) uses 'S3_VECTORS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption. |
Informational | N/A |
111122223333 |
us-west-2 |
OW-06 |
OWASP LLM06: Agent Action-Group Least Privilege
|
Informational | N/A |
111122223333 |
us-west-2 |
OW-10 |
OWASP LLM10: Service Quota Throttling Limits
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-22: 7 custom throttling quotas are configured. Regular quota review helps maintain appropriate rate limits. Resolution
Customise Bedrock TPM / RPM service quotas above the account default to establish an explicit consumption ceiling. |
Low | Passed |
111122223333 |
us-west-2 |
OW-01 |
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) is missing content filters: INSULTS, HATE, SEXUAL, VIOLENCE. Complete content filter coverage is essential for comprehensive content safety. Resolution
Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier. |
High | Failed |
111122223333 |
us-west-2 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: Knowledge base 'knowledge-base-bedrock-agent' (ID: XSPYLN4FQL) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context. |
Low | Failed |
111122223333 |
us-west-2 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check BR-25: Knowledge base 'knowledge-base-bedrock-agent' (ID: XSPYLN4FQL) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates. |
Low | Failed |
111122223333 |
us-west-2 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: Knowledge base 'IDP-DOCUMENTBEDROCKKB-CY8N0Q7N4YDT' (ID: SUGAG7RGYD) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context. |
Low | Failed |
111122223333 |
us-west-2 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check BR-25: Knowledge base 'IDP-DOCUMENTBEDROCKKB-CY8N0Q7N4YDT' (ID: SUGAG7RGYD) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates. |
Low | Failed |
111122223333 |
us-west-2 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: Knowledge base 'promptfoo-rag-workshop-111122223333-kb' (ID: N74ZIKTUFL) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context. |
Low | Failed |
111122223333 |
us-west-2 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check BR-25: Knowledge base 'promptfoo-rag-workshop-111122223333-kb' (ID: N74ZIKTUFL) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates. |
Low | Failed |
111122223333 |
us-west-2 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: Knowledge base 'InvestmentResearchKB' (ID: M1GMUG3BP0) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context. |
Low | Failed |
111122223333 |
us-west-2 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check BR-25: Knowledge base 'InvestmentResearchKB' (ID: M1GMUG3BP0) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates. |
Low | Failed |
111122223333 |
us-west-2 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: Knowledge base 'knowledge-base-quick-start-xtwwd' (ID: ENFHSBBLMV) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context. |
Low | Failed |
111122223333 |
us-west-2 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check BR-25: Knowledge base 'knowledge-base-quick-start-xtwwd' (ID: ENFHSBBLMV) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates. |
Low | Failed |
111122223333 |
us-west-2 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: Knowledge base 'kb-s3-vector-store' (ID: 116IXQU5VP) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context. |
Low | Failed |
111122223333 |
us-west-2 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check BR-25: Knowledge base 'kb-s3-vector-store' (ID: 116IXQU5VP) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates. |
Low | Failed |
111122223333 |
us-west-2 |
OW-02 |
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check BR-26: Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) has no sensitive-information filters configured (no PII entities or regex patterns). Prompts and model responses are not screened for sensitive data such as PII. Resolution
Configure guardrail sensitiveInformationPolicy with PII entities and regex patterns; set outputAction=ANONYMIZE or BLOCK. |
High | Failed |
111122223333 |
us-west-2 |
OW-01 |
OWASP LLM01: Contextual Grounding Guardrail
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-27: Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) does not have contextual grounding checks enabled. Without grounding and relevance checks, the guardrail cannot detect hallucinated (ungrounded) or off-topic model responses. Resolution
Enable Bedrock guardrail contextual grounding checks to reduce the surface for indirect prompt injection through retrieved context. |
Medium | Failed |
111122223333 |
us-west-2 |
OW-04 |
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-27: Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) does not have contextual grounding checks enabled. Without grounding and relevance checks, the guardrail cannot detect hallucinated (ungrounded) or off-topic model responses. Resolution
Enable contextual grounding guardrail filters so retrieved context that diverges from ground truth is filtered before reaching the model. |
Medium | Failed |
111122223333 |
us-west-2 |
OW-09 |
OWASP LLM09: Contextual Grounding for Faithfulness
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check BR-27: Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) does not have contextual grounding checks enabled. Without grounding and relevance checks, the guardrail cannot detect hallucinated (ungrounded) or off-topic model responses. Resolution
Set the contextual grounding filter threshold to at least 0.70 to reduce hallucinated responses. |
Medium | Failed |
111122223333 |
us-west-2 |
OW-06 |
OWASP LLM06: Bedrock Agent Guardrail Association
|
Informational | N/A |
111122223333 |
us-west-2 |
OW-06 |
OWASP LLM06: Agent Idle Session TTL
|
Informational | N/A |
111122223333 |
us-west-2 |
OW-03 |
OWASP LLM03: Imported-Model KMS Provenance
|
Informational | N/A |
111122223333 |
us-west-2 |
OW-10 |
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-32: No CloudWatch alarms are configured on Amazon Bedrock runtime metrics (AWS/Bedrock namespace). Without alarms, abuse, denial-of-wallet, sustained throttling, and content-filter spikes can go undetected. Resolution
Create CloudWatch alarms on Bedrock InvocationThrottles, InputTokenCount, OutputTokenCount, and EstimatedTPMQuotaUsage. |
Medium | Failed |
111122223333 |
us-west-2 |
OW-03 |
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check BR-33: Amazon Inspector Lambda scanning is not fully enabled in us-west-2. Lambda standard scan status: DISABLED. Lambda code scan status: DISABLED. Detected 6 Lambda function(s) with Bedrock indicators: IDP-DOCUMENTBEDROCKKB-CY8-GetAdjustedStackNameFunc-MFYZSG0nWqdj, IDP-DOCUMENTBEDROCKKB-CY8-StartIngestionJobFunctio-QGtm6KrDTRYu, IDP-DOCUMENTBEDROCKKB-CY8N0Q7N-GetSeedUrlsFunction-vCBSeTw4AdDV, IDP-PATTERN1STACK-TNHNKPKJY-ProcessResultsFunction-xLOdarbvGDm7, IDP-QueryKnowledgeBaseResolverFunction-tkmkVZ4lgxf8 (and 1 more). Without both scan types enabled, vulnerable dependencies and hardcoded secrets in these in-scope functions will not be detected. Resolution
Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain. |
Medium | Failed |
111122223333 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker Internet Exposure
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-01: SageMaker domain 'd-krxh4fmtaxjl' (PromptEvaluationDomain) is not configured for VPC-only access Resolution
Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths. |
High | Failed |
111122223333 |
us-west-2 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: Domain 'PromptEvaluationDomain' - No KMS key configured Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
High | Failed |
111122223333 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Clarify Evaluation
|
Informational | N/A |
111122223333 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation |
Informational | N/A |
111122223333 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Model Monitor Coverage
|
Informational | N/A |
111122223333 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker Notebook VPC Deployment
|
Informational | N/A |
111122223333 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker Model Network Isolation
|
Informational | N/A |
111122223333 |
us-west-2 |
OW-10 |
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation |
Informational | N/A |
111122223333 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker Container Repository Access
Details and remediation |
Informational | N/A |
111122223333 |
us-west-2 |
OW-02 |
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation |
Informational | N/A |
111122223333 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker AutoML Network Isolation
|
Informational | N/A |
111122223333 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically. |
Informational | N/A |
111122223333 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release. |
Informational | N/A |
111122223333 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
111122223333 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
111122223333 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain. |
Informational | N/A |
111122223333 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated. |
Informational | N/A |
111122223333 |
us-west-2 |
OW-06 |
OWASP LLM06: AgentCore Resource-Based Policies
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check AC-10: The following AgentCore resources do not have resource-based policies: Gateway 'aws-news-mcp'. Without RBPs, access control relies solely on identity-based policies. Resolution
Attach resource-based policies to AgentCore runtimes and gateways so caller identities are constrained. |
High | Failed |
111122223333 |
us-west-2 |
OW-11 |
OWASP LLM07: System Prompt Embedded in Lambda Env Var
|
Medium | Passed |
111122223333 |
us-west-2 |
OW-12 |
OWASP LLM07: System-Prompt-Disclosure Denied Topic
Details and remediationDetails
No Bedrock guardrail in us-west-2 has a DENY topic covering system-prompt disclosure. Attackers can craft prompts that ask the agent to reveal its system prompt or instructions. Resolution
Add a DENY topic to at least one guardrail. Suggested topic name: 'SystemPromptDisclosure'. Suggested definition: 'Requests to reveal, describe, or summarise the system prompt, instructions, or internal role definition given to the assistant.' |
Medium | Failed |
111122223333 |
us-west-2 |
BR-02 |
Amazon Bedrock private connectivity not used
Details and remediationDetails
No Bedrock service VPC endpoints found in VPCs: vpc-0f85a6754ab37efb7, vpc-5c3b6524, vpc-03bcafcb58a3029fc Resolution
Create a VPC endpoint in your VPC with any of the following Bedrock service endpoints that your application may be using: - com.amazonaws.region.bedrock - com.amazonaws.region.bedrock-runtime - com.amazonaws.region.bedrock-agent - com.amazonaws.region.bedrock-agent-runtime |
Medium | Failed |
111122223333 |
us-west-2 |
BR-04 |
Bedrock Model Invocation Logging Check
Details and remediationDetails
Model invocation logging is not enabled. This limits your ability to track and audit model usage. Resolution
Enable model invocation logging to collect invocation logs, model input data, and model output data. Configure logging to deliver to Amazon S3, CloudWatch Logs, or both for comprehensive monitoring. |
Medium | Failed |
111122223333 |
us-west-2 |
BR-05 |
Bedrock Guardrails Check
|
High | Passed |
111122223333 |
us-west-2 |
BR-06 |
Bedrock CloudTrail Logging Check
|
Medium | Passed |
111122223333 |
us-west-2 |
BR-07 |
Bedrock Prompt Management Check
Details and remediationDetails
Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates |
Informational | N/A |
111122223333 |
us-west-2 |
BR-08 |
Bedrock Agent IAM Roles Check
|
Informational | N/A |
111122223333 |
us-west-2 |
BR-09 |
Bedrock Knowledge Base Encryption Review
Details and remediationDetails
Knowledge Base 'knowledge-base-bedrock-agent' (XSPYLN4FQL) uses 'OPENSEARCH_SERVERLESS' storage. Encryption is managed at the storage layer and cannot be validated from the KB API. Verify encryption configuration on the underlying storage resource. Resolution
1. For OpenSearch Serverless: Verify encryption with CMK at collection level 2. For S3 data sources: Verify CMK-encrypted S3 buckets 3. For RDS: Verify KMS encryption on the database 4. Consider using CMK for transient data during ingestion |
Informational | N/A |
111122223333 |
us-west-2 |
BR-09 |
Bedrock Knowledge Base Encryption Review
Details and remediationDetails
Knowledge Base 'IDP-DOCUMENTBEDROCKKB-CY8N0Q7N4YDT' (SUGAG7RGYD) uses 'OPENSEARCH_SERVERLESS' storage. Encryption is managed at the storage layer and cannot be validated from the KB API. Verify encryption configuration on the underlying storage resource. Resolution
1. For OpenSearch Serverless: Verify encryption with CMK at collection level 2. For S3 data sources: Verify CMK-encrypted S3 buckets 3. For RDS: Verify KMS encryption on the database 4. Consider using CMK for transient data during ingestion |
Informational | N/A |
111122223333 |
us-west-2 |
BR-09 |
Bedrock Knowledge Base Encryption Review
Details and remediationDetails
Knowledge Base 'promptfoo-rag-workshop-111122223333-kb' (N74ZIKTUFL) uses 'RDS' storage. Encryption is managed at the storage layer and cannot be validated from the KB API. Verify encryption configuration on the underlying storage resource. Resolution
1. For OpenSearch Serverless: Verify encryption with CMK at collection level 2. For S3 data sources: Verify CMK-encrypted S3 buckets 3. For RDS: Verify KMS encryption on the database 4. Consider using CMK for transient data during ingestion |
Informational | N/A |
111122223333 |
us-west-2 |
BR-09 |
Bedrock Knowledge Base Encryption Review
Details and remediationDetails
Knowledge Base 'InvestmentResearchKB' (M1GMUG3BP0) uses 'OPENSEARCH_SERVERLESS' storage. Encryption is managed at the storage layer and cannot be validated from the KB API. Verify encryption configuration on the underlying storage resource. Resolution
1. For OpenSearch Serverless: Verify encryption with CMK at collection level 2. For S3 data sources: Verify CMK-encrypted S3 buckets 3. For RDS: Verify KMS encryption on the database 4. Consider using CMK for transient data during ingestion |
Informational | N/A |
111122223333 |
us-west-2 |
BR-09 |
Bedrock Knowledge Base Encryption Review
Details and remediationDetails
Knowledge Base 'knowledge-base-quick-start-xtwwd' (ENFHSBBLMV) uses 'OPENSEARCH_SERVERLESS' storage. Encryption is managed at the storage layer and cannot be validated from the KB API. Verify encryption configuration on the underlying storage resource. Resolution
1. For OpenSearch Serverless: Verify encryption with CMK at collection level 2. For S3 data sources: Verify CMK-encrypted S3 buckets 3. For RDS: Verify KMS encryption on the database 4. Consider using CMK for transient data during ingestion |
Informational | N/A |
111122223333 |
us-west-2 |
BR-09 |
Bedrock Knowledge Base Encryption Review
Details and remediationDetails
Knowledge Base 'kb-s3-vector-store' (116IXQU5VP) uses 'S3_VECTORS' storage. Encryption is managed at the storage layer and cannot be validated from the KB API. Verify encryption configuration on the underlying storage resource. Resolution
1. For OpenSearch Serverless: Verify encryption with CMK at collection level 2. For S3 data sources: Verify CMK-encrypted S3 buckets 3. For RDS: Verify KMS encryption on the database 4. Consider using CMK for transient data during ingestion |
Informational | N/A |
111122223333 |
us-west-2 |
BR-10 |
Bedrock Guardrail IAM Enforcement Missing
Details and remediationDetails
The following roles can invoke Bedrock models without enforced guardrails: 111122223333-us-east-1-kb-bedrock-service-role, agentcore-wildrydes_gateway_role_ab3991f6-role, AgentCoreEvalsSDK-us-east-1-d04ba7b68b, AmazonBedrockAgentCoreSDKRuntime-us-east-1-a6ddf3fc76, AmazonBedrockAgentCoreSDKRuntime-us-east-1-ed660add8b, AmazonBedrockExecutionRoleForAgents_S0T9VNPP9D, AmazonBedrockExecutionRoleForAgents_WNCOPE29NZ, AmazonBedrockExecutionRoleForKnowledgeBase_072pr, AmazonBedrockExecutionRoleForKnowledgeBase_byjin, AmazonBedrockExecutionRoleForKnowledgeBase_h9718... Resolution
Add IAM policy conditions to enforce guardrail usage: 1. Use 'bedrock:GuardrailIdentifier' condition key 2. Specify required guardrail ARN or ID 3. Example: "Condition": {"StringEquals": {"bedrock:GuardrailIdentifier": "arn:aws:bedrock:region:account:guardrail/guardrail-id"}} |
High | Failed |
111122223333 |
us-west-2 |
BR-11 |
Bedrock Custom Model Encryption Check
|
Informational | N/A |
111122223333 |
us-west-2 |
BR-12 |
Bedrock Invocation Log Encryption Check
|
Informational | N/A |
111122223333 |
us-west-2 |
BR-13 |
Bedrock Flows Guardrails Check
|
Informational | N/A |
111122223333 |
us-west-2 |
BR-16 |
Guardrail Tier Validation Check
Details and remediationDetails
Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) is using the 'CLASSIC' content-filter tier instead of 'STANDARD'. The STANDARD tier provides more robust content filtering and broader language support than the CLASSIC tier. Resolution
Update the guardrail to use the STANDARD content-filter tier for improved contextual understanding, better prompt attack filtering (distinguishing jailbreaks from prompt injection), and broader language support. The STANDARD tier requires cross-Region inference. Review pricing implications before upgrading. |
Medium | Failed |
111122223333 |
us-west-2 |
BR-17 |
Custom Model Customer-Managed KMS Encryption Check
|
High | N/A |
111122223333 |
us-west-2 |
BR-18 |
Model Evaluation Implementation Check
Details and remediationDetails
No Bedrock model evaluation jobs found. Model evaluation helps assess toxicity, accuracy, semantic robustness, and other safety metrics before production deployment. Resolution
Create model evaluation jobs using Amazon Bedrock Evaluations to assess foundation model performance against safety and quality metrics. Use built-in datasets or custom test sets. Enable LLM-as-a-judge evaluation for comprehensive assessment. |
Medium | Failed |
111122223333 |
us-west-2 |
BR-19 |
Prompt Flow Validation Check
|
Medium | N/A |
111122223333 |
us-west-2 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Review
Details and remediationDetails
Knowledge base 'knowledge-base-bedrock-agent' (ID: XSPYLN4FQL) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
1. For OpenSearch Serverless: verify the collection uses a customer-managed KMS key 2. For Amazon RDS/Aurora: verify KMS encryption on the database 3. For third-party stores (Pinecone, Redis, MongoDB): verify the provider's encryption configuration 4. Verify the customer-managed KMS key used for transient data during ingestion |
Informational | N/A |
111122223333 |
us-west-2 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Review
Details and remediationDetails
Knowledge base 'IDP-DOCUMENTBEDROCKKB-CY8N0Q7N4YDT' (ID: SUGAG7RGYD) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
1. For OpenSearch Serverless: verify the collection uses a customer-managed KMS key 2. For Amazon RDS/Aurora: verify KMS encryption on the database 3. For third-party stores (Pinecone, Redis, MongoDB): verify the provider's encryption configuration 4. Verify the customer-managed KMS key used for transient data during ingestion |
Informational | N/A |
111122223333 |
us-west-2 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Review
Details and remediationDetails
Knowledge base 'promptfoo-rag-workshop-111122223333-kb' (ID: N74ZIKTUFL) uses 'RDS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
1. For OpenSearch Serverless: verify the collection uses a customer-managed KMS key 2. For Amazon RDS/Aurora: verify KMS encryption on the database 3. For third-party stores (Pinecone, Redis, MongoDB): verify the provider's encryption configuration 4. Verify the customer-managed KMS key used for transient data during ingestion |
Informational | N/A |
111122223333 |
us-west-2 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Review
Details and remediationDetails
Knowledge base 'InvestmentResearchKB' (ID: M1GMUG3BP0) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
1. For OpenSearch Serverless: verify the collection uses a customer-managed KMS key 2. For Amazon RDS/Aurora: verify KMS encryption on the database 3. For third-party stores (Pinecone, Redis, MongoDB): verify the provider's encryption configuration 4. Verify the customer-managed KMS key used for transient data during ingestion |
Informational | N/A |
111122223333 |
us-west-2 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Review
Details and remediationDetails
Knowledge base 'knowledge-base-quick-start-xtwwd' (ID: ENFHSBBLMV) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
1. For OpenSearch Serverless: verify the collection uses a customer-managed KMS key 2. For Amazon RDS/Aurora: verify KMS encryption on the database 3. For third-party stores (Pinecone, Redis, MongoDB): verify the provider's encryption configuration 4. Verify the customer-managed KMS key used for transient data during ingestion |
Informational | N/A |
111122223333 |
us-west-2 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Review
Details and remediationDetails
Knowledge base 'kb-s3-vector-store' (ID: 116IXQU5VP) uses 'S3_VECTORS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
1. For OpenSearch Serverless: verify the collection uses a customer-managed KMS key 2. For Amazon RDS/Aurora: verify KMS encryption on the database 3. For third-party stores (Pinecone, Redis, MongoDB): verify the provider's encryption configuration 4. Verify the customer-managed KMS key used for transient data during ingestion |
Informational | N/A |
111122223333 |
us-west-2 |
BR-21 |
Agent Action Group IAM Least Privilege Check
|
High | N/A |
111122223333 |
us-west-2 |
BR-22 |
Model Invocation Throttling Limits Check
|
Low | Passed |
111122223333 |
us-west-2 |
BR-23 |
Guardrail Content Filter Coverage Check
Details and remediationDetails
Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) is missing content filters: INSULTS, HATE, SEXUAL, VIOLENCE. Complete content filter coverage is essential for comprehensive content safety. Resolution
Update guardrail to enable all content filters (HATE, INSULTS, SEXUAL, VIOLENCE). Configure appropriate threshold levels (LOW, MEDIUM, HIGH) for both input and output filtering based on your use case. Review AWS documentation for threshold guidance. |
High | Failed |
111122223333 |
us-west-2 |
BR-24 |
Automated Reasoning Policy Implementation Check
Details and remediationDetails
Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) does not have an Automated Reasoning policy configured. Automated Reasoning provides formal verification of model responses against defined policies. Resolution
Configure Automated Reasoning policies on guardrails to mathematically verify model responses. Define policies that specify allowed and disallowed behaviors. Use for high-assurance use cases where formal verification is required. |
Medium | Failed |
111122223333 |
us-west-2 |
BR-25 |
RAG Evaluation Jobs Check
Details and remediationDetails
Knowledge base 'knowledge-base-bedrock-agent' (ID: XSPYLN4FQL) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Create RAG evaluation jobs for knowledge bases using Amazon Bedrock Model Evaluation. Configure evaluations to test context relevance, answer correctness, and faithfulness metrics. Run evaluations regularly (monthly or after significant KB updates) to maintain quality. |
Low | Failed |
111122223333 |
us-west-2 |
BR-25 |
RAG Evaluation Jobs Check
Details and remediationDetails
Knowledge base 'IDP-DOCUMENTBEDROCKKB-CY8N0Q7N4YDT' (ID: SUGAG7RGYD) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Create RAG evaluation jobs for knowledge bases using Amazon Bedrock Model Evaluation. Configure evaluations to test context relevance, answer correctness, and faithfulness metrics. Run evaluations regularly (monthly or after significant KB updates) to maintain quality. |
Low | Failed |
111122223333 |
us-west-2 |
BR-25 |
RAG Evaluation Jobs Check
Details and remediationDetails
Knowledge base 'promptfoo-rag-workshop-111122223333-kb' (ID: N74ZIKTUFL) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Create RAG evaluation jobs for knowledge bases using Amazon Bedrock Model Evaluation. Configure evaluations to test context relevance, answer correctness, and faithfulness metrics. Run evaluations regularly (monthly or after significant KB updates) to maintain quality. |
Low | Failed |
111122223333 |
us-west-2 |
BR-25 |
RAG Evaluation Jobs Check
Details and remediationDetails
Knowledge base 'InvestmentResearchKB' (ID: M1GMUG3BP0) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Create RAG evaluation jobs for knowledge bases using Amazon Bedrock Model Evaluation. Configure evaluations to test context relevance, answer correctness, and faithfulness metrics. Run evaluations regularly (monthly or after significant KB updates) to maintain quality. |
Low | Failed |
111122223333 |
us-west-2 |
BR-25 |
RAG Evaluation Jobs Check
Details and remediationDetails
Knowledge base 'knowledge-base-quick-start-xtwwd' (ID: ENFHSBBLMV) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Create RAG evaluation jobs for knowledge bases using Amazon Bedrock Model Evaluation. Configure evaluations to test context relevance, answer correctness, and faithfulness metrics. Run evaluations regularly (monthly or after significant KB updates) to maintain quality. |
Low | Failed |
111122223333 |
us-west-2 |
BR-25 |
RAG Evaluation Jobs Check
Details and remediationDetails
Knowledge base 'kb-s3-vector-store' (ID: 116IXQU5VP) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Create RAG evaluation jobs for knowledge bases using Amazon Bedrock Model Evaluation. Configure evaluations to test context relevance, answer correctness, and faithfulness metrics. Run evaluations regularly (monthly or after significant KB updates) to maintain quality. |
Low | Failed |
111122223333 |
us-west-2 |
BR-26 |
Guardrail Sensitive Information Filter Check
Details and remediationDetails
Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) has no sensitive-information filters configured (no PII entities or regex patterns). Prompts and model responses are not screened for sensitive data such as PII. Resolution
Configure sensitive-information filters on the guardrail: add PII entity types (e.g. NAME, EMAIL, SSN, CREDIT_DEBIT_CARD_NUMBER) and/or custom regex patterns, and set the appropriate BLOCK or ANONYMIZE action for input and output. |
High | Failed |
111122223333 |
us-west-2 |
BR-27 |
Guardrail Contextual Grounding Check
Details and remediationDetails
Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) does not have contextual grounding checks enabled. Without grounding and relevance checks, the guardrail cannot detect hallucinated (ungrounded) or off-topic model responses. Resolution
Enable contextual grounding checks (GROUNDING and RELEVANCE filter types) on the guardrail with appropriate thresholds. This is especially important for RAG applications to ensure responses are grounded in the retrieved source material. |
Medium | Failed |
111122223333 |
us-west-2 |
BR-28 |
Agent Guardrail Association Check
|
High | N/A |
111122223333 |
us-west-2 |
BR-29 |
Agent Idle Session TTL Check
|
Low | N/A |
111122223333 |
us-west-2 |
BR-30 |
Imported Model Customer-Managed KMS Encryption Check
|
High | N/A |
111122223333 |
us-west-2 |
BR-31 |
Batch Inference Output Encryption Check
|
Medium | N/A |
111122223333 |
us-west-2 |
BR-32 |
Bedrock CloudWatch Alarm Check
Details and remediationDetails
No CloudWatch alarms are configured on Amazon Bedrock runtime metrics (AWS/Bedrock namespace). Without alarms, abuse, denial-of-wallet, sustained throttling, and content-filter spikes can go undetected. Resolution
Create CloudWatch alarms on AWS/Bedrock runtime metrics such as Invocations, InvocationThrottles, InputTokenCount, OutputTokenCount, and ContentFilteredCount, and route them to an Amazon SNS topic for notification. |
Medium | Failed |
111122223333 |
us-west-2 |
BR-33 |
Amazon Inspector Lambda Code Scanning Check
Details and remediationDetails
Amazon Inspector Lambda scanning is not fully enabled in us-west-2. Lambda standard scan status: DISABLED. Lambda code scan status: DISABLED. Detected 6 Lambda function(s) with Bedrock indicators: IDP-DOCUMENTBEDROCKKB-CY8-GetAdjustedStackNameFunc-MFYZSG0nWqdj, IDP-DOCUMENTBEDROCKKB-CY8-StartIngestionJobFunctio-QGtm6KrDTRYu, IDP-DOCUMENTBEDROCKKB-CY8N0Q7N-GetSeedUrlsFunction-vCBSeTw4AdDV, IDP-PATTERN1STACK-TNHNKPKJY-ProcessResultsFunction-xLOdarbvGDm7, IDP-QueryKnowledgeBaseResolverFunction-tkmkVZ4lgxf8 (and 1 more). Without both scan types enabled, vulnerable dependencies and hardcoded secrets in these in-scope functions will not be detected. Resolution
Enable both Lambda standard scanning and Lambda code scanning in Amazon Inspector for this account and region. Console: Inspector -> Account management -> Activate for Lambda functions and Lambda code. |
Medium | Failed |
111122223333 |
us-west-2 |
AG-07 |
Agentic AI Model Invocation Logging
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: Model invocation logging is not enabled. This limits your ability to track and audit model usage. Resolution
Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements. |
Medium | Failed |
111122223333 |
us-west-2 |
AG-08 |
Agentic AI API Audit Trail
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: CloudTrail is properly configured to log Bedrock API activity in trails: IsengardTrail-DO-NOT-DELETE Resolution
Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured. |
Medium | Passed |
111122223333 |
us-west-2 |
AG-10 |
Agentic AI Adversarial Evaluation Coverage
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No Bedrock model evaluation jobs found. Model evaluation helps assess toxicity, accuracy, semantic robustness, and other safety metrics before production deployment. Resolution
Configure model or application evaluations that include adversarial, safety, and security-relevant test cases. |
Medium | Failed |
111122223333 |
us-west-2 |
AG-11 |
Agentic AI Prompt Flow Validation
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region Resolution
Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions. |
Informational | N/A |
111122223333 |
us-west-2 |
AG-06 |
Agentic AI Tool Execution Least Privilege
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region Resolution
Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required. |
Informational | N/A |
111122223333 |
us-west-2 |
AG-12 |
Agentic AI Invocation Abuse Controls
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: 7 custom throttling quotas are configured. Regular quota review helps maintain appropriate rate limits. Resolution
Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns. |
Low | Passed |
111122223333 |
us-west-2 |
AG-02 |
Agentic AI Harmful Content Guardrail Coverage
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) is missing content filters: INSULTS, HATE, SEXUAL, VIOLENCE. Complete content filter coverage is essential for comprehensive content safety. Resolution
Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads. |
High | Failed |
111122223333 |
us-west-2 |
AG-04 |
Agentic AI Automated Reasoning Guardrails
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) does not have an Automated Reasoning policy configured. Automated Reasoning provides formal verification of model responses against defined policies. Resolution
Configure automated reasoning policies on guardrails where formal response validation is required. |
Medium | Failed |
111122223333 |
us-west-2 |
AG-03 |
Agentic AI Sensitive Information Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) has no sensitive-information filters configured (no PII entities or regex patterns). Prompts and model responses are not screened for sensitive data such as PII. Resolution
Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns. |
High | Failed |
111122223333 |
us-west-2 |
AG-05 |
Agentic AI Grounding Controls
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) does not have contextual grounding checks enabled. Without grounding and relevance checks, the guardrail cannot detect hallucinated (ungrounded) or off-topic model responses. Resolution
Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows. |
Medium | Failed |
111122223333 |
us-west-2 |
AG-01 |
Agentic AI Agent Guardrail Association
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region Resolution
Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating. |
Informational | N/A |
111122223333 |
us-west-2 |
AG-13 |
Agentic AI Session Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region Resolution
Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements. |
Informational | N/A |
111122223333 |
us-west-2 |
AG-14 |
Agentic AI Operational Abuse Alarms
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No CloudWatch alarms are configured on Amazon Bedrock runtime metrics (AWS/Bedrock namespace). Without alarms, abuse, denial-of-wallet, sustained throttling, and content-filter spikes can go undetected. Resolution
Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available. |
Medium | Failed |
111122223333 |
us-east-1 |
OW-01 |
OWASP LLM01: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: Model invocation logging is properly configured with delivery to: Amazon S3, CloudWatch Logs Resolution
Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis. |
Medium | Passed |
111122223333 |
us-east-1 |
OW-07 |
OWASP LLM07: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-04: Model invocation logging is properly configured with delivery to: Amazon S3, CloudWatch Logs Resolution
Enable Bedrock model invocation logging so prompt-extraction attempts against the system prompt are auditable after the fact. |
Medium | Passed |
111122223333 |
us-east-1 |
OW-07 |
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident. |
Informational | N/A |
111122223333 |
us-east-1 |
OW-07 |
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-16: Guardrail 'nist-ai-rmf-guardrail' (ID: do7xkmhadx7k) is using the 'CLASSIC' content-filter tier instead of 'STANDARD'. The STANDARD tier provides more robust content filtering and broader language support than the CLASSIC tier. Resolution
Set guardrail contentPolicy.tier.tierName to STANDARD; Standard tier additionally detects prompt-leakage attacks. |
Medium | Failed |
111122223333 |
us-east-1 |
OW-09 |
OWASP LLM09: Model Evaluation Jobs
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check BR-18: No Bedrock model evaluation jobs found. Model evaluation helps assess toxicity, accuracy, semantic robustness, and other safety metrics before production deployment. Resolution
Run Bedrock model evaluation jobs that include correctness and safety datasets. |
Medium | Failed |
111122223333 |
us-east-1 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: Knowledge base 'knowledge-base-semiconductors' (ID: RQYFDSE1LT) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption. |
Informational | N/A |
111122223333 |
us-east-1 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: Knowledge base '111122223333-us-east-1-kb' (ID: PAJOKBSIMQ) uses 'S3_VECTORS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption. |
Informational | N/A |
111122223333 |
us-east-1 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: Knowledge base 'e2e-rag-knowledgebase' (ID: ESIYAYSYTJ) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption. |
Informational | N/A |
111122223333 |
us-east-1 |
OW-06 |
OWASP LLM06: Agent Action-Group Least Privilege
|
Informational | N/A |
111122223333 |
us-east-1 |
OW-10 |
OWASP LLM10: Service Quota Throttling Limits
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-22: 11 custom throttling quotas are configured. Regular quota review helps maintain appropriate rate limits. Resolution
Customise Bedrock TPM / RPM service quotas above the account default to establish an explicit consumption ceiling. |
Low | Passed |
111122223333 |
us-east-1 |
OW-01 |
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: 1 guardrails have complete content filter coverage (hate, insults, sexual, violence) Resolution
Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier. |
Low | Passed |
111122223333 |
us-east-1 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: Knowledge base 'knowledge-base-semiconductors' (ID: RQYFDSE1LT) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context. |
Low | Failed |
111122223333 |
us-east-1 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check BR-25: Knowledge base 'knowledge-base-semiconductors' (ID: RQYFDSE1LT) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates. |
Low | Failed |
111122223333 |
us-east-1 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: Knowledge base '111122223333-us-east-1-kb' (ID: PAJOKBSIMQ) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context. |
Low | Failed |
111122223333 |
us-east-1 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check BR-25: Knowledge base '111122223333-us-east-1-kb' (ID: PAJOKBSIMQ) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates. |
Low | Failed |
111122223333 |
us-east-1 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: Knowledge base 'e2e-rag-knowledgebase' (ID: ESIYAYSYTJ) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context. |
Low | Failed |
111122223333 |
us-east-1 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check BR-25: Knowledge base 'e2e-rag-knowledgebase' (ID: ESIYAYSYTJ) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates. |
Low | Failed |
111122223333 |
us-east-1 |
OW-02 |
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation |
Low | Passed |
111122223333 |
us-east-1 |
OW-01 |
OWASP LLM01: Contextual Grounding Guardrail
Details and remediation |
Low | Passed |
111122223333 |
us-east-1 |
OW-04 |
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation |
Low | Passed |
111122223333 |
us-east-1 |
OW-09 |
OWASP LLM09: Contextual Grounding for Faithfulness
|
Low | Passed |
111122223333 |
us-east-1 |
OW-06 |
OWASP LLM06: Bedrock Agent Guardrail Association
|
Informational | N/A |
111122223333 |
us-east-1 |
OW-06 |
OWASP LLM06: Agent Idle Session TTL
|
Informational | N/A |
111122223333 |
us-east-1 |
OW-03 |
OWASP LLM03: Imported-Model KMS Provenance
|
Informational | N/A |
111122223333 |
us-east-1 |
OW-10 |
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-32: No CloudWatch alarms are configured on Amazon Bedrock runtime metrics (AWS/Bedrock namespace). Without alarms, abuse, denial-of-wallet, sustained throttling, and content-filter spikes can go undetected. Resolution
Create CloudWatch alarms on Bedrock InvocationThrottles, InputTokenCount, OutputTokenCount, and EstimatedTPMQuotaUsage. |
Medium | Failed |
111122223333 |
us-east-1 |
OW-03 |
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check BR-33: Amazon Inspector Lambda scanning is not fully enabled in us-east-1. Lambda standard scan status: ENABLED. Lambda code scan status: DISABLED. Detected 6 Lambda function(s) with Bedrock indicators: aiml-security-aiml-security-111122223333-BedrockAssessment, e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk, gateway_lambda, myAskMeAnything, resco-aiml-BedrockAssessment (and 1 more). Without both scan types enabled, vulnerable dependencies and hardcoded secrets in these in-scope functions will not be detected. Resolution
Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain. |
Medium | Failed |
111122223333 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Internet Exposure
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-01: SageMaker domain 'd-cz8qi7j81si3' (QuickSetupDomain-20250525T153160) is not configured for VPC-only access Resolution
Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths. |
High | Failed |
111122223333 |
us-east-1 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: Domain 'QuickSetupDomain-20250525T153160' - No KMS key configured Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
High | Failed |
111122223333 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Clarify Evaluation
|
Informational | N/A |
111122223333 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation |
Informational | N/A |
111122223333 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Model Monitor Coverage
|
Informational | N/A |
111122223333 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Notebook VPC Deployment
|
Informational | N/A |
111122223333 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Model Network Isolation
|
Informational | N/A |
111122223333 |
us-east-1 |
OW-10 |
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation |
Informational | N/A |
111122223333 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Container Repository Access
Details and remediation |
Informational | N/A |
111122223333 |
us-east-1 |
OW-02 |
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation |
Informational | N/A |
111122223333 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker AutoML Network Isolation
|
Informational | N/A |
111122223333 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically. |
Informational | N/A |
111122223333 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release. |
Informational | N/A |
111122223333 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
111122223333 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
111122223333 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain. |
Informational | N/A |
111122223333 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated. |
Informational | N/A |
111122223333 |
Global |
OW-06 |
OWASP LLM06: AgentCore IAM Least Privilege
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check AC-02: The following roles have BedrockAgentCoreFullAccess policy: AmazonSageMaker-ExecutionRole-20250525T153161 Resolution
Remove AmazonBedrockAgentCoreFullAccess (or equivalents) from identities that only need read/execute permissions. |
High | Failed |
111122223333 |
Global |
OW-06 |
OWASP LLM06: AgentCore IAM Least Privilege
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check AC-02: The following roles have wildcard AgentCore permissions on all resources: agentcore-wildrydes_gateway_role_ab3991f6-role Resolution
Remove AmazonBedrockAgentCoreFullAccess (or equivalents) from identities that only need read/execute permissions. |
High | Failed |
111122223333 |
us-east-1 |
OW-06 |
OWASP LLM06: AgentCore Resource-Based Policies
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check AC-10: The following AgentCore resources do not have resource-based policies: Runtime 'origami_expeditions', Runtime 'neoCyan_Agent', Runtime 'customer_support_agent', Runtime 'cdk_agent_core', Runtime 'awsapimcpserver' and 2 more. Without RBPs, access control relies solely on identity-based policies. Resolution
Attach resource-based policies to AgentCore runtimes and gateways so caller identities are constrained. |
High | Failed |
111122223333 |
us-east-1 |
OW-10 |
OWASP LLM10: WAF Rate-Based & Shield Protection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-01: AWS Shield Advanced is not subscribed. GenAI API endpoints are vulnerable to volumetric DDoS attacks that can exhaust token quotas and inflate costs. Resolution
Add a WAF RateBasedStatement plus a SizeConstraintStatement on the GenAI ingress and subscribe to AWS Shield Advanced. |
Low | Failed |
111122223333 |
us-east-2 |
OW-10 |
OWASP LLM10: WAF Rate-Based & Shield Protection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-01: AWS Shield Advanced is not subscribed. GenAI API endpoints are vulnerable to volumetric DDoS attacks that can exhaust token quotas and inflate costs. Resolution
Add a WAF RateBasedStatement plus a SizeConstraintStatement on the GenAI ingress and subscribe to AWS Shield Advanced. |
Low | Failed |
111122223333 |
us-west-2 |
OW-10 |
OWASP LLM10: WAF Rate-Based & Shield Protection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-01: AWS Shield Advanced is not subscribed. GenAI API endpoints are vulnerable to volumetric DDoS attacks that can exhaust token quotas and inflate costs. Resolution
Add a WAF RateBasedStatement plus a SizeConstraintStatement on the GenAI ingress and subscribe to AWS Shield Advanced. |
Low | Failed |
111122223333 |
us-east-1 |
OW-10 |
OWASP LLM10: WAF Rate-Based & Shield Protection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-01: No AWS WAF regional Web ACLs found. Without WAF, GenAI endpoints lack rate-based rules to block abusive callers. Resolution
Add a WAF RateBasedStatement plus a SizeConstraintStatement on the GenAI ingress and subscribe to AWS Shield Advanced. |
Medium | Failed |
111122223333 |
us-east-2 |
OW-10 |
OWASP LLM10: WAF Rate-Based & Shield Protection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-01: No AWS WAF regional Web ACLs found. Without WAF, GenAI endpoints lack rate-based rules to block abusive callers. Resolution
Add a WAF RateBasedStatement plus a SizeConstraintStatement on the GenAI ingress and subscribe to AWS Shield Advanced. |
Medium | Failed |
111122223333 |
us-west-2 |
OW-10 |
OWASP LLM10: WAF Rate-Based & Shield Protection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-01: No AWS WAF regional Web ACLs found. Without WAF, GenAI endpoints lack rate-based rules to block abusive callers. Resolution
Add a WAF RateBasedStatement plus a SizeConstraintStatement on the GenAI ingress and subscribe to AWS Shield Advanced. |
Medium | Failed |
111122223333 |
us-east-1 |
OW-10 |
OWASP LLM10: API Gateway Usage Plans
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-02: Usage plans without throttling: myAskMeAnything-UsagePlan. Unbounded API calls can exhaust Bedrock token quotas and inflate costs. Resolution
Attach API Gateway Usage Plans with non-zero rateLimit / burstLimit to any REST APIs that proxy Bedrock. |
Medium | Failed |
111122223333 |
us-east-2 |
OW-10 |
OWASP LLM10: API Gateway Usage Plans
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-02: Usage plans without throttling: myAskMeAnything-UsagePlan. Unbounded API calls can exhaust Bedrock token quotas and inflate costs. Resolution
Attach API Gateway Usage Plans with non-zero rateLimit / burstLimit to any REST APIs that proxy Bedrock. |
Medium | Failed |
111122223333 |
us-west-2 |
OW-10 |
OWASP LLM10: API Gateway Usage Plans
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-02: Usage plans without throttling: myAskMeAnything-UsagePlan. Unbounded API calls can exhaust Bedrock token quotas and inflate costs. Resolution
Attach API Gateway Usage Plans with non-zero rateLimit / burstLimit to any REST APIs that proxy Bedrock. |
Medium | Failed |
111122223333 |
us-east-1 |
OW-10 |
OWASP LLM10: Bedrock TPM/RPM Quotas Customised
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-03: Found 240 Bedrock token-based quota(s); at least one applied value exceeds the AWS default, indicating quotas have been reviewed and raised. Resolution
Customise Bedrock service quotas above the account default so consumption is explicitly bounded. |
Medium | Passed |
111122223333 |
us-east-2 |
OW-10 |
OWASP LLM10: Bedrock TPM/RPM Quotas Customised
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-03: Found 240 Bedrock token-based quota(s); at least one applied value exceeds the AWS default, indicating quotas have been reviewed and raised. Resolution
Customise Bedrock service quotas above the account default so consumption is explicitly bounded. |
Medium | Passed |
111122223333 |
us-west-2 |
OW-10 |
OWASP LLM10: Bedrock TPM/RPM Quotas Customised
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-03: Found 240 Bedrock token-based quota(s); at least one applied value exceeds the AWS default, indicating quotas have been reviewed and raised. Resolution
Customise Bedrock service quotas above the account default so consumption is explicitly bounded. |
Medium | Passed |
111122223333 |
us-east-1 |
OW-10 |
OWASP LLM10: Cost Anomaly Detection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-04: No AWS Cost Anomaly Detection monitors found. Unexpected spikes in Bedrock/SageMaker usage (e.g., from prompt injection loops) will go undetected. Resolution
Configure AWS Cost Anomaly Detection monitors that include Bedrock and SageMaker. |
Medium | Failed |
111122223333 |
us-east-2 |
OW-10 |
OWASP LLM10: Cost Anomaly Detection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-04: No AWS Cost Anomaly Detection monitors found. Unexpected spikes in Bedrock/SageMaker usage (e.g., from prompt injection loops) will go undetected. Resolution
Configure AWS Cost Anomaly Detection monitors that include Bedrock and SageMaker. |
Medium | Failed |
111122223333 |
us-west-2 |
OW-10 |
OWASP LLM10: Cost Anomaly Detection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-04: No AWS Cost Anomaly Detection monitors found. Unexpected spikes in Bedrock/SageMaker usage (e.g., from prompt injection loops) will go undetected. Resolution
Configure AWS Cost Anomaly Detection monitors that include Bedrock and SageMaker. |
Medium | Failed |
111122223333 |
us-east-1 |
OW-10 |
OWASP LLM10: Token / Throttle Alarms
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-05: No CloudWatch alarms found for Bedrock metrics. Token exhaustion and throttling events will not trigger operational alerts. Resolution
Create CloudWatch alarms on the Bedrock namespace for InvocationThrottles and token counters. |
Medium | Failed |
111122223333 |
us-east-2 |
OW-10 |
OWASP LLM10: Token / Throttle Alarms
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-05: No CloudWatch alarms found for Bedrock metrics. Token exhaustion and throttling events will not trigger operational alerts. Resolution
Create CloudWatch alarms on the Bedrock namespace for InvocationThrottles and token counters. |
Medium | Failed |
111122223333 |
us-west-2 |
OW-10 |
OWASP LLM10: Token / Throttle Alarms
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-05: No CloudWatch alarms found for Bedrock metrics. Token exhaustion and throttling events will not trigger operational alerts. Resolution
Create CloudWatch alarms on the Bedrock namespace for InvocationThrottles and token counters. |
Medium | Failed |
111122223333 |
us-east-1 |
OW-10 |
OWASP LLM10: AWS Budgets with Bedrock Filters
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-06: No AWS Budgets found scoped to Bedrock or SageMaker. Unbounded GenAI spend can go undetected until the monthly bill. Resolution
Configure AWS Budgets with FilterExpression / CostFilters targeting Bedrock or SageMaker spend, with an alerting SNS action. |
Medium | Failed |
111122223333 |
us-east-2 |
OW-10 |
OWASP LLM10: AWS Budgets with Bedrock Filters
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-06: No AWS Budgets found scoped to Bedrock or SageMaker. Unbounded GenAI spend can go undetected until the monthly bill. Resolution
Configure AWS Budgets with FilterExpression / CostFilters targeting Bedrock or SageMaker spend, with an alerting SNS action. |
Medium | Failed |
111122223333 |
us-west-2 |
OW-10 |
OWASP LLM10: AWS Budgets with Bedrock Filters
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-06: No AWS Budgets found scoped to Bedrock or SageMaker. Unbounded GenAI spend can go undetected until the monthly bill. Resolution
Configure AWS Budgets with FilterExpression / CostFilters targeting Bedrock or SageMaker spend, with an alerting SNS action. |
Medium | Failed |
111122223333 |
us-east-1 |
OW-06 |
OWASP LLM06: Agent Execution Role Least Privilege
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-06 |
OWASP LLM06: Agent Execution Role Least Privilege
|
Informational | N/A |
111122223333 |
us-west-2 |
OW-06 |
OWASP LLM06: Agent Execution Role Least Privilege
|
Informational | N/A |
111122223333 |
us-east-1 |
OW-06 |
OWASP LLM06: AgentCore Gateway Policy Engine
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check FS-08: Runtimes without authorizer configuration: origami_expeditions, neoCyan_Agent, customer_support_agent, cdk_agent_core, awsapimcpserver. Without a policy engine, agents can invoke any registered tool without authorization checks. Resolution
Set AgentCore Gateway policyEngineConfiguration.mode to ENFORCE and require identity propagation on Runtimes. |
High | Failed |
111122223333 |
us-east-2 |
OW-06 |
OWASP LLM06: AgentCore Gateway Policy Engine
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check FS-08: Runtimes without authorizer configuration: origami_expeditions, neoCyan_Agent, customer_support_agent, cdk_agent_core, awsapimcpserver. Without a policy engine, agents can invoke any registered tool without authorization checks. Resolution
Set AgentCore Gateway policyEngineConfiguration.mode to ENFORCE and require identity propagation on Runtimes. |
High | Failed |
111122223333 |
us-west-2 |
OW-06 |
OWASP LLM06: AgentCore Gateway Policy Engine
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check FS-08: Runtimes without authorizer configuration: origami_expeditions, neoCyan_Agent, customer_support_agent, cdk_agent_core, awsapimcpserver. Without a policy engine, agents can invoke any registered tool without authorization checks. Resolution
Set AgentCore Gateway policyEngineConfiguration.mode to ENFORCE and require identity propagation on Runtimes. |
High | Failed |
111122223333 |
us-east-1 |
OW-06 |
OWASP LLM06: Agent Tool Concurrency Limits
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check FS-09: Agent-related Lambda functions without reserved concurrency: aiml-security-aiml-security-111122223333-FinServAssessment, resco-aiml-IAMPermissionCaching, aiml-security-aiml-security-111122223333-OWASPAssessment, aiml-security-aiml-security-111122223333-SagemakerAssessment, resco-aiml-CleanupBucket, aiml-security-aiml-security-111122223333-BedrockAssessment, resco-aiml-BedrockAssessment, aiml-security-aiml-security-111122223333-CleanupBucket, aiml-security-aiml-security-111122223333-AgentCoreAssessment, e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk. Unlimited concurrency allows runaway agent loops to exhaust account limits. Resolution
Set reserved concurrency on agent action-group Lambdas so a runaway agent cannot exhaust downstream capacity. |
Medium | Failed |
111122223333 |
us-east-2 |
OW-06 |
OWASP LLM06: Agent Tool Concurrency Limits
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check FS-09: Agent-related Lambda functions without reserved concurrency: aiml-security-aiml-security-111122223333-FinServAssessment, resco-aiml-IAMPermissionCaching, aiml-security-aiml-security-111122223333-OWASPAssessment, aiml-security-aiml-security-111122223333-SagemakerAssessment, resco-aiml-CleanupBucket, aiml-security-aiml-security-111122223333-BedrockAssessment, resco-aiml-BedrockAssessment, aiml-security-aiml-security-111122223333-CleanupBucket, aiml-security-aiml-security-111122223333-AgentCoreAssessment, e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk. Unlimited concurrency allows runaway agent loops to exhaust account limits. Resolution
Set reserved concurrency on agent action-group Lambdas so a runaway agent cannot exhaust downstream capacity. |
Medium | Failed |
111122223333 |
us-west-2 |
OW-06 |
OWASP LLM06: Agent Tool Concurrency Limits
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check FS-09: Agent-related Lambda functions without reserved concurrency: aiml-security-aiml-security-111122223333-FinServAssessment, resco-aiml-IAMPermissionCaching, aiml-security-aiml-security-111122223333-OWASPAssessment, aiml-security-aiml-security-111122223333-SagemakerAssessment, resco-aiml-CleanupBucket, aiml-security-aiml-security-111122223333-BedrockAssessment, resco-aiml-BedrockAssessment, aiml-security-aiml-security-111122223333-CleanupBucket, aiml-security-aiml-security-111122223333-AgentCoreAssessment, e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk. Unlimited concurrency allows runaway agent loops to exhaust account limits. Resolution
Set reserved concurrency on agent action-group Lambdas so a runaway agent cannot exhaust downstream capacity. |
Medium | Failed |
111122223333 |
us-east-1 |
OW-06 |
OWASP LLM06: Human-in-the-Loop Callback States
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check FS-10: No Step Functions state machines with agent/approval naming found. Verify that high-risk agent actions (e.g., fund transfers, account changes) have human approval gates. Resolution
Insert Step Functions .waitForTaskToken callback states before any high-risk agent-triggered action. |
Informational | N/A |
111122223333 |
us-east-2 |
OW-06 |
OWASP LLM06: Human-in-the-Loop Callback States
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check FS-10: No Step Functions state machines with agent/approval naming found. Verify that high-risk agent actions (e.g., fund transfers, account changes) have human approval gates. Resolution
Insert Step Functions .waitForTaskToken callback states before any high-risk agent-triggered action. |
Informational | N/A |
111122223333 |
us-west-2 |
OW-06 |
OWASP LLM06: Human-in-the-Loop Callback States
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check FS-10: No Step Functions state machines with agent/approval naming found. Verify that high-risk agent actions (e.g., fund transfers, account changes) have human approval gates. Resolution
Insert Step Functions .waitForTaskToken callback states before any high-risk agent-triggered action. |
Informational | N/A |
111122223333 |
us-east-1 |
OW-03 |
OWASP LLM03: SCP-Enforced Model Allowlist
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check FS-12: No Service Control Policies reference Bedrock. Without SCPs, any account in the organization can access any Bedrock model, including unapproved third-party models. Resolution
Attach an Organizations SCP that denies bedrock:InvokeModel* except for allowlisted bedrock:ModelId values. |
High | Failed |
111122223333 |
us-east-2 |
OW-03 |
OWASP LLM03: SCP-Enforced Model Allowlist
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check FS-12: No Service Control Policies reference Bedrock. Without SCPs, any account in the organization can access any Bedrock model, including unapproved third-party models. Resolution
Attach an Organizations SCP that denies bedrock:InvokeModel* except for allowlisted bedrock:ModelId values. |
High | Failed |
111122223333 |
us-west-2 |
OW-03 |
OWASP LLM03: SCP-Enforced Model Allowlist
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check FS-12: No Service Control Policies reference Bedrock. Without SCPs, any account in the organization can access any Bedrock model, including unapproved third-party models. Resolution
Attach an Organizations SCP that denies bedrock:InvokeModel* except for allowlisted bedrock:ModelId values. |
High | Failed |
111122223333 |
us-east-1 |
OW-03 |
OWASP LLM03: Custom-Model Provenance Tags
|
Medium | Passed |
111122223333 |
us-east-2 |
OW-03 |
OWASP LLM03: Custom-Model Provenance Tags
|
Medium | Passed |
111122223333 |
us-west-2 |
OW-03 |
OWASP LLM03: Custom-Model Provenance Tags
|
Medium | Passed |
111122223333 |
us-east-1 |
OW-03 |
OWASP LLM03: Config Rules for Model Onboarding
|
Medium | Passed |
111122223333 |
us-east-2 |
OW-03 |
OWASP LLM03: Config Rules for Model Onboarding
|
Medium | Passed |
111122223333 |
us-west-2 |
OW-03 |
OWASP LLM03: Config Rules for Model Onboarding
|
Medium | Passed |
111122223333 |
us-east-1 |
OW-03 |
OWASP LLM03: Adversarial Evaluation Coverage
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check FS-15: No Bedrock Model Evaluation jobs found. Models have not been evaluated for adversarial robustness. FinServ model-risk management (SR 11-7) expects documented model validation/evaluation. Resolution
Run Bedrock evaluation jobs that include adversarial and safety datasets before promoting a model to production. |
Medium | Failed |
111122223333 |
us-east-2 |
OW-03 |
OWASP LLM03: Adversarial Evaluation Coverage
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check FS-15: No Bedrock Model Evaluation jobs found. Models have not been evaluated for adversarial robustness. FinServ model-risk management (SR 11-7) expects documented model validation/evaluation. Resolution
Run Bedrock evaluation jobs that include adversarial and safety datasets before promoting a model to production. |
Medium | Failed |
111122223333 |
us-west-2 |
OW-03 |
OWASP LLM03: Adversarial Evaluation Coverage
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check FS-15: No Bedrock Model Evaluation jobs found. Models have not been evaluated for adversarial robustness. FinServ model-risk management (SR 11-7) expects documented model validation/evaluation. Resolution
Run Bedrock evaluation jobs that include adversarial and safety datasets before promoting a model to production. |
Medium | Failed |
111122223333 |
us-east-1 |
OW-03 |
OWASP LLM03: ECR Image Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check FS-16: 4 ECR repo(s) without scan-on-push: mlexplorationrepo, cdk-hnb659fds-container-assets-111122223333-us-east-1, bedrock-agentcore-customer_support_agent, bedrock-agentcore-origami_expeditions. Resolution
Enable Amazon Inspector enhanced scanning or scan-on-push on ECR repositories that hold model / agent container images. |
High | Failed |
111122223333 |
us-east-2 |
OW-03 |
OWASP LLM03: ECR Image Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check FS-16: 4 ECR repo(s) without scan-on-push: mlexplorationrepo, cdk-hnb659fds-container-assets-111122223333-us-east-1, bedrock-agentcore-customer_support_agent, bedrock-agentcore-origami_expeditions. Resolution
Enable Amazon Inspector enhanced scanning or scan-on-push on ECR repositories that hold model / agent container images. |
High | Failed |
111122223333 |
us-west-2 |
OW-03 |
OWASP LLM03: ECR Image Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check FS-16: 4 ECR repo(s) without scan-on-push: mlexplorationrepo, cdk-hnb659fds-container-assets-111122223333-us-east-1, bedrock-agentcore-customer_support_agent, bedrock-agentcore-origami_expeditions. Resolution
Enable Amazon Inspector enhanced scanning or scan-on-push on ECR repositories that hold model / agent container images. |
High | Failed |
111122223333 |
us-east-1 |
OW-04 |
OWASP LLM04: Feature Store Offline Recovery
Details and remediation |
Informational | N/A |
111122223333 |
us-east-2 |
OW-04 |
OWASP LLM04: Feature Store Offline Recovery
Details and remediation |
Informational | N/A |
111122223333 |
us-west-2 |
OW-04 |
OWASP LLM04: Feature Store Offline Recovery
Details and remediation |
Informational | N/A |
111122223333 |
us-east-1 |
OW-04 |
OWASP LLM04: Training-Data Versioning
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check FS-21: 13 training data bucket(s) without versioning: ancbedrocklogging, bedrock-agentcore-codebuild-sources-111122223333-us-east-1, bedrock-bda-us-east-1-dda43109-6557-48bb-993d-3f97126b64b4, bedrock-bda-us-east-1-logging-00719114-debd-4487-85d1-09cbc3fc8, bedrock-kb-bucket-f736570b, bedrock-video-generation-us-east-1-h5ltpm, fsi-genai-workshop-bedrock-datasources-111122223333-us-west-2, knowledgebase-bedrock-agent-agasthik, llmevaluationpromptfoo-bedrockkb-cozhbzbrcmd2, sagemaker-studio-111122223333-huo1mvme4t. Resolution
Enable S3 versioning on training-data buckets so poisoned data can be reverted. |
High | Failed |
111122223333 |
us-east-2 |
OW-04 |
OWASP LLM04: Training-Data Versioning
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check FS-21: 13 training data bucket(s) without versioning: ancbedrocklogging, bedrock-agentcore-codebuild-sources-111122223333-us-east-1, bedrock-bda-us-east-1-dda43109-6557-48bb-993d-3f97126b64b4, bedrock-bda-us-east-1-logging-00719114-debd-4487-85d1-09cbc3fc8, bedrock-kb-bucket-f736570b, bedrock-video-generation-us-east-1-h5ltpm, fsi-genai-workshop-bedrock-datasources-111122223333-us-west-2, knowledgebase-bedrock-agent-agasthik, llmevaluationpromptfoo-bedrockkb-cozhbzbrcmd2, sagemaker-studio-111122223333-huo1mvme4t. Resolution
Enable S3 versioning on training-data buckets so poisoned data can be reverted. |
High | Failed |
111122223333 |
us-west-2 |
OW-04 |
OWASP LLM04: Training-Data Versioning
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check FS-21: 13 training data bucket(s) without versioning: ancbedrocklogging, bedrock-agentcore-codebuild-sources-111122223333-us-east-1, bedrock-bda-us-east-1-dda43109-6557-48bb-993d-3f97126b64b4, bedrock-bda-us-east-1-logging-00719114-debd-4487-85d1-09cbc3fc8, bedrock-kb-bucket-f736570b, bedrock-video-generation-us-east-1-h5ltpm, fsi-genai-workshop-bedrock-datasources-111122223333-us-west-2, knowledgebase-bedrock-agent-agasthik, llmevaluationpromptfoo-bedrockkb-cozhbzbrcmd2, sagemaker-studio-111122223333-huo1mvme4t. Resolution
Enable S3 versioning on training-data buckets so poisoned data can be reverted. |
High | Failed |
111122223333 |
us-east-1 |
OW-08 |
OWASP LLM08: KB IAM Scope
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-22: 829 role(s) with wildcard KB permissions: - Role '111122223333-us-east-1-kb-setup-function-role' allows 'bedrock:CreateKnowledgeBase' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role '111122223333-us-east-1-kb-setup-function-role' allows 'bedrock:CreateDataSource' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'Admin' allows '*' - Role 'agentcore-wildrydes_gateway_role_ab3991f6-role' allows 'bedrock:*' - Role 'AgentCoreEvalsSDK-us-east-1-d04ba7b68b' allows 'bedrock:InvokeModel' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'AgentCoreEvalsSDK-us-east-1-d04ba7b68b' allows 'bedrock:InvokeModelWithResponseStream' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'Agentic-AI-MCP-Strands-SDK-Works-VSCodeInstanceRole-NCTUnlnRBFO6' allows '*' - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:ListGuardrails' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:GetGuardrail' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:ListModelInvocationJobs' on Resource '*' (no ARN scoping to specific Knowledge Bases) Resolution
Scope Knowledge Base IAM roles to specific KB ARNs; remove wildcard bedrock:* on KB actions. |
High | Failed |
111122223333 |
us-east-2 |
OW-08 |
OWASP LLM08: KB IAM Scope
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-22: 829 role(s) with wildcard KB permissions: - Role '111122223333-us-east-1-kb-setup-function-role' allows 'bedrock:CreateKnowledgeBase' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role '111122223333-us-east-1-kb-setup-function-role' allows 'bedrock:CreateDataSource' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'Admin' allows '*' - Role 'agentcore-wildrydes_gateway_role_ab3991f6-role' allows 'bedrock:*' - Role 'AgentCoreEvalsSDK-us-east-1-d04ba7b68b' allows 'bedrock:InvokeModel' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'AgentCoreEvalsSDK-us-east-1-d04ba7b68b' allows 'bedrock:InvokeModelWithResponseStream' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'Agentic-AI-MCP-Strands-SDK-Works-VSCodeInstanceRole-NCTUnlnRBFO6' allows '*' - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:ListGuardrails' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:GetGuardrail' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:ListModelInvocationJobs' on Resource '*' (no ARN scoping to specific Knowledge Bases) Resolution
Scope Knowledge Base IAM roles to specific KB ARNs; remove wildcard bedrock:* on KB actions. |
High | Failed |
111122223333 |
us-west-2 |
OW-08 |
OWASP LLM08: KB IAM Scope
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-22: 829 role(s) with wildcard KB permissions: - Role '111122223333-us-east-1-kb-setup-function-role' allows 'bedrock:CreateKnowledgeBase' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role '111122223333-us-east-1-kb-setup-function-role' allows 'bedrock:CreateDataSource' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'Admin' allows '*' - Role 'agentcore-wildrydes_gateway_role_ab3991f6-role' allows 'bedrock:*' - Role 'AgentCoreEvalsSDK-us-east-1-d04ba7b68b' allows 'bedrock:InvokeModel' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'AgentCoreEvalsSDK-us-east-1-d04ba7b68b' allows 'bedrock:InvokeModelWithResponseStream' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'Agentic-AI-MCP-Strands-SDK-Works-VSCodeInstanceRole-NCTUnlnRBFO6' allows '*' - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:ListGuardrails' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:GetGuardrail' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:ListModelInvocationJobs' on Resource '*' (no ARN scoping to specific Knowledge Bases) Resolution
Scope Knowledge Base IAM roles to specific KB ARNs; remove wildcard bedrock:* on KB actions. |
High | Failed |
111122223333 |
us-east-1 |
OW-08 |
OWASP LLM08: KB Metadata Filtering
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-24: Found 3 Knowledge Base(s). Tenant-isolation metadata filtering is a design pattern that cannot be verified via API — manual review required. Verify that metadata attributes (e.g., tenantId, classification) are indexed and that Retrieve calls include RetrievalFilter conditions for tenant isolation. Resolution
Define Knowledge Base metadata fields so tenant / document-level filtering can be applied at retrieval time. |
Informational | N/A |
111122223333 |
us-east-2 |
OW-08 |
OWASP LLM08: KB Metadata Filtering
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-24: Found 3 Knowledge Base(s). Tenant-isolation metadata filtering is a design pattern that cannot be verified via API — manual review required. Verify that metadata attributes (e.g., tenantId, classification) are indexed and that Retrieve calls include RetrievalFilter conditions for tenant isolation. Resolution
Define Knowledge Base metadata fields so tenant / document-level filtering can be applied at retrieval time. |
Informational | N/A |
111122223333 |
us-west-2 |
OW-08 |
OWASP LLM08: KB Metadata Filtering
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-24: Found 3 Knowledge Base(s). Tenant-isolation metadata filtering is a design pattern that cannot be verified via API — manual review required. Verify that metadata attributes (e.g., tenantId, classification) are indexed and that Retrieve calls include RetrievalFilter conditions for tenant isolation. Resolution
Define Knowledge Base metadata fields so tenant / document-level filtering can be applied at retrieval time. |
Informational | N/A |
111122223333 |
us-east-1 |
OW-08 |
OWASP LLM08: OpenSearch Serverless Encryption
Details and remediation |
High | Passed |
111122223333 |
us-east-2 |
OW-08 |
OWASP LLM08: OpenSearch Serverless Encryption
Details and remediation |
High | Passed |
111122223333 |
us-west-2 |
OW-08 |
OWASP LLM08: OpenSearch Serverless Encryption
Details and remediation |
High | Passed |
111122223333 |
us-east-1 |
OW-08 |
OWASP LLM08: OpenSearch Serverless Network Policy
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-26: Found 5 network policy(ies) but none restrict to VPC. Vector stores may be accessible from the public internet. Resolution
Set AllowFromPublic=false on the OpenSearch Serverless network policy and restrict access to bedrock.amazonaws.com or a specific VPC endpoint. |
High | Failed |
111122223333 |
us-east-2 |
OW-08 |
OWASP LLM08: OpenSearch Serverless Network Policy
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-26: Found 5 network policy(ies) but none restrict to VPC. Vector stores may be accessible from the public internet. Resolution
Set AllowFromPublic=false on the OpenSearch Serverless network policy and restrict access to bedrock.amazonaws.com or a specific VPC endpoint. |
High | Failed |
111122223333 |
us-west-2 |
OW-08 |
OWASP LLM08: OpenSearch Serverless Network Policy
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-26: Found 5 network policy(ies) but none restrict to VPC. Vector stores may be accessible from the public internet. Resolution
Set AllowFromPublic=false on the OpenSearch Serverless network policy and restrict access to bedrock.amazonaws.com or a specific VPC endpoint. |
High | Failed |
111122223333 |
us-east-1 |
OW-09 |
OWASP LLM09: Knowledge-Base Ingestion Freshness
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check FS-31: 2 data source(s) not synced in >7 days (a configurable review threshold, NOT an AWS-mandated limit): - KB 'knowledge-base-semiconductors' source 'knowledge-base-quick-start-qpvuv-data-source' last synced 731 days ago - KB '111122223333-us-east-1-kb' source '111122223333-us-east-1-kb-datasource' last synced 209 days ago Confirm this age is acceptable for each data source's currency requirement — slow-changing reference data may legitimately sync infrequently. Resolution
Sync Knowledge Base data sources on a schedule (weekly at most); stale KB content increases hallucination risk. |
Medium | Failed |
111122223333 |
us-east-2 |
OW-09 |
OWASP LLM09: Knowledge-Base Ingestion Freshness
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check FS-31: 2 data source(s) not synced in >7 days (a configurable review threshold, NOT an AWS-mandated limit): - KB 'knowledge-base-semiconductors' source 'knowledge-base-quick-start-qpvuv-data-source' last synced 731 days ago - KB '111122223333-us-east-1-kb' source '111122223333-us-east-1-kb-datasource' last synced 209 days ago Confirm this age is acceptable for each data source's currency requirement — slow-changing reference data may legitimately sync infrequently. Resolution
Sync Knowledge Base data sources on a schedule (weekly at most); stale KB content increases hallucination risk. |
Medium | Failed |
111122223333 |
us-west-2 |
OW-09 |
OWASP LLM09: Knowledge-Base Ingestion Freshness
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check FS-31: 2 data source(s) not synced in >7 days (a configurable review threshold, NOT an AWS-mandated limit): - KB 'knowledge-base-semiconductors' source 'knowledge-base-quick-start-qpvuv-data-source' last synced 731 days ago - KB '111122223333-us-east-1-kb' source '111122223333-us-east-1-kb-datasource' last synced 209 days ago Confirm this age is acceptable for each data source's currency requirement — slow-changing reference data may legitimately sync infrequently. Resolution
Sync Knowledge Base data sources on a schedule (weekly at most); stale KB content increases hallucination risk. |
Medium | Failed |
111122223333 |
us-east-1 |
OW-09 |
OWASP LLM09: Source Attribution
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check FS-32: Source attribution in GenAI responses cannot be verified via AWS APIs. Manual review required to confirm responses include citations. Resolution
Return citations in RetrieveAndGenerate responses so end users can verify grounding. |
Informational | N/A |
111122223333 |
us-east-2 |
OW-09 |
OWASP LLM09: Source Attribution
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check FS-32: Source attribution in GenAI responses cannot be verified via AWS APIs. Manual review required to confirm responses include citations. Resolution
Return citations in RetrieveAndGenerate responses so end users can verify grounding. |
Informational | N/A |
111122223333 |
us-west-2 |
OW-09 |
OWASP LLM09: Source Attribution
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check FS-32: Source attribution in GenAI responses cannot be verified via AWS APIs. Manual review required to confirm responses include citations. Resolution
Return citations in RetrieveAndGenerate responses so end users can verify grounding. |
Informational | N/A |
111122223333 |
us-east-1 |
OW-09 |
OWASP LLM09: KB S3 Data-Source Integrity
Details and remediation |
Medium | Failed |
111122223333 |
us-east-2 |
OW-09 |
OWASP LLM09: KB S3 Data-Source Integrity
Details and remediation |
Medium | Failed |
111122223333 |
us-west-2 |
OW-09 |
OWASP LLM09: KB S3 Data-Source Integrity
Details and remediation |
Medium | Failed |
111122223333 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker Model Card Documentation
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check FS-42: No SageMaker Model Cards found. Production AI models lack documented intended use, limitations, and bias evaluations. Resolution
Create SageMaker Model Cards for production models that document intended use, training data provenance, and bias/fairness evaluations so poisoned or drifted models are detectable against a documented baseline. |
Medium | Failed |
111122223333 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Model Card Documentation
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check FS-42: No SageMaker Model Cards found. Production AI models lack documented intended use, limitations, and bias evaluations. Resolution
Document each production model's intended use, known limitations, and evaluation results in a SageMaker Model Card so misinformation risks tied to model behaviour are traceable to a reviewed system card. |
Medium | Failed |
111122223333 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker Model Card Documentation
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check FS-42: No SageMaker Model Cards found. Production AI models lack documented intended use, limitations, and bias evaluations. Resolution
Create SageMaker Model Cards for production models that document intended use, training data provenance, and bias/fairness evaluations so poisoned or drifted models are detectable against a documented baseline. |
Medium | Failed |
111122223333 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Model Card Documentation
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check FS-42: No SageMaker Model Cards found. Production AI models lack documented intended use, limitations, and bias evaluations. Resolution
Document each production model's intended use, known limitations, and evaluation results in a SageMaker Model Card so misinformation risks tied to model behaviour are traceable to a reviewed system card. |
Medium | Failed |
111122223333 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker Model Card Documentation
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check FS-42: No SageMaker Model Cards found. Production AI models lack documented intended use, limitations, and bias evaluations. Resolution
Create SageMaker Model Cards for production models that document intended use, training data provenance, and bias/fairness evaluations so poisoned or drifted models are detectable against a documented baseline. |
Medium | Failed |
111122223333 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Model Card Documentation
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check FS-42: No SageMaker Model Cards found. Production AI models lack documented intended use, limitations, and bias evaluations. Resolution
Document each production model's intended use, known limitations, and evaluation results in a SageMaker Model Card so misinformation risks tied to model behaviour are traceable to a reviewed system card. |
Medium | Failed |
111122223333 |
us-east-1 |
OW-02 |
OWASP LLM02: CloudWatch Log Data Protection Policies
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-43: No CloudWatch Logs data protection policies found. PII (SSN, account numbers, credit card numbers) in Bedrock invocation logs may be stored in plaintext. Resolution
Apply a CloudWatch Logs data protection policy to log groups that receive Bedrock invocation logs. |
High | Failed |
111122223333 |
us-east-2 |
OW-02 |
OWASP LLM02: CloudWatch Log Data Protection Policies
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-43: No CloudWatch Logs data protection policies found. PII (SSN, account numbers, credit card numbers) in Bedrock invocation logs may be stored in plaintext. Resolution
Apply a CloudWatch Logs data protection policy to log groups that receive Bedrock invocation logs. |
High | Failed |
111122223333 |
us-west-2 |
OW-02 |
OWASP LLM02: CloudWatch Log Data Protection Policies
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-43: No CloudWatch Logs data protection policies found. PII (SSN, account numbers, credit card numbers) in Bedrock invocation logs may be stored in plaintext. Resolution
Apply a CloudWatch Logs data protection policy to log groups that receive Bedrock invocation logs. |
High | Failed |
111122223333 |
us-east-1 |
OW-02 |
OWASP LLM02: Macie Sensitive-Data Discovery
|
High | Passed |
111122223333 |
us-east-2 |
OW-02 |
OWASP LLM02: Macie Sensitive-Data Discovery
|
High | Passed |
111122223333 |
us-west-2 |
OW-02 |
OWASP LLM02: Macie Sensitive-Data Discovery
|
High | Passed |
111122223333 |
us-east-1 |
OW-02 |
OWASP LLM02: Guardrail PII Entities Coverage
Details and remediation |
High | Passed |
111122223333 |
us-east-2 |
OW-02 |
OWASP LLM02: Guardrail PII Entities Coverage
Details and remediation |
High | Passed |
111122223333 |
us-west-2 |
OW-02 |
OWASP LLM02: Guardrail PII Entities Coverage
Details and remediation |
High | Passed |
111122223333 |
us-east-1 |
OW-02 |
OWASP LLM02: S3 Data-Classification Tagging
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-46: 18 AI/ML bucket(s) without data-classification tags: 111122223333-us-east-1-kb-data-bucket, ancbedrocklogging, ancknowledgebase, aws-streaming-data-solut-outputaccesslogsbucket8b-1o7m0kb4bafm4, bedrock-agentcore-codebuild-sources-111122223333-us-east-1, bedrock-bda-us-east-1-dda43109-6557-48bb-993d-3f97126b64b4, bedrock-bda-us-east-1-logging-00719114-debd-4487-85d1-09cbc3fc8, bedrock-kb-bucket-f736570b, bedrock-video-generation-us-east-1-h5ltpm, create-customer-resources-kb-bucket-111122223333. Resolution
Tag training and knowledge-base S3 buckets with a data-classification tag so downstream automations enforce controls consistent with the sensitivity level. |
Medium | Failed |
111122223333 |
us-east-2 |
OW-02 |
OWASP LLM02: S3 Data-Classification Tagging
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-46: 18 AI/ML bucket(s) without data-classification tags: 111122223333-us-east-1-kb-data-bucket, ancbedrocklogging, ancknowledgebase, aws-streaming-data-solut-outputaccesslogsbucket8b-1o7m0kb4bafm4, bedrock-agentcore-codebuild-sources-111122223333-us-east-1, bedrock-bda-us-east-1-dda43109-6557-48bb-993d-3f97126b64b4, bedrock-bda-us-east-1-logging-00719114-debd-4487-85d1-09cbc3fc8, bedrock-kb-bucket-f736570b, bedrock-video-generation-us-east-1-h5ltpm, create-customer-resources-kb-bucket-111122223333. Resolution
Tag training and knowledge-base S3 buckets with a data-classification tag so downstream automations enforce controls consistent with the sensitivity level. |
Medium | Failed |
111122223333 |
us-west-2 |
OW-02 |
OWASP LLM02: S3 Data-Classification Tagging
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-46: 18 AI/ML bucket(s) without data-classification tags: 111122223333-us-east-1-kb-data-bucket, ancbedrocklogging, ancknowledgebase, aws-streaming-data-solut-outputaccesslogsbucket8b-1o7m0kb4bafm4, bedrock-agentcore-codebuild-sources-111122223333-us-east-1, bedrock-bda-us-east-1-dda43109-6557-48bb-993d-3f97126b64b4, bedrock-bda-us-east-1-logging-00719114-debd-4487-85d1-09cbc3fc8, bedrock-kb-bucket-f736570b, bedrock-video-generation-us-east-1-h5ltpm, create-customer-resources-kb-bucket-111122223333. Resolution
Tag training and knowledge-base S3 buckets with a data-classification tag so downstream automations enforce controls consistent with the sensitivity level. |
Medium | Failed |
111122223333 |
us-east-1 |
OW-09 |
OWASP LLM09: Grounding Filter Threshold
|
High | Passed |
111122223333 |
us-east-2 |
OW-09 |
OWASP LLM09: Grounding Filter Threshold
|
High | Passed |
111122223333 |
us-west-2 |
OW-09 |
OWASP LLM09: Grounding Filter Threshold
|
High | Passed |
111122223333 |
us-east-1 |
OW-09 |
OWASP LLM09: Active Knowledge Base Present
|
Medium | Passed |
111122223333 |
us-east-2 |
OW-09 |
OWASP LLM09: Active Knowledge Base Present
|
Medium | Passed |
111122223333 |
us-west-2 |
OW-09 |
OWASP LLM09: Active Knowledge Base Present
|
Medium | Passed |
111122223333 |
us-east-1 |
OW-01 |
OWASP LLM01: PROMPT_ATTACK Filter at Standard Tier
Details and remediation |
High | Failed |
111122223333 |
us-east-2 |
OW-01 |
OWASP LLM01: PROMPT_ATTACK Filter at Standard Tier
Details and remediation |
High | Failed |
111122223333 |
us-west-2 |
OW-01 |
OWASP LLM01: PROMPT_ATTACK Filter at Standard Tier
Details and remediation |
High | Failed |
111122223333 |
us-east-1 |
OW-01 |
OWASP LLM01: Bedrock-Calling Lambda Runtimes
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check FS-52: Functions on deprecated runtimes: e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk, e2ebedrockrag-OSSInfraSta-OSSIndexCreationProvider-g56en9UzRjII. Deprecated runtimes may use outdated boto3/SDK versions lacking security patches. Resolution
Ensure Lambda functions that invoke Bedrock use a supported (non-deprecated) runtime to receive security patches. |
Medium | Failed |
111122223333 |
us-east-2 |
OW-01 |
OWASP LLM01: Bedrock-Calling Lambda Runtimes
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check FS-52: Functions on deprecated runtimes: e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk, e2ebedrockrag-OSSInfraSta-OSSIndexCreationProvider-g56en9UzRjII. Deprecated runtimes may use outdated boto3/SDK versions lacking security patches. Resolution
Ensure Lambda functions that invoke Bedrock use a supported (non-deprecated) runtime to receive security patches. |
Medium | Failed |
111122223333 |
us-west-2 |
OW-01 |
OWASP LLM01: Bedrock-Calling Lambda Runtimes
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check FS-52: Functions on deprecated runtimes: e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk, e2ebedrockrag-OSSInfraSta-OSSIndexCreationProvider-g56en9UzRjII. Deprecated runtimes may use outdated boto3/SDK versions lacking security patches. Resolution
Ensure Lambda functions that invoke Bedrock use a supported (non-deprecated) runtime to receive security patches. |
Medium | Failed |
111122223333 |
us-east-1 |
OW-01 |
OWASP LLM01: WAF SQLi & KnownBadInputs Coverage
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-01 |
OWASP LLM01: WAF SQLi & KnownBadInputs Coverage
|
Informational | N/A |
111122223333 |
us-west-2 |
OW-01 |
OWASP LLM01: WAF SQLi & KnownBadInputs Coverage
|
Informational | N/A |
111122223333 |
us-east-1 |
OW-01 |
OWASP LLM01: Adversarial Testing Evidence
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check FS-54: Penetration testing evidence cannot be verified via AWS APIs. Manual review required to confirm GenAI applications have been tested. Resolution
Track adversarial / red-team penetration test evidence for the GenAI application via resource tags or an equivalent audit trail. |
Informational | N/A |
111122223333 |
us-east-2 |
OW-01 |
OWASP LLM01: Adversarial Testing Evidence
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check FS-54: Penetration testing evidence cannot be verified via AWS APIs. Manual review required to confirm GenAI applications have been tested. Resolution
Track adversarial / red-team penetration test evidence for the GenAI application via resource tags or an equivalent audit trail. |
Informational | N/A |
111122223333 |
us-west-2 |
OW-01 |
OWASP LLM01: Adversarial Testing Evidence
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check FS-54: Penetration testing evidence cannot be verified via AWS APIs. Manual review required to confirm GenAI applications have been tested. Resolution
Track adversarial / red-team penetration test evidence for the GenAI application via resource tags or an equivalent audit trail. |
Informational | N/A |
111122223333 |
us-east-1 |
OW-05 |
OWASP LLM05: Output-Validation Lambda
Details and remediationDetails
OWASP category: LLM05:2025 Improper Output Handling. Source check FS-55: No Lambda functions with output validation/sanitization naming found. GenAI outputs may be passed directly to downstream systems without validation. Resolution
Deploy an output-validation / sanitisation Lambda between the model response and any downstream consumer to filter injection payloads in generated output. |
Medium | Failed |
111122223333 |
us-east-2 |
OW-05 |
OWASP LLM05: Output-Validation Lambda
Details and remediationDetails
OWASP category: LLM05:2025 Improper Output Handling. Source check FS-55: No Lambda functions with output validation/sanitization naming found. GenAI outputs may be passed directly to downstream systems without validation. Resolution
Deploy an output-validation / sanitisation Lambda between the model response and any downstream consumer to filter injection payloads in generated output. |
Medium | Failed |
111122223333 |
us-west-2 |
OW-05 |
OWASP LLM05: Output-Validation Lambda
Details and remediationDetails
OWASP category: LLM05:2025 Improper Output Handling. Source check FS-55: No Lambda functions with output validation/sanitization naming found. GenAI outputs may be passed directly to downstream systems without validation. Resolution
Deploy an output-validation / sanitisation Lambda between the model response and any downstream consumer to filter injection payloads in generated output. |
Medium | Failed |
111122223333 |
us-east-1 |
OW-05 |
OWASP LLM05: WAF XSS Protection
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-05 |
OWASP LLM05: WAF XSS Protection
|
Informational | N/A |
111122223333 |
us-west-2 |
OW-05 |
OWASP LLM05: WAF XSS Protection
|
Informational | N/A |
111122223333 |
us-east-1 |
OW-05 |
OWASP LLM05: Output Encoding Libraries
Details and remediationDetails
OWASP category: LLM05:2025 Improper Output Handling. Source check FS-57: Output encoding practices cannot be verified via AWS APIs. Manual code review required. Resolution
Ensure Lambdas that render model output use a well-known output-encoding library appropriate to the downstream sink (HTML, SQL, shell, etc.). |
Informational | N/A |
111122223333 |
us-east-2 |
OW-05 |
OWASP LLM05: Output Encoding Libraries
Details and remediationDetails
OWASP category: LLM05:2025 Improper Output Handling. Source check FS-57: Output encoding practices cannot be verified via AWS APIs. Manual code review required. Resolution
Ensure Lambdas that render model output use a well-known output-encoding library appropriate to the downstream sink (HTML, SQL, shell, etc.). |
Informational | N/A |
111122223333 |
us-west-2 |
OW-05 |
OWASP LLM05: Output Encoding Libraries
Details and remediationDetails
OWASP category: LLM05:2025 Improper Output Handling. Source check FS-57: Output encoding practices cannot be verified via AWS APIs. Manual code review required. Resolution
Ensure Lambdas that render model output use a well-known output-encoding library appropriate to the downstream sink (HTML, SQL, shell, etc.). |
Informational | N/A |
111122223333 |
us-east-1 |
OW-05 |
OWASP LLM05: Step Functions Output Schema Validation
Details and remediationDetails
OWASP category: LLM05:2025 Improper Output Handling. Source check FS-58: Found 0 Lambda function(s) whose names suggest schema/validation handling. Structured-output / JSON-schema validation of GenAI responses is an application-layer control that cannot be verified automatically — manual review required. Resolution
Add explicit schema-validation states in Step Functions workflows that consume model output. |
Informational | N/A |
111122223333 |
us-east-2 |
OW-05 |
OWASP LLM05: Step Functions Output Schema Validation
Details and remediationDetails
OWASP category: LLM05:2025 Improper Output Handling. Source check FS-58: Found 0 Lambda function(s) whose names suggest schema/validation handling. Structured-output / JSON-schema validation of GenAI responses is an application-layer control that cannot be verified automatically — manual review required. Resolution
Add explicit schema-validation states in Step Functions workflows that consume model output. |
Informational | N/A |
111122223333 |
us-west-2 |
OW-05 |
OWASP LLM05: Step Functions Output Schema Validation
Details and remediationDetails
OWASP category: LLM05:2025 Improper Output Handling. Source check FS-58: Found 0 Lambda function(s) whose names suggest schema/validation handling. Structured-output / JSON-schema validation of GenAI responses is an application-layer control that cannot be verified automatically — manual review required. Resolution
Add explicit schema-validation states in Step Functions workflows that consume model output. |
Informational | N/A |
111122223333 |
us-east-1 |
OW-06 |
OWASP LLM06: Agent Transaction Thresholds
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check FS-67: The following agent action-group Lambda functions have no environment variables whose names suggest transaction-value threshold configuration (this is a best-effort heuristic — a threshold enforced in code or in an AgentCore Policy Engine rule would not be detected here, so treat this as a prompt for manual verification rather than a definitive gap). Without explicit limits, agents could initiate unbounded financial transactions: - aiml-security-aiml-security-111122223333-FinServAssessment - aiml-security-aiml-security-111122223333-BedrockAssessment - resco-aiml-BedrockAssessment - aiml-security-aiml-security-111122223333-AgentCoreAssessment - e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk - e2ebedrockrag-OSSInfraSta-OSSIndexCreationProvider-g56en9UzRjII - resco-aiml-AgentCoreAssessment Resolution
Encode agent transaction thresholds in Cedar policies or Lambda configuration so per-action limits are enforced. |
High | Failed |
111122223333 |
us-east-2 |
OW-06 |
OWASP LLM06: Agent Transaction Thresholds
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check FS-67: The following agent action-group Lambda functions have no environment variables whose names suggest transaction-value threshold configuration (this is a best-effort heuristic — a threshold enforced in code or in an AgentCore Policy Engine rule would not be detected here, so treat this as a prompt for manual verification rather than a definitive gap). Without explicit limits, agents could initiate unbounded financial transactions: - aiml-security-aiml-security-111122223333-FinServAssessment - aiml-security-aiml-security-111122223333-BedrockAssessment - resco-aiml-BedrockAssessment - aiml-security-aiml-security-111122223333-AgentCoreAssessment - e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk - e2ebedrockrag-OSSInfraSta-OSSIndexCreationProvider-g56en9UzRjII - resco-aiml-AgentCoreAssessment Resolution
Encode agent transaction thresholds in Cedar policies or Lambda configuration so per-action limits are enforced. |
High | Failed |
111122223333 |
us-west-2 |
OW-06 |
OWASP LLM06: Agent Transaction Thresholds
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check FS-67: The following agent action-group Lambda functions have no environment variables whose names suggest transaction-value threshold configuration (this is a best-effort heuristic — a threshold enforced in code or in an AgentCore Policy Engine rule would not be detected here, so treat this as a prompt for manual verification rather than a definitive gap). Without explicit limits, agents could initiate unbounded financial transactions: - aiml-security-aiml-security-111122223333-FinServAssessment - aiml-security-aiml-security-111122223333-BedrockAssessment - resco-aiml-BedrockAssessment - aiml-security-aiml-security-111122223333-AgentCoreAssessment - e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk - e2ebedrockrag-OSSInfraSta-OSSIndexCreationProvider-g56en9UzRjII - resco-aiml-AgentCoreAssessment Resolution
Encode agent transaction thresholds in Cedar policies or Lambda configuration so per-action limits are enforced. |
High | Failed |
111122223333 |
us-east-1 |
OW-10 |
OWASP LLM10: API Gateway Request Body Size Limits
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-68: Found 3 REST API(s) and 0 regional WAF Web ACL(s), but none enforce a maximum request-body size. Note: an API Gateway request validator does NOT cap body size (it validates the schema and required params; the REST limit is a fixed 10 MB), and a WAF body SizeConstraint only inspects the first ~16 KB of the body by default. Oversized prompts can exhaust Bedrock token quotas and inflate costs. Resolution
Configure API Gateway request validation or an equivalent ingress control so GenAI endpoints reject oversized request bodies before they can drive excessive model consumption. |
Medium | Failed |
111122223333 |
us-east-2 |
OW-10 |
OWASP LLM10: API Gateway Request Body Size Limits
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-68: Found 3 REST API(s) and 0 regional WAF Web ACL(s), but none enforce a maximum request-body size. Note: an API Gateway request validator does NOT cap body size (it validates the schema and required params; the REST limit is a fixed 10 MB), and a WAF body SizeConstraint only inspects the first ~16 KB of the body by default. Oversized prompts can exhaust Bedrock token quotas and inflate costs. Resolution
Configure API Gateway request validation or an equivalent ingress control so GenAI endpoints reject oversized request bodies before they can drive excessive model consumption. |
Medium | Failed |
111122223333 |
us-west-2 |
OW-10 |
OWASP LLM10: API Gateway Request Body Size Limits
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-68: Found 3 REST API(s) and 0 regional WAF Web ACL(s), but none enforce a maximum request-body size. Note: an API Gateway request validator does NOT cap body size (it validates the schema and required params; the REST limit is a fixed 10 MB), and a WAF body SizeConstraint only inspects the first ~16 KB of the body by default. Oversized prompts can exhaust Bedrock token quotas and inflate costs. Resolution
Configure API Gateway request validation or an equivalent ingress control so GenAI endpoints reject oversized request bodies before they can drive excessive model consumption. |
Medium | Failed |
111122223333 |
us-east-1 |
OW-01 |
OWASP LLM01: Prompt-Input Validation Lambda
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check FS-69: Found 3 Lambda function(s) with input validation/sanitization naming patterns: resco-aiml-CleanupBucket, visa-bulletin-tracker-prod-cleanup, aiml-security-aiml-security-111122223333-CleanupBucket. Resolution
Deploy a prompt-input validation Lambda in front of Bedrock invocations to sanitise untrusted input before it reaches the model. |
Medium | Passed |
111122223333 |
us-east-2 |
OW-01 |
OWASP LLM01: Prompt-Input Validation Lambda
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check FS-69: Found 3 Lambda function(s) with input validation/sanitization naming patterns: resco-aiml-CleanupBucket, visa-bulletin-tracker-prod-cleanup, aiml-security-aiml-security-111122223333-CleanupBucket. Resolution
Deploy a prompt-input validation Lambda in front of Bedrock invocations to sanitise untrusted input before it reaches the model. |
Medium | Passed |
111122223333 |
us-west-2 |
OW-01 |
OWASP LLM01: Prompt-Input Validation Lambda
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check FS-69: Found 3 Lambda function(s) with input validation/sanitization naming patterns: resco-aiml-CleanupBucket, visa-bulletin-tracker-prod-cleanup, aiml-security-aiml-security-111122223333-CleanupBucket. Resolution
Deploy a prompt-input validation Lambda in front of Bedrock invocations to sanitise untrusted input before it reaches the model. |
Medium | Passed |
111122223333 |
us-east-1 |
OW-11 |
OWASP LLM07: System Prompt Embedded in Lambda Env Var
|
Medium | Passed |
111122223333 |
us-east-1 |
OW-12 |
OWASP LLM07: System-Prompt-Disclosure Denied Topic
Details and remediationDetails
No Bedrock guardrail in us-east-1 has a DENY topic covering system-prompt disclosure. Attackers can craft prompts that ask the agent to reveal its system prompt or instructions. Resolution
Add a DENY topic to at least one guardrail. Suggested topic name: 'SystemPromptDisclosure'. Suggested definition: 'Requests to reveal, describe, or summarise the system prompt, instructions, or internal role definition given to the assistant.' |
Medium | Failed |
111122223333 |
eu-west-1 |
OW-01 |
OWASP LLM01: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis. |
Informational | N/A |
111122223333 |
eu-west-1 |
OW-07 |
OWASP LLM07: Model Invocation Logging
Details and remediation |
Informational | N/A |
111122223333 |
eu-west-1 |
OW-07 |
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident. |
Informational | N/A |
111122223333 |
eu-west-1 |
OW-07 |
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
|
Informational | N/A |
111122223333 |
eu-west-1 |
OW-09 |
OWASP LLM09: Model Evaluation Jobs
|
Informational | N/A |
111122223333 |
eu-west-1 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
|
Informational | N/A |
111122223333 |
eu-west-1 |
OW-06 |
OWASP LLM06: Agent Action-Group Least Privilege
|
Informational | N/A |
111122223333 |
eu-west-1 |
OW-10 |
OWASP LLM10: Service Quota Throttling Limits
Details and remediation |
Informational | N/A |
111122223333 |
eu-west-1 |
OW-01 |
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier. |
Informational | N/A |
111122223333 |
eu-west-1 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
|
Informational | N/A |
111122223333 |
eu-west-1 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
|
Informational | N/A |
111122223333 |
eu-west-1 |
OW-02 |
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation |
Informational | N/A |
111122223333 |
eu-west-1 |
OW-01 |
OWASP LLM01: Contextual Grounding Guardrail
|
Informational | N/A |
111122223333 |
eu-west-1 |
OW-04 |
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation |
Informational | N/A |
111122223333 |
eu-west-1 |
OW-09 |
OWASP LLM09: Contextual Grounding for Faithfulness
|
Informational | N/A |
111122223333 |
eu-west-1 |
OW-06 |
OWASP LLM06: Bedrock Agent Guardrail Association
|
Informational | N/A |
111122223333 |
eu-west-1 |
OW-06 |
OWASP LLM06: Agent Idle Session TTL
|
Informational | N/A |
111122223333 |
eu-west-1 |
OW-03 |
OWASP LLM03: Imported-Model KMS Provenance
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check BR-30: Unable to check Imported model encryption check: An error occurred (AccessDeniedException) when calling the ListImportedModels operation: Your account is not authorized to invoke this API operation. Resolution
Encrypt imported Bedrock models with a customer-managed KMS key to preserve provenance and access control across model artefacts. |
Informational | N/A |
111122223333 |
eu-west-1 |
OW-10 |
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation |
Informational | N/A |
111122223333 |
eu-west-1 |
OW-03 |
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check BR-33: No Lambda functions with Bedrock indicators were found in eu-west-1; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain. |
Informational | N/A |
111122223333 |
eu-west-1 |
OW-03 |
OWASP LLM03: SageMaker Internet Exposure
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-01: No SageMaker notebook instances or domains found to check Resolution
Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths. |
Informational | N/A |
111122223333 |
eu-west-1 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: No SageMaker resources found to check for data protection Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
Informational | N/A |
111122223333 |
eu-west-1 |
OW-09 |
OWASP LLM09: SageMaker Clarify Evaluation
|
Informational | N/A |
111122223333 |
eu-west-1 |
OW-04 |
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation |
Informational | N/A |
111122223333 |
eu-west-1 |
OW-09 |
OWASP LLM09: SageMaker Model Monitor Coverage
|
Informational | N/A |
111122223333 |
eu-west-1 |
OW-03 |
OWASP LLM03: SageMaker Notebook VPC Deployment
|
Informational | N/A |
111122223333 |
eu-west-1 |
OW-03 |
OWASP LLM03: SageMaker Model Network Isolation
|
Informational | N/A |
111122223333 |
eu-west-1 |
OW-10 |
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation |
Informational | N/A |
111122223333 |
eu-west-1 |
OW-03 |
OWASP LLM03: SageMaker Container Repository Access
Details and remediation |
Informational | N/A |
111122223333 |
eu-west-1 |
OW-02 |
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation |
Informational | N/A |
111122223333 |
eu-west-1 |
OW-03 |
OWASP LLM03: SageMaker AutoML Network Isolation
|
Informational | N/A |
111122223333 |
eu-west-1 |
OW-04 |
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically. |
Informational | N/A |
111122223333 |
eu-west-1 |
OW-09 |
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release. |
Informational | N/A |
111122223333 |
eu-west-1 |
OW-04 |
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
111122223333 |
eu-west-1 |
OW-09 |
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
111122223333 |
eu-west-1 |
OW-03 |
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain. |
Informational | N/A |
111122223333 |
eu-west-1 |
OW-04 |
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated. |
Informational | N/A |
111122223333 |
eu-west-1 |
OW-06 |
OWASP LLM06: AgentCore Resource-Based Policies
|
Informational | N/A |
111122223333 |
eu-west-1 |
OW-11 |
OWASP LLM07: System Prompt Embedded in Lambda Env Var
|
Informational | N/A |
111122223333 |
eu-west-1 |
OW-12 |
OWASP LLM07: System-Prompt-Disclosure Denied Topic
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-02 |
Amazon Bedrock private connectivity check
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-04 |
Bedrock Model Invocation Logging Check
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-05 |
Bedrock Guardrails Check
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-06 |
Bedrock CloudTrail Logging Check
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-07 |
Bedrock Prompt Management Check
Details and remediationDetails
Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates |
Informational | N/A |
111122223333 |
us-east-2 |
BR-08 |
Bedrock Agent IAM Roles Check
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-09 |
Bedrock Knowledge Base Encryption Check
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-10 |
Bedrock Guardrail IAM Enforcement Check
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-11 |
Bedrock Custom Model Encryption Check
|
Low | N/A |
111122223333 |
us-east-2 |
BR-12 |
Bedrock Invocation Log Encryption Check
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-13 |
Bedrock Flows Guardrails Check
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-16 |
Guardrail Tier Validation Check
|
Medium | N/A |
111122223333 |
us-east-2 |
BR-17 |
Custom Model Customer-Managed KMS Encryption Check
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-18 |
Model Evaluation Implementation Check
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-19 |
Prompt Flow Validation Check
|
Medium | N/A |
111122223333 |
us-east-2 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Check
|
High | N/A |
111122223333 |
us-east-2 |
BR-21 |
Agent Action Group IAM Least Privilege Check
|
High | N/A |
111122223333 |
us-east-2 |
BR-22 |
Model Invocation Throttling Limits Check
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-23 |
Guardrail Content Filter Coverage Check
|
High | N/A |
111122223333 |
us-east-2 |
BR-24 |
Automated Reasoning Policy Implementation Check
|
Medium | N/A |
111122223333 |
us-east-2 |
BR-25 |
RAG Evaluation Jobs Check
|
Low | N/A |
111122223333 |
us-east-2 |
BR-26 |
Guardrail Sensitive Information Filter Check
|
High | N/A |
111122223333 |
us-east-2 |
BR-27 |
Guardrail Contextual Grounding Check
|
Medium | N/A |
111122223333 |
us-east-2 |
BR-28 |
Agent Guardrail Association Check
|
High | N/A |
111122223333 |
us-east-2 |
BR-29 |
Agent Idle Session TTL Check
|
Low | N/A |
111122223333 |
us-east-2 |
BR-30 |
Imported Model Customer-Managed KMS Encryption Check
|
High | N/A |
111122223333 |
us-east-2 |
BR-31 |
Batch Inference Output Encryption Check
|
Medium | N/A |
111122223333 |
us-east-2 |
BR-32 |
Bedrock CloudWatch Alarm Check
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-33 |
Amazon Inspector Lambda Code Scanning Check
Details and remediationDetails
No Lambda functions with Bedrock indicators were found in us-east-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
No action required. If Bedrock-calling Lambda functions exist, ensure their function name, ARN, description, handler, role, or environment variables contain a Bedrock identifier that the assessment can detect, or evaluate Inspector coverage manually. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-07 |
Agentic AI Model Invocation Logging
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-08 |
Agentic AI API Audit Trail
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage Resolution
Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-10 |
Agentic AI Adversarial Evaluation Coverage
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs Resolution
Configure model or application evaluations that include adversarial, safety, and security-relevant test cases. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-11 |
Agentic AI Prompt Flow Validation
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region Resolution
Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-06 |
Agentic AI Tool Execution Least Privilege
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region Resolution
Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-12 |
Agentic AI Invocation Abuse Controls
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas Resolution
Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-02 |
Agentic AI Harmful Content Guardrail Coverage
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-04 |
Agentic AI Automated Reasoning Guardrails
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: No Bedrock guardrails configured in this region Resolution
Configure automated reasoning policies on guardrails where formal response validation is required. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-03 |
Agentic AI Sensitive Information Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: No Bedrock guardrails configured in this region Resolution
Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-05 |
Agentic AI Grounding Controls
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: No Bedrock guardrails configured in this region Resolution
Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-01 |
Agentic AI Agent Guardrail Association
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region Resolution
Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-13 |
Agentic AI Session Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region Resolution
Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-14 |
Agentic AI Operational Abuse Alarms
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms Resolution
Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available. |
Informational | N/A |
111122223333 |
eu-west-1 |
SM-01 |
SageMaker Internet Access Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
SM-02 |
SageMaker SSO Configuration Check
|
Medium | Passed |
111122223333 |
eu-west-1 |
SM-03 |
Data Protection Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
SM-04 |
GuardDuty Enabled
|
Medium | Passed |
111122223333 |
eu-west-1 |
SM-05 |
SageMaker Model Registry Issue
|
Informational | N/A |
111122223333 |
eu-west-1 |
SM-05 |
SageMaker Feature Store Issue
|
Informational | N/A |
111122223333 |
eu-west-1 |
SM-05 |
SageMaker Pipelines Issue
|
Informational | N/A |
111122223333 |
eu-west-1 |
SM-06 |
SageMaker Clarify No Clarify Usage
|
Informational | N/A |
111122223333 |
eu-west-1 |
SM-07 |
SageMaker Model Monitor No Model Monitoring
|
Informational | N/A |
111122223333 |
eu-west-1 |
SM-08 |
Model Registry Registry Not Used
|
Informational | N/A |
111122223333 |
eu-west-1 |
SM-09 |
SageMaker Notebook Root Access Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
SM-10 |
SageMaker Notebook VPC Deployment Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
SM-11 |
SageMaker Model Network Isolation Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
SM-12 |
SageMaker Endpoint Instance Count Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
SM-13 |
SageMaker Monitoring Network Isolation Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
SM-14 |
SageMaker Model Repository Access Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
SM-15 |
SageMaker Feature Store Encryption Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
SM-16 |
SageMaker Data Quality Job Encryption Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
SM-17 |
SageMaker Processing Job Encryption Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
SM-18 |
SageMaker Transform Job Encryption Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
SM-19 |
SageMaker Hyperparameter Tuning Job Encryption Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
SM-20 |
SageMaker Compilation Job Encryption Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
SM-21 |
SageMaker AutoML Job Network Isolation Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
SM-22 |
Model Approval Workflow Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
SM-23 |
Model Drift Detection Check
|
Medium | Passed |
111122223333 |
eu-west-1 |
SM-24 |
A/B Testing and Shadow Deployment Check
|
Low | Passed |
111122223333 |
eu-west-1 |
SM-25 |
ML Lineage Tracking - Experiments Not Used
|
Informational | N/A |
111122223333 |
eu-west-1 |
BR-02 |
Amazon Bedrock private connectivity check
|
Informational | N/A |
111122223333 |
eu-west-1 |
BR-04 |
Bedrock Model Invocation Logging Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
BR-05 |
Bedrock Guardrails Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
BR-06 |
Bedrock CloudTrail Logging Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
BR-07 |
Bedrock Prompt Management Check
Details and remediationDetails
Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates |
Informational | N/A |
111122223333 |
eu-west-1 |
BR-08 |
Bedrock Agent IAM Roles Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
BR-09 |
Bedrock Knowledge Base Encryption Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
BR-10 |
Bedrock Guardrail IAM Enforcement Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
BR-11 |
Bedrock Custom Model Encryption Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
BR-12 |
Bedrock Invocation Log Encryption Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
BR-13 |
Bedrock Flows Guardrails Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
BR-16 |
Guardrail Tier Validation Check
|
Medium | N/A |
111122223333 |
eu-west-1 |
BR-17 |
Custom Model Customer-Managed KMS Encryption Check
|
High | N/A |
111122223333 |
eu-west-1 |
BR-18 |
Model Evaluation Implementation Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
BR-19 |
Prompt Flow Validation Check
|
Medium | N/A |
111122223333 |
eu-west-1 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Check
|
High | N/A |
111122223333 |
eu-west-1 |
BR-21 |
Agent Action Group IAM Least Privilege Check
|
High | N/A |
111122223333 |
eu-west-1 |
BR-22 |
Model Invocation Throttling Limits Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
BR-23 |
Guardrail Content Filter Coverage Check
|
High | N/A |
111122223333 |
eu-west-1 |
BR-24 |
Automated Reasoning Policy Implementation Check
|
Medium | N/A |
111122223333 |
eu-west-1 |
BR-25 |
RAG Evaluation Jobs Check
|
Low | N/A |
111122223333 |
eu-west-1 |
BR-26 |
Guardrail Sensitive Information Filter Check
|
High | N/A |
111122223333 |
eu-west-1 |
BR-27 |
Guardrail Contextual Grounding Check
|
Medium | N/A |
111122223333 |
eu-west-1 |
BR-28 |
Agent Guardrail Association Check
|
High | N/A |
111122223333 |
eu-west-1 |
BR-29 |
Agent Idle Session TTL Check
|
Low | N/A |
111122223333 |
eu-west-1 |
BR-30 |
Imported Model Customer-Managed KMS Encryption Check
Details and remediationDetails
Unable to check Imported model encryption check: An error occurred (AccessDeniedException) when calling the ListImportedModels operation: Your account is not authorized to invoke this API operation. Resolution
Amazon Bedrock Custom Model Import is not enabled or available for this account in this region. No IAM change is required; the check applies only once model import is in use. |
Low | N/A |
111122223333 |
eu-west-1 |
BR-31 |
Batch Inference Output Encryption Check
|
Medium | N/A |
111122223333 |
eu-west-1 |
BR-32 |
Bedrock CloudWatch Alarm Check
|
Informational | N/A |
111122223333 |
eu-west-1 |
BR-33 |
Amazon Inspector Lambda Code Scanning Check
Details and remediationDetails
No Lambda functions with Bedrock indicators were found in eu-west-1; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
No action required. If Bedrock-calling Lambda functions exist, ensure their function name, ARN, description, handler, role, or environment variables contain a Bedrock identifier that the assessment can detect, or evaluate Inspector coverage manually. |
Informational | N/A |
111122223333 |
eu-west-1 |
AG-07 |
Agentic AI Model Invocation Logging
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements. |
Informational | N/A |
111122223333 |
eu-west-1 |
AG-08 |
Agentic AI API Audit Trail
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage Resolution
Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured. |
Informational | N/A |
111122223333 |
eu-west-1 |
AG-10 |
Agentic AI Adversarial Evaluation Coverage
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs Resolution
Configure model or application evaluations that include adversarial, safety, and security-relevant test cases. |
Informational | N/A |
111122223333 |
eu-west-1 |
AG-11 |
Agentic AI Prompt Flow Validation
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region Resolution
Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions. |
Informational | N/A |
111122223333 |
eu-west-1 |
AG-06 |
Agentic AI Tool Execution Least Privilege
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region Resolution
Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required. |
Informational | N/A |
111122223333 |
eu-west-1 |
AG-12 |
Agentic AI Invocation Abuse Controls
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas Resolution
Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns. |
Informational | N/A |
111122223333 |
eu-west-1 |
AG-02 |
Agentic AI Harmful Content Guardrail Coverage
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads. |
Informational | N/A |
111122223333 |
eu-west-1 |
AG-04 |
Agentic AI Automated Reasoning Guardrails
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: No Bedrock guardrails configured in this region Resolution
Configure automated reasoning policies on guardrails where formal response validation is required. |
Informational | N/A |
111122223333 |
eu-west-1 |
AG-03 |
Agentic AI Sensitive Information Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: No Bedrock guardrails configured in this region Resolution
Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns. |
Informational | N/A |
111122223333 |
eu-west-1 |
AG-05 |
Agentic AI Grounding Controls
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: No Bedrock guardrails configured in this region Resolution
Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows. |
Informational | N/A |
111122223333 |
eu-west-1 |
AG-01 |
Agentic AI Agent Guardrail Association
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region Resolution
Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating. |
Informational | N/A |
111122223333 |
eu-west-1 |
AG-13 |
Agentic AI Session Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region Resolution
Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements. |
Informational | N/A |
111122223333 |
eu-west-1 |
AG-14 |
Agentic AI Operational Abuse Alarms
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms Resolution
Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available. |
Informational | N/A |
111122223333 |
Global |
SM-02 |
SageMaker Full Access Policy Used
|
High | Failed |
111122223333 |
Global |
SM-02 |
SageMaker Full Access Policy Used
|
High | Failed |
111122223333 |
Global |
SM-02 |
SageMaker Full Access Policy Used
|
High | Failed |
111122223333 |
Global |
SM-02 |
SageMaker Full Access Policy Used
|
High | Failed |
111122223333 |
Global |
SM-02 |
SageMaker Full Access Policy Used
|
High | Failed |
111122223333 |
Global |
SM-02 |
SageMaker Full Access Policy Used
|
High | Failed |
111122223333 |
Global |
SM-02 |
SageMaker Full Access Policy Used
|
High | Failed |
111122223333 |
us-east-1 |
SM-01 |
Non-VPC Only Network Access
|
High | Failed |
111122223333 |
us-east-1 |
SM-02 |
SSO Not Properly Configured
Details and remediation |
Medium | Failed |
111122223333 |
us-east-1 |
SM-03 |
Missing Encryption Configuration
|
High | Failed |
111122223333 |
us-east-1 |
SM-04 |
GuardDuty Enabled
|
Medium | Passed |
111122223333 |
us-east-1 |
SM-05 |
SageMaker Model Registry Issue
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-05 |
SageMaker Feature Store Issue
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-05 |
SageMaker Pipelines Issue
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-06 |
SageMaker Clarify No Clarify Usage
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-07 |
SageMaker Model Monitor No Model Monitoring
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-08 |
Model Registry Registry Not Used
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-09 |
SageMaker Notebook Root Access Check
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-10 |
SageMaker Notebook VPC Deployment Check
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-11 |
SageMaker Model Network Isolation Check
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-12 |
SageMaker Endpoint Instance Count Check
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-13 |
SageMaker Monitoring Network Isolation Check
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-14 |
SageMaker Model Repository Access Check
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-15 |
SageMaker Feature Store Encryption Check
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-16 |
SageMaker Data Quality Job Encryption Check
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-17 |
SageMaker Processing Job Encryption Check
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-18 |
SageMaker Transform Job Encryption Check
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-19 |
SageMaker Hyperparameter Tuning Job Encryption Check
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-20 |
SageMaker Compilation Job Encryption Check
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-21 |
SageMaker AutoML Job Network Isolation Check
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-22 |
Model Approval Workflow Check
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-23 |
Model Drift Detection Check
|
Medium | Passed |
111122223333 |
us-east-1 |
SM-24 |
A/B Testing and Shadow Deployment Check
|
Low | Passed |
111122223333 |
us-east-1 |
SM-25 |
ML Lineage Tracking - Experiments Not Used
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-01 |
Non-VPC Only Network Access
|
High | Failed |
111122223333 |
us-west-2 |
SM-02 |
SSO Not Properly Configured
|
Medium | Failed |
111122223333 |
us-west-2 |
SM-03 |
Missing Encryption Configuration
|
High | Failed |
111122223333 |
us-west-2 |
SM-04 |
GuardDuty Enabled
|
Medium | Passed |
111122223333 |
us-west-2 |
SM-05 |
SageMaker Model Registry Issue
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-05 |
SageMaker Feature Store Issue
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-05 |
SageMaker Pipelines Issue
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-06 |
SageMaker Clarify No Clarify Usage
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-07 |
SageMaker Model Monitor No Model Monitoring
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-08 |
Model Registry Registry Not Used
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-09 |
SageMaker Notebook Root Access Check
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-10 |
SageMaker Notebook VPC Deployment Check
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-11 |
SageMaker Model Network Isolation Check
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-12 |
SageMaker Endpoint Instance Count Check
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-13 |
SageMaker Monitoring Network Isolation Check
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-14 |
SageMaker Model Repository Access Check
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-15 |
SageMaker Feature Store Encryption Check
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-16 |
SageMaker Data Quality Job Encryption Check
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-17 |
SageMaker Processing Job Encryption Check
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-18 |
SageMaker Transform Job Encryption Check
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-19 |
SageMaker Hyperparameter Tuning Job Encryption Check
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-20 |
SageMaker Compilation Job Encryption Check
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-21 |
SageMaker AutoML Job Network Isolation Check
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-22 |
Model Approval Workflow Check
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-23 |
Model Drift Detection Check
|
Medium | Passed |
111122223333 |
us-west-2 |
SM-24 |
A/B Testing and Shadow Deployment Check
|
Low | Passed |
111122223333 |
us-west-2 |
SM-25 |
ML Lineage Tracking - Experiments Not Used
|
Informational | N/A |
111122223333 |
Global |
BR-01 |
AmazonBedrockFullAccess role check
|
High | Failed |
111122223333 |
Global |
BR-01 |
AmazonBedrockFullAccess role check
|
High | Failed |
111122223333 |
Global |
BR-01 |
AmazonBedrockFullAccess role check
|
High | Failed |
111122223333 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
Role 'AmazonBedrockAgentCoreSDKRuntime-us-east-1-a6ddf3fc76' has overly permissive marketplace subscription access through policy 'BedrockAgentCoreRuntimeExecutionPolicy-cdk_agent_core' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | Failed |
111122223333 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
Role 'AmazonBedrockAgentCoreSDKRuntime-us-east-1-ed660add8b' has overly permissive marketplace subscription access through policy 'BedrockAgentCoreRuntimeExecutionPolicy-neoCyan_Agent' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | Failed |
111122223333 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
Role 'AmazonBedrockExecutionRoleForKnowledgeBase_knnc9' has overly permissive marketplace subscription access through policy 'AmazonBedrockFoundationModelPolicyForKnowledgeBase_knnc9' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | Failed |
111122223333 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
Role 'AmazonBedrockExecutionRoleForKnowledgeBase_qxqw2' has overly permissive marketplace subscription access through policy 'AmazonBedrockFoundationModelPolicyForKnowledgeBase_qxqw2' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | Failed |
111122223333 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
Role 'AmazonSageMaker-ExecutionRole-20250525T153161' has overly permissive marketplace subscription access through policy 'AmazonBedrockLimitedAccess' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | Failed |
111122223333 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
Role 'IDPSageMakerCfnStack-SageMakerExecutionRole-aqrHz6dVkoHC' has overly permissive marketplace subscription access through policy 'AmazonBedrockFullAccess' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | Failed |
111122223333 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
Role 'LLMEvaluationPromptfoo-SageMakerExecutionRole-M69xCHJ9c3LU' has overly permissive marketplace subscription access through policy 'AmazonBedrockFullAccess' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | Failed |
111122223333 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
Role 'myAskMeAnything-role-kmsizqwf' has overly permissive marketplace subscription access through policy 'AmazonBedrockFullAccess' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | Failed |
111122223333 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
User 'BedrockAPIKey-20pp' has overly permissive marketplace subscription access through policy 'AmazonBedrockLimitedAccess' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | Failed |
111122223333 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
User 'BedrockAPIKey-yhc3' has overly permissive marketplace subscription access through policy 'AmazonBedrockLimitedAccess' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | Failed |
111122223333 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
User 'BedrockClientUser' has overly permissive marketplace subscription access through policy 'AmazonBedrockFullAccess' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | Failed |
111122223333 |
us-east-1 |
BR-02 |
Amazon Bedrock private connectivity not used
Details and remediationDetails
No Bedrock service VPC endpoints found in VPCs: vpc-03472be90d65c2f68, vpc-39319f44, vpc-064f3e808e378cbc8, vpc-02d020a365a06c7fe Resolution
Create a VPC endpoint in your VPC with any of the following Bedrock service endpoints that your application may be using: - com.amazonaws.region.bedrock - com.amazonaws.region.bedrock-runtime - com.amazonaws.region.bedrock-agent - com.amazonaws.region.bedrock-agent-runtime |
Medium | Failed |
111122223333 |
us-east-1 |
BR-04 |
Bedrock Model Invocation Logging Check
|
Medium | Passed |
111122223333 |
us-east-1 |
BR-05 |
Bedrock Guardrails Check
|
High | Passed |
111122223333 |
us-east-1 |
BR-06 |
Bedrock CloudTrail Logging Check
|
Medium | Passed |
111122223333 |
us-east-1 |
BR-07 |
Bedrock Prompt Management Check
Details and remediationDetails
Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates |
Informational | N/A |
111122223333 |
us-east-1 |
BR-08 |
Bedrock Agent IAM Roles Check
|
Informational | N/A |
111122223333 |
us-east-1 |
BR-09 |
Bedrock Knowledge Base Encryption Review
Details and remediationDetails
Knowledge Base 'knowledge-base-semiconductors' (RQYFDSE1LT) uses 'OPENSEARCH_SERVERLESS' storage. Encryption is managed at the storage layer and cannot be validated from the KB API. Verify encryption configuration on the underlying storage resource. Resolution
1. For OpenSearch Serverless: Verify encryption with CMK at collection level 2. For S3 data sources: Verify CMK-encrypted S3 buckets 3. For RDS: Verify KMS encryption on the database 4. Consider using CMK for transient data during ingestion |
Informational | N/A |
111122223333 |
us-east-1 |
BR-09 |
Bedrock Knowledge Base Encryption Review
Details and remediationDetails
Knowledge Base '111122223333-us-east-1-kb' (PAJOKBSIMQ) uses 'S3_VECTORS' storage. Encryption is managed at the storage layer and cannot be validated from the KB API. Verify encryption configuration on the underlying storage resource. Resolution
1. For OpenSearch Serverless: Verify encryption with CMK at collection level 2. For S3 data sources: Verify CMK-encrypted S3 buckets 3. For RDS: Verify KMS encryption on the database 4. Consider using CMK for transient data during ingestion |
Informational | N/A |
111122223333 |
us-east-1 |
BR-09 |
Bedrock Knowledge Base Encryption Review
Details and remediationDetails
Knowledge Base 'e2e-rag-knowledgebase' (ESIYAYSYTJ) uses 'OPENSEARCH_SERVERLESS' storage. Encryption is managed at the storage layer and cannot be validated from the KB API. Verify encryption configuration on the underlying storage resource. Resolution
1. For OpenSearch Serverless: Verify encryption with CMK at collection level 2. For S3 data sources: Verify CMK-encrypted S3 buckets 3. For RDS: Verify KMS encryption on the database 4. Consider using CMK for transient data during ingestion |
Informational | N/A |
111122223333 |
us-east-1 |
BR-10 |
Bedrock Guardrail IAM Enforcement Missing
Details and remediationDetails
The following roles can invoke Bedrock models without enforced guardrails: 111122223333-us-east-1-kb-bedrock-service-role, agentcore-wildrydes_gateway_role_ab3991f6-role, AgentCoreEvalsSDK-us-east-1-d04ba7b68b, AmazonBedrockAgentCoreSDKRuntime-us-east-1-a6ddf3fc76, AmazonBedrockAgentCoreSDKRuntime-us-east-1-ed660add8b, AmazonBedrockExecutionRoleForAgents_S0T9VNPP9D, AmazonBedrockExecutionRoleForAgents_WNCOPE29NZ, AmazonBedrockExecutionRoleForKnowledgeBase_072pr, AmazonBedrockExecutionRoleForKnowledgeBase_byjin, AmazonBedrockExecutionRoleForKnowledgeBase_h9718... Resolution
Add IAM policy conditions to enforce guardrail usage: 1. Use 'bedrock:GuardrailIdentifier' condition key 2. Specify required guardrail ARN or ID 3. Example: "Condition": {"StringEquals": {"bedrock:GuardrailIdentifier": "arn:aws:bedrock:region:account:guardrail/guardrail-id"}} |
High | Failed |
111122223333 |
us-east-1 |
BR-11 |
Bedrock Custom Model Encryption Check
|
Informational | N/A |
111122223333 |
us-east-1 |
BR-12 |
Bedrock Invocation Log Encryption
Details and remediationDetails
S3 bucket 'nistairmfguardrail-invocationlogsbucket8fe5371b-wmlsng7pkyhm' for invocation logs uses SSE-S3 encryption instead of customer-managed KMS. Invocation logs may contain sensitive prompts and responses. Resolution
1. Enable SSE-KMS with a customer-managed key on the S3 bucket 2. Update bucket policy to require encrypted uploads 3. Consider enabling S3 bucket versioning and MFA delete for log integrity |
Medium | Failed |
111122223333 |
us-east-1 |
BR-13 |
Bedrock Flows Guardrails Check
|
Informational | N/A |
111122223333 |
Global |
BR-15 |
Cross-Account Guardrails Enforcement Check
|
Medium | N/A |
111122223333 |
us-east-1 |
BR-16 |
Guardrail Tier Validation Check
Details and remediationDetails
Guardrail 'nist-ai-rmf-guardrail' (ID: do7xkmhadx7k) is using the 'CLASSIC' content-filter tier instead of 'STANDARD'. The STANDARD tier provides more robust content filtering and broader language support than the CLASSIC tier. Resolution
Update the guardrail to use the STANDARD content-filter tier for improved contextual understanding, better prompt attack filtering (distinguishing jailbreaks from prompt injection), and broader language support. The STANDARD tier requires cross-Region inference. Review pricing implications before upgrading. |
Medium | Failed |
111122223333 |
us-east-1 |
BR-17 |
Custom Model Customer-Managed KMS Encryption Check
|
High | N/A |
111122223333 |
us-east-1 |
BR-18 |
Model Evaluation Implementation Check
Details and remediationDetails
No Bedrock model evaluation jobs found. Model evaluation helps assess toxicity, accuracy, semantic robustness, and other safety metrics before production deployment. Resolution
Create model evaluation jobs using Amazon Bedrock Evaluations to assess foundation model performance against safety and quality metrics. Use built-in datasets or custom test sets. Enable LLM-as-a-judge evaluation for comprehensive assessment. |
Medium | Failed |
111122223333 |
us-east-1 |
BR-19 |
Prompt Flow Validation Check
|
Medium | N/A |
111122223333 |
us-east-1 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Review
Details and remediationDetails
Knowledge base 'knowledge-base-semiconductors' (ID: RQYFDSE1LT) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
1. For OpenSearch Serverless: verify the collection uses a customer-managed KMS key 2. For Amazon RDS/Aurora: verify KMS encryption on the database 3. For third-party stores (Pinecone, Redis, MongoDB): verify the provider's encryption configuration 4. Verify the customer-managed KMS key used for transient data during ingestion |
Informational | N/A |
111122223333 |
us-east-1 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Review
Details and remediationDetails
Knowledge base '111122223333-us-east-1-kb' (ID: PAJOKBSIMQ) uses 'S3_VECTORS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
1. For OpenSearch Serverless: verify the collection uses a customer-managed KMS key 2. For Amazon RDS/Aurora: verify KMS encryption on the database 3. For third-party stores (Pinecone, Redis, MongoDB): verify the provider's encryption configuration 4. Verify the customer-managed KMS key used for transient data during ingestion |
Informational | N/A |
111122223333 |
us-east-1 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Review
Details and remediationDetails
Knowledge base 'e2e-rag-knowledgebase' (ID: ESIYAYSYTJ) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
1. For OpenSearch Serverless: verify the collection uses a customer-managed KMS key 2. For Amazon RDS/Aurora: verify KMS encryption on the database 3. For third-party stores (Pinecone, Redis, MongoDB): verify the provider's encryption configuration 4. Verify the customer-managed KMS key used for transient data during ingestion |
Informational | N/A |
111122223333 |
us-east-1 |
BR-21 |
Agent Action Group IAM Least Privilege Check
|
High | N/A |
111122223333 |
us-east-1 |
BR-22 |
Model Invocation Throttling Limits Check
|
Low | Passed |
111122223333 |
us-east-1 |
BR-23 |
Guardrail Content Filter Coverage Check
|
Low | Passed |
111122223333 |
us-east-1 |
BR-24 |
Automated Reasoning Policy Implementation Check
Details and remediationDetails
Guardrail 'nist-ai-rmf-guardrail' (ID: do7xkmhadx7k) does not have an Automated Reasoning policy configured. Automated Reasoning provides formal verification of model responses against defined policies. Resolution
Configure Automated Reasoning policies on guardrails to mathematically verify model responses. Define policies that specify allowed and disallowed behaviors. Use for high-assurance use cases where formal verification is required. |
Medium | Failed |
111122223333 |
us-east-1 |
BR-25 |
RAG Evaluation Jobs Check
Details and remediationDetails
Knowledge base 'knowledge-base-semiconductors' (ID: RQYFDSE1LT) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Create RAG evaluation jobs for knowledge bases using Amazon Bedrock Model Evaluation. Configure evaluations to test context relevance, answer correctness, and faithfulness metrics. Run evaluations regularly (monthly or after significant KB updates) to maintain quality. |
Low | Failed |
111122223333 |
us-east-1 |
BR-25 |
RAG Evaluation Jobs Check
Details and remediationDetails
Knowledge base '111122223333-us-east-1-kb' (ID: PAJOKBSIMQ) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Create RAG evaluation jobs for knowledge bases using Amazon Bedrock Model Evaluation. Configure evaluations to test context relevance, answer correctness, and faithfulness metrics. Run evaluations regularly (monthly or after significant KB updates) to maintain quality. |
Low | Failed |
111122223333 |
us-east-1 |
BR-25 |
RAG Evaluation Jobs Check
Details and remediationDetails
Knowledge base 'e2e-rag-knowledgebase' (ID: ESIYAYSYTJ) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Create RAG evaluation jobs for knowledge bases using Amazon Bedrock Model Evaluation. Configure evaluations to test context relevance, answer correctness, and faithfulness metrics. Run evaluations regularly (monthly or after significant KB updates) to maintain quality. |
Low | Failed |
111122223333 |
us-east-1 |
BR-26 |
Guardrail Sensitive Information Filter Check
|
Low | Passed |
111122223333 |
us-east-1 |
BR-27 |
Guardrail Contextual Grounding Check
|
Low | Passed |
111122223333 |
us-east-1 |
BR-28 |
Agent Guardrail Association Check
|
High | N/A |
111122223333 |
us-east-1 |
BR-29 |
Agent Idle Session TTL Check
|
Low | N/A |
111122223333 |
us-east-1 |
BR-30 |
Imported Model Customer-Managed KMS Encryption Check
|
High | N/A |
111122223333 |
us-east-1 |
BR-31 |
Batch Inference Output Encryption Check
|
Medium | N/A |
111122223333 |
us-east-1 |
BR-32 |
Bedrock CloudWatch Alarm Check
Details and remediationDetails
No CloudWatch alarms are configured on Amazon Bedrock runtime metrics (AWS/Bedrock namespace). Without alarms, abuse, denial-of-wallet, sustained throttling, and content-filter spikes can go undetected. Resolution
Create CloudWatch alarms on AWS/Bedrock runtime metrics such as Invocations, InvocationThrottles, InputTokenCount, OutputTokenCount, and ContentFilteredCount, and route them to an Amazon SNS topic for notification. |
Medium | Failed |
111122223333 |
us-east-1 |
BR-33 |
Amazon Inspector Lambda Code Scanning Check
Details and remediationDetails
Amazon Inspector Lambda scanning is not fully enabled in us-east-1. Lambda standard scan status: ENABLED. Lambda code scan status: DISABLED. Detected 6 Lambda function(s) with Bedrock indicators: aiml-security-aiml-security-111122223333-BedrockAssessment, e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk, gateway_lambda, myAskMeAnything, resco-aiml-BedrockAssessment (and 1 more). Without both scan types enabled, vulnerable dependencies and hardcoded secrets in these in-scope functions will not be detected. Resolution
Enable both Lambda standard scanning and Lambda code scanning in Amazon Inspector for this account and region. Console: Inspector -> Account management -> Activate for Lambda functions and Lambda code. |
Medium | Failed |
111122223333 |
us-east-1 |
AG-07 |
Agentic AI Model Invocation Logging
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: Model invocation logging is properly configured with delivery to: Amazon S3, CloudWatch Logs Resolution
Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements. |
Medium | Passed |
111122223333 |
us-east-1 |
AG-08 |
Agentic AI API Audit Trail
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: CloudTrail is properly configured to log Bedrock API activity in trails: IsengardTrail-DO-NOT-DELETE Resolution
Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured. |
Medium | Passed |
111122223333 |
Global |
AG-09 |
Agentic AI Guardrail Enforcement Boundary
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Organization-level guardrail enforcement helps prevent agents from bypassing required safety controls across accounts. Source check BR-15: Check must run in AWS Organizations management account to evaluate organizational policies Resolution
Use IAM and organization controls to require approved guardrails for model and agent invocations where supported. |
Informational | N/A |
111122223333 |
us-east-1 |
AG-10 |
Agentic AI Adversarial Evaluation Coverage
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No Bedrock model evaluation jobs found. Model evaluation helps assess toxicity, accuracy, semantic robustness, and other safety metrics before production deployment. Resolution
Configure model or application evaluations that include adversarial, safety, and security-relevant test cases. |
Medium | Failed |
111122223333 |
us-east-1 |
AG-11 |
Agentic AI Prompt Flow Validation
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region Resolution
Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions. |
Informational | N/A |
111122223333 |
us-east-1 |
AG-06 |
Agentic AI Tool Execution Least Privilege
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region Resolution
Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required. |
Informational | N/A |
111122223333 |
us-east-1 |
AG-12 |
Agentic AI Invocation Abuse Controls
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: 11 custom throttling quotas are configured. Regular quota review helps maintain appropriate rate limits. Resolution
Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns. |
Low | Passed |
111122223333 |
us-east-1 |
AG-02 |
Agentic AI Harmful Content Guardrail Coverage
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: 1 guardrails have complete content filter coverage (hate, insults, sexual, violence) Resolution
Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads. |
Low | Passed |
111122223333 |
us-east-1 |
AG-04 |
Agentic AI Automated Reasoning Guardrails
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: Guardrail 'nist-ai-rmf-guardrail' (ID: do7xkmhadx7k) does not have an Automated Reasoning policy configured. Automated Reasoning provides formal verification of model responses against defined policies. Resolution
Configure automated reasoning policies on guardrails where formal response validation is required. |
Medium | Failed |
111122223333 |
us-east-1 |
AG-03 |
Agentic AI Sensitive Information Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: 1 guardrails have sensitive-information (PII) filters configured Resolution
Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns. |
Low | Passed |
111122223333 |
us-east-1 |
AG-05 |
Agentic AI Grounding Controls
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: 1 guardrails have contextual grounding checks enabled Resolution
Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows. |
Low | Passed |
111122223333 |
us-east-1 |
AG-01 |
Agentic AI Agent Guardrail Association
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region Resolution
Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating. |
Informational | N/A |
111122223333 |
us-east-1 |
AG-13 |
Agentic AI Session Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region Resolution
Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements. |
Informational | N/A |
111122223333 |
us-east-1 |
AG-14 |
Agentic AI Operational Abuse Alarms
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No CloudWatch alarms are configured on Amazon Bedrock runtime metrics (AWS/Bedrock namespace). Without alarms, abuse, denial-of-wallet, sustained throttling, and content-filter spikes can go undetected. Resolution
Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available. |
Medium | Failed |
111122223333 |
us-east-2 |
SM-01 |
SageMaker Internet Access Check
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-02 |
SageMaker SSO Configuration Check
|
Medium | Passed |
111122223333 |
us-east-2 |
SM-03 |
Missing Encryption Configuration
|
High | Failed |
111122223333 |
us-east-2 |
SM-03 |
Missing VPC Encryption
|
Medium | Failed |
111122223333 |
us-east-2 |
SM-04 |
GuardDuty Enabled
|
Medium | Passed |
111122223333 |
us-east-2 |
SM-05 |
SageMaker Model Registry Issue
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-05 |
SageMaker Feature Store Issue
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-05 |
SageMaker Pipelines Issue
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-06 |
SageMaker Clarify No Clarify Usage
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-07 |
SageMaker Model Monitor No Model Monitoring
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-08 |
Model Registry Registry Not Used
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-09 |
SageMaker Notebook Root Access Check
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-10 |
SageMaker Notebook VPC Deployment Check
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-11 |
SageMaker Model Network Isolation Disabled
Details and remediationDetails
Model 'xgboost-2021-12-19-01-25-44-527' does not have network isolation enabled. Model containers can make outbound network calls, potentially exfiltrating data. Resolution
Enable network isolation by setting EnableNetworkIsolation=True when creating models. This prevents containers from making outbound network calls. |
High | Failed |
111122223333 |
us-east-2 |
SM-12 |
SageMaker Endpoint Instance Count Check
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-13 |
SageMaker Monitoring Network Isolation Check
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-14 |
SageMaker Model Platform Repository Access
Details and remediationDetails
Model 'xgboost-2021-12-19-01-25-44-527' uses Platform repository access mode. Container images are pulled from public/external registries, exposing supply chain risks. Resolution
Configure RepositoryAccessMode=Vpc in ImageConfig to pull images from private ECR repositories through VPC. This provides supply chain security. |
Medium | Failed |
111122223333 |
us-east-2 |
SM-15 |
SageMaker Feature Store Encryption Check
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-16 |
SageMaker Data Quality Job Encryption Check
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-17 |
SageMaker Processing Job Encryption Check
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-18 |
SageMaker Transform Job Volume Encryption Missing
Details and remediationDetails
Transform job 'xgboost-2021-12-19-01-25-49-740' does not have volume encryption configured. Data at rest on transform instances is not encrypted with customer-managed keys. Resolution
Configure VolumeKmsKeyId in TransformResources when creating transform jobs to encrypt attached EBS volumes. |
Medium | Failed |
111122223333 |
us-east-2 |
SM-19 |
SageMaker Hyperparameter Tuning Job Encryption Check
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-20 |
SageMaker Compilation Job Encryption Check
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-21 |
SageMaker AutoML Job Network Isolation Check
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-22 |
Model Approval Workflow Check
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-23 |
Model Drift Detection Check
|
Medium | Passed |
111122223333 |
us-east-2 |
SM-24 |
A/B Testing and Shadow Deployment Check
|
Low | Passed |
111122223333 |
us-east-2 |
SM-25 |
ML Lineage Tracking - Experiments Not Used
|
Informational | N/A |
444455556666 |
eu-west-1 |
AC-01 |
AgentCore VPC Configuration Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
AC-04 |
AgentCore Observability Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
AC-05 |
AgentCore Encryption Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
AC-06 |
AgentCore Browser Tool Recording Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
AC-07 |
AgentCore Memory Configuration Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
AC-13 |
AgentCore Gateway Configuration Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
AC-08 |
AgentCore VPC Endpoints Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
AC-10 |
AgentCore Resource-Based Policies Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
AC-11 |
AgentCore Policy Engine Encryption Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
AC-12 |
AgentCore Gateway Encryption Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
AG-24 |
Agentic AI Gateway Inbound Authorization
|
Informational | N/A |
444455556666 |
eu-west-1 |
AG-25 |
Agentic AI Gateway Tool Policy Enforcement
|
Informational | N/A |
444455556666 |
eu-west-1 |
AG-26 |
Agentic AI Gateway Error Detail Exposure
|
Informational | N/A |
444455556666 |
eu-west-1 |
AG-27 |
Agentic AI Gateway WAF Protection
|
Informational | N/A |
444455556666 |
eu-west-1 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
Informational | N/A |
444455556666 |
eu-west-1 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Informational | N/A |
444455556666 |
eu-west-1 |
AG-19 |
Agentic AI Memory Data Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found Resolution
Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions. |
Informational | N/A |
444455556666 |
eu-west-1 |
AG-20 |
Agentic AI Private AgentCore Connectivity
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found Resolution
Create required VPC endpoints for AgentCore services and validate endpoint availability. |
Informational | N/A |
444455556666 |
eu-west-1 |
AG-21 |
Agentic AI Resource Policy Boundary
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies Resolution
Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources. |
Informational | N/A |
444455556666 |
eu-west-1 |
AG-22 |
Agentic AI Policy Engine Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found Resolution
Configure policy engines with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
444455556666 |
eu-west-1 |
AG-23 |
Agentic AI Gateway Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found Resolution
Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
444455556666 |
us-east-1 |
OW-01 |
OWASP LLM01: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis. |
Informational | N/A |
444455556666 |
us-east-1 |
OW-07 |
OWASP LLM07: Model Invocation Logging
Details and remediation |
Informational | N/A |
444455556666 |
us-east-1 |
OW-07 |
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident. |
Informational | N/A |
444455556666 |
us-east-1 |
OW-07 |
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-09 |
OWASP LLM09: Model Evaluation Jobs
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-06 |
OWASP LLM06: Agent Action-Group Least Privilege
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-10 |
OWASP LLM10: Service Quota Throttling Limits
Details and remediation |
Informational | N/A |
444455556666 |
us-east-1 |
OW-01 |
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier. |
Informational | N/A |
444455556666 |
us-east-1 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-02 |
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation |
Informational | N/A |
444455556666 |
us-east-1 |
OW-01 |
OWASP LLM01: Contextual Grounding Guardrail
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-04 |
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation |
Informational | N/A |
444455556666 |
us-east-1 |
OW-09 |
OWASP LLM09: Contextual Grounding for Faithfulness
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-06 |
OWASP LLM06: Bedrock Agent Guardrail Association
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-06 |
OWASP LLM06: Agent Idle Session TTL
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-03 |
OWASP LLM03: Imported-Model KMS Provenance
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-10 |
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation |
Informational | N/A |
444455556666 |
us-east-1 |
OW-03 |
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check BR-33: Amazon Inspector Lambda standard scanning and Lambda code scanning are both ENABLED in us-east-1. Detected 2 Lambda function(s) with Bedrock indicators: aiml-security-aiml-security-444455556666-BedrockAssessment, resco-aiml-BedrockAssessment. Resolution
Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain. |
Medium | Passed |
444455556666 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Internet Exposure
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-01: No SageMaker notebook instances or domains found to check Resolution
Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths. |
Informational | N/A |
444455556666 |
us-east-1 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: No SageMaker resources found to check for data protection Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
Informational | N/A |
444455556666 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Clarify Evaluation
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation |
Informational | N/A |
444455556666 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Model Monitor Coverage
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Notebook VPC Deployment
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Model Network Isolation
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-10 |
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation |
Informational | N/A |
444455556666 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Container Repository Access
Details and remediation |
Informational | N/A |
444455556666 |
us-east-1 |
OW-02 |
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation |
Informational | N/A |
444455556666 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker AutoML Network Isolation
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically. |
Informational | N/A |
444455556666 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release. |
Informational | N/A |
444455556666 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
444455556666 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
444455556666 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain. |
Informational | N/A |
444455556666 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated. |
Informational | N/A |
444455556666 |
Global |
OW-06 |
OWASP LLM06: AgentCore IAM Least Privilege
|
High | Passed |
444455556666 |
us-east-1 |
OW-06 |
OWASP LLM06: AgentCore Resource-Based Policies
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-11 |
OWASP LLM07: System Prompt Embedded in Lambda Env Var
|
Medium | Passed |
444455556666 |
us-east-1 |
OW-12 |
OWASP LLM07: System-Prompt-Disclosure Denied Topic
|
Informational | N/A |
444455556666 |
Global |
AC-02 |
AgentCore IAM Full Access Check
|
High | Passed |
444455556666 |
Global |
AC-03 |
AgentCore Stale Access
|
Medium | Failed |
444455556666 |
Global |
AC-03 |
AgentCore Unused Permissions
|
Informational | N/A |
444455556666 |
Global |
AC-09 |
AgentCore Service-Linked Role Missing
Details and remediationDetails
Service-linked role 'AWSServiceRoleForBedrockAgentCoreNetwork' does not exist. VPC configuration for AgentCore Runtimes will fail without this role. Resolution
The service-linked role is automatically created when you configure VPC for an AgentCore Runtime. Ensure IAM permissions allow service-linked role creation. |
Medium | Failed |
444455556666 |
us-east-1 |
AC-01 |
AgentCore VPC Configuration Check
|
Informational | N/A |
444455556666 |
us-east-1 |
AC-04 |
AgentCore Observability Check
|
Informational | N/A |
444455556666 |
us-east-1 |
AC-05 |
AgentCore Encryption Check
|
Informational | N/A |
444455556666 |
us-east-1 |
AC-06 |
AgentCore Browser Tool Recording Check
|
Informational | N/A |
444455556666 |
us-east-1 |
AC-07 |
AgentCore Memory Configuration Check
|
Informational | N/A |
444455556666 |
us-east-1 |
AC-13 |
AgentCore Gateway Configuration Check
|
Informational | N/A |
444455556666 |
us-east-1 |
AC-08 |
AgentCore VPC Endpoints Check
|
Informational | N/A |
444455556666 |
us-east-1 |
AC-10 |
AgentCore Resource-Based Policies Check
|
Informational | N/A |
444455556666 |
us-east-1 |
AC-11 |
AgentCore Policy Engine Encryption Check
|
Informational | N/A |
444455556666 |
us-east-1 |
AC-12 |
AgentCore Gateway Encryption Check
|
Informational | N/A |
444455556666 |
us-east-1 |
AG-24 |
Agentic AI Gateway Inbound Authorization
|
Informational | N/A |
444455556666 |
us-east-1 |
AG-25 |
Agentic AI Gateway Tool Policy Enforcement
|
Informational | N/A |
444455556666 |
us-east-1 |
AG-26 |
Agentic AI Gateway Error Detail Exposure
|
Informational | N/A |
444455556666 |
us-east-1 |
AG-27 |
Agentic AI Gateway WAF Protection
|
Informational | N/A |
444455556666 |
Global |
AG-16 |
Agentic AI AgentCore Least Privilege
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Over-permissive AgentCore principals can let agents or operators bypass intended autonomy and tool boundaries. Source check AC-02: No roles with overly permissive AgentCore access found Resolution
Replace full-access AgentCore permissions with least-privilege IAM policies scoped to required resources and actions. |
High | Passed |
444455556666 |
Global |
AG-17 |
Agentic AI Stale AgentCore Access
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Unused AgentCore permissions increase the blast radius of compromised principals. Source check AC-03: The following principals have not accessed AgentCore in 60+ days: role 'resco-aiml-security-23026-AgentCoreSecurityAssessme-2AEt2MTxg4AU' (91 days) Resolution
Remove or restrict stale AgentCore permissions for principals that no longer need access. |
Medium | Failed |
444455556666 |
Global |
AG-17 |
Agentic AI Stale AgentCore Access
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Unused AgentCore permissions increase the blast radius of compromised principals. Source check AC-03: The following principals have AgentCore permissions but have never accessed the service: role 'AIMLSecurityMemberRole', role 'CloudSeerTrustedServiceRole' Resolution
Remove or restrict stale AgentCore permissions for principals that no longer need access. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-19 |
Agentic AI Memory Data Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found Resolution
Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-20 |
Agentic AI Private AgentCore Connectivity
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found Resolution
Create required VPC endpoints for AgentCore services and validate endpoint availability. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-21 |
Agentic AI Resource Policy Boundary
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies Resolution
Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-22 |
Agentic AI Policy Engine Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found Resolution
Configure policy engines with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-23 |
Agentic AI Gateway Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found Resolution
Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
444455556666 |
us-west-2 |
OW-01 |
OWASP LLM01: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis. |
Informational | N/A |
444455556666 |
us-west-2 |
OW-07 |
OWASP LLM07: Model Invocation Logging
Details and remediation |
Informational | N/A |
444455556666 |
us-west-2 |
OW-07 |
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident. |
Informational | N/A |
444455556666 |
us-west-2 |
OW-07 |
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-09 |
OWASP LLM09: Model Evaluation Jobs
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-06 |
OWASP LLM06: Agent Action-Group Least Privilege
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-10 |
OWASP LLM10: Service Quota Throttling Limits
Details and remediation |
Informational | N/A |
444455556666 |
us-west-2 |
OW-01 |
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier. |
Informational | N/A |
444455556666 |
us-west-2 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-02 |
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation |
Informational | N/A |
444455556666 |
us-west-2 |
OW-01 |
OWASP LLM01: Contextual Grounding Guardrail
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-04 |
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation |
Informational | N/A |
444455556666 |
us-west-2 |
OW-09 |
OWASP LLM09: Contextual Grounding for Faithfulness
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-06 |
OWASP LLM06: Bedrock Agent Guardrail Association
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-06 |
OWASP LLM06: Agent Idle Session TTL
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-03 |
OWASP LLM03: Imported-Model KMS Provenance
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-10 |
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation |
Informational | N/A |
444455556666 |
us-west-2 |
OW-03 |
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check BR-33: No Lambda functions with Bedrock indicators were found in us-west-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain. |
Informational | N/A |
444455556666 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker Internet Exposure
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-01: No SageMaker notebook instances or domains found to check Resolution
Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths. |
Informational | N/A |
444455556666 |
us-west-2 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: No SageMaker resources found to check for data protection Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
Informational | N/A |
444455556666 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Clarify Evaluation
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation |
Informational | N/A |
444455556666 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Model Monitor Coverage
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker Notebook VPC Deployment
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker Model Network Isolation
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-10 |
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation |
Informational | N/A |
444455556666 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker Container Repository Access
Details and remediation |
Informational | N/A |
444455556666 |
us-west-2 |
OW-02 |
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation |
Informational | N/A |
444455556666 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker AutoML Network Isolation
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically. |
Informational | N/A |
444455556666 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release. |
Informational | N/A |
444455556666 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
444455556666 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
444455556666 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain. |
Informational | N/A |
444455556666 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated. |
Informational | N/A |
444455556666 |
us-west-2 |
OW-06 |
OWASP LLM06: AgentCore Resource-Based Policies
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-11 |
OWASP LLM07: System Prompt Embedded in Lambda Env Var
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-12 |
OWASP LLM07: System-Prompt-Disclosure Denied Topic
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-01 |
OWASP LLM01: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis. |
Informational | N/A |
444455556666 |
us-east-2 |
OW-07 |
OWASP LLM07: Model Invocation Logging
Details and remediation |
Informational | N/A |
444455556666 |
us-east-2 |
OW-07 |
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident. |
Informational | N/A |
444455556666 |
us-east-2 |
OW-07 |
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-09 |
OWASP LLM09: Model Evaluation Jobs
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-06 |
OWASP LLM06: Agent Action-Group Least Privilege
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-10 |
OWASP LLM10: Service Quota Throttling Limits
Details and remediation |
Informational | N/A |
444455556666 |
us-east-2 |
OW-01 |
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier. |
Informational | N/A |
444455556666 |
us-east-2 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-02 |
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation |
Informational | N/A |
444455556666 |
us-east-2 |
OW-01 |
OWASP LLM01: Contextual Grounding Guardrail
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-04 |
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation |
Informational | N/A |
444455556666 |
us-east-2 |
OW-09 |
OWASP LLM09: Contextual Grounding for Faithfulness
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-06 |
OWASP LLM06: Bedrock Agent Guardrail Association
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-06 |
OWASP LLM06: Agent Idle Session TTL
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-03 |
OWASP LLM03: Imported-Model KMS Provenance
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-10 |
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation |
Informational | N/A |
444455556666 |
us-east-2 |
OW-03 |
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check BR-33: No Lambda functions with Bedrock indicators were found in us-east-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain. |
Informational | N/A |
444455556666 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker Internet Exposure
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-01: SageMaker notebook instance 'aws-neptune-Mybookstore-Bookstore-WS-Notebook' has direct internet access enabled Resolution
Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths. |
High | Failed |
444455556666 |
us-east-2 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: Notebook Instance 'aws-neptune-Mybookstore-Bookstore-WS-Notebook' - No KMS key configured Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
High | Failed |
444455556666 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Clarify Evaluation
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation |
Informational | N/A |
444455556666 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Model Monitor Coverage
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker Notebook VPC Deployment
Details and remediation |
High | Passed |
444455556666 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker Model Network Isolation
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-10 |
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation |
Informational | N/A |
444455556666 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker Container Repository Access
Details and remediation |
Informational | N/A |
444455556666 |
us-east-2 |
OW-02 |
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation |
Informational | N/A |
444455556666 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker AutoML Network Isolation
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically. |
Informational | N/A |
444455556666 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release. |
Informational | N/A |
444455556666 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
444455556666 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
444455556666 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain. |
Informational | N/A |
444455556666 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated. |
Informational | N/A |
444455556666 |
us-east-2 |
OW-06 |
OWASP LLM06: AgentCore Resource-Based Policies
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-11 |
OWASP LLM07: System Prompt Embedded in Lambda Env Var
|
Medium | Passed |
444455556666 |
us-east-2 |
OW-12 |
OWASP LLM07: System-Prompt-Disclosure Denied Topic
|
Informational | N/A |
444455556666 |
us-east-2 |
AC-01 |
AgentCore VPC Configuration Check
|
Informational | N/A |
444455556666 |
us-east-2 |
AC-04 |
AgentCore Observability Check
|
Informational | N/A |
444455556666 |
us-east-2 |
AC-05 |
AgentCore Encryption Check
|
Informational | N/A |
444455556666 |
us-east-2 |
AC-06 |
AgentCore Browser Tool Recording Check
|
Informational | N/A |
444455556666 |
us-east-2 |
AC-07 |
AgentCore Memory Configuration Check
|
Informational | N/A |
444455556666 |
us-east-2 |
AC-13 |
AgentCore Gateway Configuration Check
|
Informational | N/A |
444455556666 |
us-east-2 |
AC-08 |
AgentCore VPC Endpoints Check
|
Informational | N/A |
444455556666 |
us-east-2 |
AC-10 |
AgentCore Resource-Based Policies Check
|
Informational | N/A |
444455556666 |
us-east-2 |
AC-11 |
AgentCore Policy Engine Encryption Check
|
Informational | N/A |
444455556666 |
us-east-2 |
AC-12 |
AgentCore Gateway Encryption Check
|
Informational | N/A |
444455556666 |
us-east-2 |
AG-24 |
Agentic AI Gateway Inbound Authorization
|
Informational | N/A |
444455556666 |
us-east-2 |
AG-25 |
Agentic AI Gateway Tool Policy Enforcement
|
Informational | N/A |
444455556666 |
us-east-2 |
AG-26 |
Agentic AI Gateway Error Detail Exposure
|
Informational | N/A |
444455556666 |
us-east-2 |
AG-27 |
Agentic AI Gateway WAF Protection
|
Informational | N/A |
444455556666 |
us-east-2 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-19 |
Agentic AI Memory Data Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found Resolution
Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-20 |
Agentic AI Private AgentCore Connectivity
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found Resolution
Create required VPC endpoints for AgentCore services and validate endpoint availability. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-21 |
Agentic AI Resource Policy Boundary
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies Resolution
Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-22 |
Agentic AI Policy Engine Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found Resolution
Configure policy engines with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-23 |
Agentic AI Gateway Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found Resolution
Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
444455556666 |
Global |
BR-01 |
AmazonBedrockFullAccess role check
|
High | Passed |
444455556666 |
Global |
BR-03 |
Marketplace Subscription Access Check
|
Medium | Passed |
444455556666 |
us-east-1 |
BR-02 |
Amazon Bedrock private connectivity check
|
Informational | N/A |
444455556666 |
us-east-1 |
BR-04 |
Bedrock Model Invocation Logging Check
|
Informational | N/A |
444455556666 |
us-east-1 |
BR-05 |
Bedrock Guardrails Check
|
Informational | N/A |
444455556666 |
us-east-1 |
BR-06 |
Bedrock CloudTrail Logging Check
|
Informational | N/A |
444455556666 |
us-east-1 |
BR-07 |
Bedrock Prompt Management Check
Details and remediationDetails
Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates |
Informational | N/A |
444455556666 |
us-east-1 |
BR-08 |
Bedrock Agent IAM Roles Check
|
Informational | N/A |
444455556666 |
us-east-1 |
BR-09 |
Bedrock Knowledge Base Encryption Check
|
Informational | N/A |
444455556666 |
us-east-1 |
BR-10 |
Bedrock Guardrail IAM Enforcement Check
|
Informational | N/A |
444455556666 |
us-east-1 |
BR-11 |
Bedrock Custom Model Encryption Check
|
Informational | N/A |
444455556666 |
us-east-1 |
BR-12 |
Bedrock Invocation Log Encryption Check
|
Informational | N/A |
444455556666 |
us-east-1 |
BR-13 |
Bedrock Flows Guardrails Check
|
Informational | N/A |
444455556666 |
Global |
BR-15 |
Cross-Account Guardrails Enforcement Check
|
Medium | N/A |
444455556666 |
us-east-1 |
BR-16 |
Guardrail Tier Validation Check
|
Medium | N/A |
444455556666 |
us-east-1 |
BR-17 |
Custom Model Customer-Managed KMS Encryption Check
|
High | N/A |
444455556666 |
us-east-1 |
BR-18 |
Model Evaluation Implementation Check
|
Informational | N/A |
444455556666 |
us-east-1 |
BR-19 |
Prompt Flow Validation Check
|
Medium | N/A |
444455556666 |
us-east-1 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Check
|
High | N/A |
444455556666 |
us-east-1 |
BR-21 |
Agent Action Group IAM Least Privilege Check
|
High | N/A |
444455556666 |
us-east-1 |
BR-22 |
Model Invocation Throttling Limits Check
|
Informational | N/A |
444455556666 |
us-east-1 |
BR-23 |
Guardrail Content Filter Coverage Check
|
High | N/A |
444455556666 |
us-east-1 |
BR-24 |
Automated Reasoning Policy Implementation Check
|
Medium | N/A |
444455556666 |
us-east-1 |
BR-25 |
RAG Evaluation Jobs Check
|
Low | N/A |
444455556666 |
us-east-1 |
BR-26 |
Guardrail Sensitive Information Filter Check
|
High | N/A |
444455556666 |
us-east-1 |
BR-27 |
Guardrail Contextual Grounding Check
|
Medium | N/A |
444455556666 |
us-east-1 |
BR-28 |
Agent Guardrail Association Check
|
High | N/A |
444455556666 |
us-east-1 |
BR-29 |
Agent Idle Session TTL Check
|
Low | N/A |
444455556666 |
us-east-1 |
BR-30 |
Imported Model Customer-Managed KMS Encryption Check
|
High | N/A |
444455556666 |
us-east-1 |
BR-31 |
Batch Inference Output Encryption Check
|
Medium | N/A |
444455556666 |
us-east-1 |
BR-32 |
Bedrock CloudWatch Alarm Check
|
Informational | N/A |
444455556666 |
us-east-1 |
BR-33 |
Amazon Inspector Lambda Code Scanning Check
Details and remediation |
Medium | Passed |
444455556666 |
us-east-1 |
AG-07 |
Agentic AI Model Invocation Logging
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-08 |
Agentic AI API Audit Trail
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage Resolution
Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured. |
Informational | N/A |
444455556666 |
Global |
AG-09 |
Agentic AI Guardrail Enforcement Boundary
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Organization-level guardrail enforcement helps prevent agents from bypassing required safety controls across accounts. Source check BR-15: Check must run in AWS Organizations management account to evaluate organizational policies Resolution
Use IAM and organization controls to require approved guardrails for model and agent invocations where supported. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-10 |
Agentic AI Adversarial Evaluation Coverage
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs Resolution
Configure model or application evaluations that include adversarial, safety, and security-relevant test cases. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-11 |
Agentic AI Prompt Flow Validation
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region Resolution
Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-06 |
Agentic AI Tool Execution Least Privilege
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region Resolution
Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-12 |
Agentic AI Invocation Abuse Controls
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas Resolution
Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-02 |
Agentic AI Harmful Content Guardrail Coverage
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-04 |
Agentic AI Automated Reasoning Guardrails
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: No Bedrock guardrails configured in this region Resolution
Configure automated reasoning policies on guardrails where formal response validation is required. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-03 |
Agentic AI Sensitive Information Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: No Bedrock guardrails configured in this region Resolution
Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-05 |
Agentic AI Grounding Controls
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: No Bedrock guardrails configured in this region Resolution
Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-01 |
Agentic AI Agent Guardrail Association
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region Resolution
Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-13 |
Agentic AI Session Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region Resolution
Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-14 |
Agentic AI Operational Abuse Alarms
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms Resolution
Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available. |
Informational | N/A |
444455556666 |
eu-west-1 |
BR-02 |
Amazon Bedrock private connectivity check
|
Informational | N/A |
444455556666 |
eu-west-1 |
BR-04 |
Bedrock Model Invocation Logging Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
BR-05 |
Bedrock Guardrails Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
BR-06 |
Bedrock CloudTrail Logging Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
BR-07 |
Bedrock Prompt Management Check
Details and remediationDetails
Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates |
Informational | N/A |
444455556666 |
eu-west-1 |
BR-08 |
Bedrock Agent IAM Roles Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
BR-09 |
Bedrock Knowledge Base Encryption Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
BR-10 |
Bedrock Guardrail IAM Enforcement Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
BR-11 |
Bedrock Custom Model Encryption Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
BR-12 |
Bedrock Invocation Log Encryption Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
BR-13 |
Bedrock Flows Guardrails Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
BR-16 |
Guardrail Tier Validation Check
|
Medium | N/A |
444455556666 |
eu-west-1 |
BR-17 |
Custom Model Customer-Managed KMS Encryption Check
|
High | N/A |
444455556666 |
eu-west-1 |
BR-18 |
Model Evaluation Implementation Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
BR-19 |
Prompt Flow Validation Check
|
Medium | N/A |
444455556666 |
eu-west-1 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Check
|
High | N/A |
444455556666 |
eu-west-1 |
BR-21 |
Agent Action Group IAM Least Privilege Check
|
High | N/A |
444455556666 |
eu-west-1 |
BR-22 |
Model Invocation Throttling Limits Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
BR-23 |
Guardrail Content Filter Coverage Check
|
High | N/A |
444455556666 |
eu-west-1 |
BR-24 |
Automated Reasoning Policy Implementation Check
|
Medium | N/A |
444455556666 |
eu-west-1 |
BR-25 |
RAG Evaluation Jobs Check
|
Low | N/A |
444455556666 |
eu-west-1 |
BR-26 |
Guardrail Sensitive Information Filter Check
|
High | N/A |
444455556666 |
eu-west-1 |
BR-27 |
Guardrail Contextual Grounding Check
|
Medium | N/A |
444455556666 |
eu-west-1 |
BR-28 |
Agent Guardrail Association Check
|
High | N/A |
444455556666 |
eu-west-1 |
BR-29 |
Agent Idle Session TTL Check
|
Low | N/A |
444455556666 |
eu-west-1 |
BR-30 |
Imported Model Customer-Managed KMS Encryption Check
Details and remediationDetails
Unable to check Imported model encryption check: An error occurred (AccessDeniedException) when calling the ListImportedModels operation: Your account is not authorized to invoke this API operation. Resolution
Amazon Bedrock Custom Model Import is not enabled or available for this account in this region. No IAM change is required; the check applies only once model import is in use. |
Low | N/A |
444455556666 |
eu-west-1 |
BR-31 |
Batch Inference Output Encryption Check
|
Medium | N/A |
444455556666 |
eu-west-1 |
BR-32 |
Bedrock CloudWatch Alarm Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
BR-33 |
Amazon Inspector Lambda Code Scanning Check
Details and remediationDetails
No Lambda functions with Bedrock indicators were found in eu-west-1; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
No action required. If Bedrock-calling Lambda functions exist, ensure their function name, ARN, description, handler, role, or environment variables contain a Bedrock identifier that the assessment can detect, or evaluate Inspector coverage manually. |
Informational | N/A |
444455556666 |
eu-west-1 |
AG-07 |
Agentic AI Model Invocation Logging
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements. |
Informational | N/A |
444455556666 |
eu-west-1 |
AG-08 |
Agentic AI API Audit Trail
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage Resolution
Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured. |
Informational | N/A |
444455556666 |
eu-west-1 |
AG-10 |
Agentic AI Adversarial Evaluation Coverage
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs Resolution
Configure model or application evaluations that include adversarial, safety, and security-relevant test cases. |
Informational | N/A |
444455556666 |
eu-west-1 |
AG-11 |
Agentic AI Prompt Flow Validation
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region Resolution
Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions. |
Informational | N/A |
444455556666 |
eu-west-1 |
AG-06 |
Agentic AI Tool Execution Least Privilege
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region Resolution
Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required. |
Informational | N/A |
444455556666 |
eu-west-1 |
AG-12 |
Agentic AI Invocation Abuse Controls
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas Resolution
Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns. |
Informational | N/A |
444455556666 |
eu-west-1 |
AG-02 |
Agentic AI Harmful Content Guardrail Coverage
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads. |
Informational | N/A |
444455556666 |
eu-west-1 |
AG-04 |
Agentic AI Automated Reasoning Guardrails
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: No Bedrock guardrails configured in this region Resolution
Configure automated reasoning policies on guardrails where formal response validation is required. |
Informational | N/A |
444455556666 |
eu-west-1 |
AG-03 |
Agentic AI Sensitive Information Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: No Bedrock guardrails configured in this region Resolution
Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns. |
Informational | N/A |
444455556666 |
eu-west-1 |
AG-05 |
Agentic AI Grounding Controls
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: No Bedrock guardrails configured in this region Resolution
Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows. |
Informational | N/A |
444455556666 |
eu-west-1 |
AG-01 |
Agentic AI Agent Guardrail Association
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region Resolution
Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating. |
Informational | N/A |
444455556666 |
eu-west-1 |
AG-13 |
Agentic AI Session Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region Resolution
Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements. |
Informational | N/A |
444455556666 |
eu-west-1 |
AG-14 |
Agentic AI Operational Abuse Alarms
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms Resolution
Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available. |
Informational | N/A |
444455556666 |
us-west-2 |
BR-02 |
Amazon Bedrock private connectivity check
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-04 |
Bedrock Model Invocation Logging Check
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-05 |
Bedrock Guardrails Check
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-06 |
Bedrock CloudTrail Logging Check
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-07 |
Bedrock Prompt Management Check
Details and remediationDetails
Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates |
Informational | N/A |
444455556666 |
us-west-2 |
BR-08 |
Bedrock Agent IAM Roles Check
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-09 |
Bedrock Knowledge Base Encryption Check
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-10 |
Bedrock Guardrail IAM Enforcement Check
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-11 |
Bedrock Custom Model Encryption Check
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-12 |
Bedrock Invocation Log Encryption Check
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-13 |
Bedrock Flows Guardrails Check
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-16 |
Guardrail Tier Validation Check
|
Medium | N/A |
444455556666 |
us-west-2 |
BR-17 |
Custom Model Customer-Managed KMS Encryption Check
|
High | N/A |
444455556666 |
us-west-2 |
BR-18 |
Model Evaluation Implementation Check
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-19 |
Prompt Flow Validation Check
|
Medium | N/A |
444455556666 |
us-west-2 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Check
|
High | N/A |
444455556666 |
us-west-2 |
BR-21 |
Agent Action Group IAM Least Privilege Check
|
High | N/A |
444455556666 |
us-west-2 |
BR-22 |
Model Invocation Throttling Limits Check
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-23 |
Guardrail Content Filter Coverage Check
|
High | N/A |
444455556666 |
us-west-2 |
BR-24 |
Automated Reasoning Policy Implementation Check
|
Medium | N/A |
444455556666 |
us-west-2 |
BR-25 |
RAG Evaluation Jobs Check
|
Low | N/A |
444455556666 |
us-west-2 |
BR-26 |
Guardrail Sensitive Information Filter Check
|
High | N/A |
444455556666 |
us-west-2 |
BR-27 |
Guardrail Contextual Grounding Check
|
Medium | N/A |
444455556666 |
us-west-2 |
BR-28 |
Agent Guardrail Association Check
|
High | N/A |
444455556666 |
us-west-2 |
BR-29 |
Agent Idle Session TTL Check
|
Low | N/A |
444455556666 |
us-west-2 |
BR-30 |
Imported Model Customer-Managed KMS Encryption Check
|
High | N/A |
444455556666 |
us-west-2 |
BR-31 |
Batch Inference Output Encryption Check
|
Medium | N/A |
444455556666 |
us-west-2 |
BR-32 |
Bedrock CloudWatch Alarm Check
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-33 |
Amazon Inspector Lambda Code Scanning Check
Details and remediationDetails
No Lambda functions with Bedrock indicators were found in us-west-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
No action required. If Bedrock-calling Lambda functions exist, ensure their function name, ARN, description, handler, role, or environment variables contain a Bedrock identifier that the assessment can detect, or evaluate Inspector coverage manually. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-07 |
Agentic AI Model Invocation Logging
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-08 |
Agentic AI API Audit Trail
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage Resolution
Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-10 |
Agentic AI Adversarial Evaluation Coverage
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs Resolution
Configure model or application evaluations that include adversarial, safety, and security-relevant test cases. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-11 |
Agentic AI Prompt Flow Validation
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region Resolution
Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-06 |
Agentic AI Tool Execution Least Privilege
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region Resolution
Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-12 |
Agentic AI Invocation Abuse Controls
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas Resolution
Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-02 |
Agentic AI Harmful Content Guardrail Coverage
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-04 |
Agentic AI Automated Reasoning Guardrails
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: No Bedrock guardrails configured in this region Resolution
Configure automated reasoning policies on guardrails where formal response validation is required. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-03 |
Agentic AI Sensitive Information Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: No Bedrock guardrails configured in this region Resolution
Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-05 |
Agentic AI Grounding Controls
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: No Bedrock guardrails configured in this region Resolution
Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-01 |
Agentic AI Agent Guardrail Association
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region Resolution
Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-13 |
Agentic AI Session Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region Resolution
Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-14 |
Agentic AI Operational Abuse Alarms
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms Resolution
Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available. |
Informational | N/A |
444455556666 |
us-east-1 |
FS-00 |
FinServ Regional Scope Not Applicable
|
Informational | N/A |
444455556666 |
us-east-2 |
FS-00 |
FinServ Regional Scope Not Applicable
|
Informational | N/A |
444455556666 |
us-west-2 |
FS-00 |
FinServ Regional Scope Not Applicable
|
Informational | N/A |
444455556666 |
eu-west-1 |
FS-00 |
FinServ Regional Scope Not Applicable
|
Informational | N/A |
444455556666 |
eu-west-1 |
OW-01 |
OWASP LLM01: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis. |
Informational | N/A |
444455556666 |
eu-west-1 |
OW-07 |
OWASP LLM07: Model Invocation Logging
Details and remediation |
Informational | N/A |
444455556666 |
eu-west-1 |
OW-07 |
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident. |
Informational | N/A |
444455556666 |
eu-west-1 |
OW-07 |
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
|
Informational | N/A |
444455556666 |
eu-west-1 |
OW-09 |
OWASP LLM09: Model Evaluation Jobs
|
Informational | N/A |
444455556666 |
eu-west-1 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
|
Informational | N/A |
444455556666 |
eu-west-1 |
OW-06 |
OWASP LLM06: Agent Action-Group Least Privilege
|
Informational | N/A |
444455556666 |
eu-west-1 |
OW-10 |
OWASP LLM10: Service Quota Throttling Limits
Details and remediation |
Informational | N/A |
444455556666 |
eu-west-1 |
OW-01 |
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier. |
Informational | N/A |
444455556666 |
eu-west-1 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
|
Informational | N/A |
444455556666 |
eu-west-1 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
|
Informational | N/A |
444455556666 |
eu-west-1 |
OW-02 |
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation |
Informational | N/A |
444455556666 |
eu-west-1 |
OW-01 |
OWASP LLM01: Contextual Grounding Guardrail
|
Informational | N/A |
444455556666 |
eu-west-1 |
OW-04 |
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation |
Informational | N/A |
444455556666 |
eu-west-1 |
OW-09 |
OWASP LLM09: Contextual Grounding for Faithfulness
|
Informational | N/A |
444455556666 |
eu-west-1 |
OW-06 |
OWASP LLM06: Bedrock Agent Guardrail Association
|
Informational | N/A |
444455556666 |
eu-west-1 |
OW-06 |
OWASP LLM06: Agent Idle Session TTL
|
Informational | N/A |
444455556666 |
eu-west-1 |
OW-03 |
OWASP LLM03: Imported-Model KMS Provenance
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check BR-30: Unable to check Imported model encryption check: An error occurred (AccessDeniedException) when calling the ListImportedModels operation: Your account is not authorized to invoke this API operation. Resolution
Encrypt imported Bedrock models with a customer-managed KMS key to preserve provenance and access control across model artefacts. |
Informational | N/A |
444455556666 |
eu-west-1 |
OW-10 |
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation |
Informational | N/A |
444455556666 |
eu-west-1 |
OW-03 |
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check BR-33: No Lambda functions with Bedrock indicators were found in eu-west-1; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain. |
Informational | N/A |
444455556666 |
eu-west-1 |
OW-03 |
OWASP LLM03: SageMaker Internet Exposure
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-01: No SageMaker notebook instances or domains found to check Resolution
Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths. |
Informational | N/A |
444455556666 |
eu-west-1 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: No SageMaker resources found to check for data protection Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
Informational | N/A |
444455556666 |
eu-west-1 |
OW-09 |
OWASP LLM09: SageMaker Clarify Evaluation
|
Informational | N/A |
444455556666 |
eu-west-1 |
OW-04 |
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation |
Informational | N/A |
444455556666 |
eu-west-1 |
OW-09 |
OWASP LLM09: SageMaker Model Monitor Coverage
|
Informational | N/A |
444455556666 |
eu-west-1 |
OW-03 |
OWASP LLM03: SageMaker Notebook VPC Deployment
|
Informational | N/A |
444455556666 |
eu-west-1 |
OW-03 |
OWASP LLM03: SageMaker Model Network Isolation
|
Informational | N/A |
444455556666 |
eu-west-1 |
OW-10 |
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation |
Informational | N/A |
444455556666 |
eu-west-1 |
OW-03 |
OWASP LLM03: SageMaker Container Repository Access
Details and remediation |
Informational | N/A |
444455556666 |
eu-west-1 |
OW-02 |
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation |
Informational | N/A |
444455556666 |
eu-west-1 |
OW-03 |
OWASP LLM03: SageMaker AutoML Network Isolation
|
Informational | N/A |
444455556666 |
eu-west-1 |
OW-04 |
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically. |
Informational | N/A |
444455556666 |
eu-west-1 |
OW-09 |
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release. |
Informational | N/A |
444455556666 |
eu-west-1 |
OW-04 |
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
444455556666 |
eu-west-1 |
OW-09 |
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
444455556666 |
eu-west-1 |
OW-03 |
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain. |
Informational | N/A |
444455556666 |
eu-west-1 |
OW-04 |
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated. |
Informational | N/A |
444455556666 |
eu-west-1 |
OW-06 |
OWASP LLM06: AgentCore Resource-Based Policies
|
Informational | N/A |
444455556666 |
eu-west-1 |
OW-11 |
OWASP LLM07: System Prompt Embedded in Lambda Env Var
|
Informational | N/A |
444455556666 |
eu-west-1 |
OW-12 |
OWASP LLM07: System-Prompt-Disclosure Denied Topic
|
Informational | N/A |
444455556666 |
eu-west-1 |
SM-01 |
SageMaker Internet Access Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
SM-02 |
SageMaker SSO Configuration Check
|
Medium | Passed |
444455556666 |
eu-west-1 |
SM-03 |
Data Protection Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
SM-04 |
GuardDuty Enabled
|
Medium | Passed |
444455556666 |
eu-west-1 |
SM-05 |
SageMaker Model Registry Issue
|
Informational | N/A |
444455556666 |
eu-west-1 |
SM-05 |
SageMaker Feature Store Issue
|
Informational | N/A |
444455556666 |
eu-west-1 |
SM-05 |
SageMaker Pipelines Issue
|
Informational | N/A |
444455556666 |
eu-west-1 |
SM-06 |
SageMaker Clarify No Clarify Usage
|
Informational | N/A |
444455556666 |
eu-west-1 |
SM-07 |
SageMaker Model Monitor No Model Monitoring
|
Informational | N/A |
444455556666 |
eu-west-1 |
SM-08 |
Model Registry Registry Not Used
|
Informational | N/A |
444455556666 |
eu-west-1 |
SM-09 |
SageMaker Notebook Root Access Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
SM-10 |
SageMaker Notebook VPC Deployment Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
SM-11 |
SageMaker Model Network Isolation Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
SM-12 |
SageMaker Endpoint Instance Count Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
SM-13 |
SageMaker Monitoring Network Isolation Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
SM-14 |
SageMaker Model Repository Access Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
SM-15 |
SageMaker Feature Store Encryption Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
SM-16 |
SageMaker Data Quality Job Encryption Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
SM-17 |
SageMaker Processing Job Encryption Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
SM-18 |
SageMaker Transform Job Encryption Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
SM-19 |
SageMaker Hyperparameter Tuning Job Encryption Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
SM-20 |
SageMaker Compilation Job Encryption Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
SM-21 |
SageMaker AutoML Job Network Isolation Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
SM-22 |
Model Approval Workflow Check
|
Informational | N/A |
444455556666 |
eu-west-1 |
SM-23 |
Model Drift Detection Check
|
Medium | Passed |
444455556666 |
eu-west-1 |
SM-24 |
A/B Testing and Shadow Deployment Check
|
Low | Passed |
444455556666 |
eu-west-1 |
SM-25 |
ML Lineage Tracking - Experiments Not Used
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-01 |
SageMaker Internet Access Check
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-02 |
SageMaker SSO Configuration Check
|
Medium | Passed |
444455556666 |
us-west-2 |
SM-03 |
Data Protection Check
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-04 |
GuardDuty Enabled
|
Medium | Passed |
444455556666 |
us-west-2 |
SM-05 |
SageMaker Model Registry Issue
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-05 |
SageMaker Feature Store Issue
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-05 |
SageMaker Pipelines Issue
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-06 |
SageMaker Clarify No Clarify Usage
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-07 |
SageMaker Model Monitor No Model Monitoring
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-08 |
Model Registry Registry Not Used
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-09 |
SageMaker Notebook Root Access Check
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-10 |
SageMaker Notebook VPC Deployment Check
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-11 |
SageMaker Model Network Isolation Check
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-12 |
SageMaker Endpoint Instance Count Check
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-13 |
SageMaker Monitoring Network Isolation Check
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-14 |
SageMaker Model Repository Access Check
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-15 |
SageMaker Feature Store Encryption Check
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-16 |
SageMaker Data Quality Job Encryption Check
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-17 |
SageMaker Processing Job Encryption Check
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-18 |
SageMaker Transform Job Encryption Check
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-19 |
SageMaker Hyperparameter Tuning Job Encryption Check
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-20 |
SageMaker Compilation Job Encryption Check
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-21 |
SageMaker AutoML Job Network Isolation Check
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-22 |
Model Approval Workflow Check
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-23 |
Model Drift Detection Check
|
Medium | Passed |
444455556666 |
us-west-2 |
SM-24 |
A/B Testing and Shadow Deployment Check
|
Low | Passed |
444455556666 |
us-west-2 |
SM-25 |
ML Lineage Tracking - Experiments Not Used
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-01 |
Direct Internet Access Enabled
|
High | Failed |
444455556666 |
us-east-2 |
SM-02 |
SageMaker SSO Configuration Check
|
Medium | Passed |
444455556666 |
us-east-2 |
SM-03 |
Missing Encryption Configuration
|
High | Failed |
444455556666 |
us-east-2 |
SM-04 |
GuardDuty Enabled
|
Medium | Passed |
444455556666 |
us-east-2 |
SM-05 |
SageMaker Model Registry Issue
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-05 |
SageMaker Feature Store Issue
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-05 |
SageMaker Pipelines Issue
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-06 |
SageMaker Clarify No Clarify Usage
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-07 |
SageMaker Model Monitor No Model Monitoring
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-08 |
Model Registry Registry Not Used
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-09 |
SageMaker Notebook Root Access Enabled
Details and remediationDetails
Notebook instance 'aws-neptune-Mybookstore-Bookstore-WS-Notebook' has root access enabled. Root access allows users to install arbitrary software, modify system configurations, and potentially escalate privileges. Resolution
Disable root access by updating the notebook instance with RootAccess=Disabled. Note: Lifecycle configurations will still run with root access. |
High | Failed |
444455556666 |
us-east-2 |
SM-10 |
SageMaker Notebook VPC Deployment Check
|
High | Passed |
444455556666 |
us-east-2 |
SM-11 |
SageMaker Model Network Isolation Check
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-12 |
SageMaker Endpoint Instance Count Check
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-13 |
SageMaker Monitoring Network Isolation Check
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-14 |
SageMaker Model Repository Access Check
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-15 |
SageMaker Feature Store Encryption Check
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-16 |
SageMaker Data Quality Job Encryption Check
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-17 |
SageMaker Processing Job Encryption Check
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-18 |
SageMaker Transform Job Encryption Check
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-19 |
SageMaker Hyperparameter Tuning Job Encryption Check
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-20 |
SageMaker Compilation Job Encryption Check
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-21 |
SageMaker AutoML Job Network Isolation Check
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-22 |
Model Approval Workflow Check
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-23 |
Model Drift Detection Check
|
Medium | Passed |
444455556666 |
us-east-2 |
SM-24 |
A/B Testing and Shadow Deployment Check
|
Low | Passed |
444455556666 |
us-east-2 |
SM-25 |
ML Lineage Tracking - Experiments Not Used
|
Informational | N/A |
444455556666 |
us-west-2 |
AC-01 |
AgentCore VPC Configuration Check
|
Informational | N/A |
444455556666 |
us-west-2 |
AC-04 |
AgentCore Observability Check
|
Informational | N/A |
444455556666 |
us-west-2 |
AC-05 |
AgentCore Encryption Check
|
Informational | N/A |
444455556666 |
us-west-2 |
AC-06 |
AgentCore Browser Tool Recording Check
|
Informational | N/A |
444455556666 |
us-west-2 |
AC-07 |
AgentCore Memory Configuration Check
|
Informational | N/A |
444455556666 |
us-west-2 |
AC-13 |
AgentCore Gateway Configuration Check
|
Informational | N/A |
444455556666 |
us-west-2 |
AC-08 |
AgentCore VPC Endpoints Check
|
Informational | N/A |
444455556666 |
us-west-2 |
AC-10 |
AgentCore Resource-Based Policies Check
|
Informational | N/A |
444455556666 |
us-west-2 |
AC-11 |
AgentCore Policy Engine Encryption Check
|
Informational | N/A |
444455556666 |
us-west-2 |
AC-12 |
AgentCore Gateway Encryption Check
|
Informational | N/A |
444455556666 |
us-west-2 |
AG-24 |
Agentic AI Gateway Inbound Authorization
|
Informational | N/A |
444455556666 |
us-west-2 |
AG-25 |
Agentic AI Gateway Tool Policy Enforcement
|
Informational | N/A |
444455556666 |
us-west-2 |
AG-26 |
Agentic AI Gateway Error Detail Exposure
|
Informational | N/A |
444455556666 |
us-west-2 |
AG-27 |
Agentic AI Gateway WAF Protection
|
Informational | N/A |
444455556666 |
us-west-2 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-19 |
Agentic AI Memory Data Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found Resolution
Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-20 |
Agentic AI Private AgentCore Connectivity
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found Resolution
Create required VPC endpoints for AgentCore services and validate endpoint availability. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-21 |
Agentic AI Resource Policy Boundary
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies Resolution
Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-22 |
Agentic AI Policy Engine Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found Resolution
Configure policy engines with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-23 |
Agentic AI Gateway Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found Resolution
Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
444455556666 |
Global |
SM-02 |
SageMaker IAM Permissions Check
|
High | Passed |
444455556666 |
us-east-1 |
SM-01 |
SageMaker Internet Access Check
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-02 |
SageMaker SSO Configuration Check
|
Medium | Passed |
444455556666 |
us-east-1 |
SM-03 |
Data Protection Check
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-04 |
GuardDuty Enabled
|
Medium | Passed |
444455556666 |
us-east-1 |
SM-05 |
SageMaker Model Registry Issue
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-05 |
SageMaker Feature Store Issue
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-05 |
SageMaker Pipelines Issue
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-06 |
SageMaker Clarify No Clarify Usage
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-07 |
SageMaker Model Monitor No Model Monitoring
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-08 |
Model Registry Registry Not Used
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-09 |
SageMaker Notebook Root Access Check
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-10 |
SageMaker Notebook VPC Deployment Check
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-11 |
SageMaker Model Network Isolation Check
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-12 |
SageMaker Endpoint Instance Count Check
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-13 |
SageMaker Monitoring Network Isolation Check
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-14 |
SageMaker Model Repository Access Check
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-15 |
SageMaker Feature Store Encryption Check
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-16 |
SageMaker Data Quality Job Encryption Check
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-17 |
SageMaker Processing Job Encryption Check
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-18 |
SageMaker Transform Job Encryption Check
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-19 |
SageMaker Hyperparameter Tuning Job Encryption Check
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-20 |
SageMaker Compilation Job Encryption Check
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-21 |
SageMaker AutoML Job Network Isolation Check
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-22 |
Model Approval Workflow Check
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-23 |
Model Drift Detection Check
|
Medium | Passed |
444455556666 |
us-east-1 |
SM-24 |
A/B Testing and Shadow Deployment Check
|
Low | Passed |
444455556666 |
us-east-1 |
SM-25 |
ML Lineage Tracking - Experiments Not Used
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-02 |
Amazon Bedrock private connectivity check
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-04 |
Bedrock Model Invocation Logging Check
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-05 |
Bedrock Guardrails Check
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-06 |
Bedrock CloudTrail Logging Check
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-07 |
Bedrock Prompt Management Check
Details and remediationDetails
Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates |
Informational | N/A |
444455556666 |
us-east-2 |
BR-08 |
Bedrock Agent IAM Roles Check
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-09 |
Bedrock Knowledge Base Encryption Check
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-10 |
Bedrock Guardrail IAM Enforcement Check
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-11 |
Bedrock Custom Model Encryption Check
|
Low | N/A |
444455556666 |
us-east-2 |
BR-12 |
Bedrock Invocation Log Encryption Check
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-13 |
Bedrock Flows Guardrails Check
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-16 |
Guardrail Tier Validation Check
|
Medium | N/A |
444455556666 |
us-east-2 |
BR-17 |
Custom Model Customer-Managed KMS Encryption Check
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-18 |
Model Evaluation Implementation Check
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-19 |
Prompt Flow Validation Check
|
Medium | N/A |
444455556666 |
us-east-2 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Check
|
High | N/A |
444455556666 |
us-east-2 |
BR-21 |
Agent Action Group IAM Least Privilege Check
|
High | N/A |
444455556666 |
us-east-2 |
BR-22 |
Model Invocation Throttling Limits Check
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-23 |
Guardrail Content Filter Coverage Check
|
High | N/A |
444455556666 |
us-east-2 |
BR-24 |
Automated Reasoning Policy Implementation Check
|
Medium | N/A |
444455556666 |
us-east-2 |
BR-25 |
RAG Evaluation Jobs Check
|
Low | N/A |
444455556666 |
us-east-2 |
BR-26 |
Guardrail Sensitive Information Filter Check
|
High | N/A |
444455556666 |
us-east-2 |
BR-27 |
Guardrail Contextual Grounding Check
|
Medium | N/A |
444455556666 |
us-east-2 |
BR-28 |
Agent Guardrail Association Check
|
High | N/A |
444455556666 |
us-east-2 |
BR-29 |
Agent Idle Session TTL Check
|
Low | N/A |
444455556666 |
us-east-2 |
BR-30 |
Imported Model Customer-Managed KMS Encryption Check
|
High | N/A |
444455556666 |
us-east-2 |
BR-31 |
Batch Inference Output Encryption Check
|
Medium | N/A |
444455556666 |
us-east-2 |
BR-32 |
Bedrock CloudWatch Alarm Check
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-33 |
Amazon Inspector Lambda Code Scanning Check
Details and remediationDetails
No Lambda functions with Bedrock indicators were found in us-east-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
No action required. If Bedrock-calling Lambda functions exist, ensure their function name, ARN, description, handler, role, or environment variables contain a Bedrock identifier that the assessment can detect, or evaluate Inspector coverage manually. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-07 |
Agentic AI Model Invocation Logging
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-08 |
Agentic AI API Audit Trail
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage Resolution
Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-10 |
Agentic AI Adversarial Evaluation Coverage
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs Resolution
Configure model or application evaluations that include adversarial, safety, and security-relevant test cases. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-11 |
Agentic AI Prompt Flow Validation
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region Resolution
Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-06 |
Agentic AI Tool Execution Least Privilege
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region Resolution
Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-12 |
Agentic AI Invocation Abuse Controls
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas Resolution
Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-02 |
Agentic AI Harmful Content Guardrail Coverage
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-04 |
Agentic AI Automated Reasoning Guardrails
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: No Bedrock guardrails configured in this region Resolution
Configure automated reasoning policies on guardrails where formal response validation is required. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-03 |
Agentic AI Sensitive Information Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: No Bedrock guardrails configured in this region Resolution
Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-05 |
Agentic AI Grounding Controls
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: No Bedrock guardrails configured in this region Resolution
Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-01 |
Agentic AI Agent Guardrail Association
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region Resolution
Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-13 |
Agentic AI Session Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region Resolution
Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-14 |
Agentic AI Operational Abuse Alarms
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms Resolution
Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available. |
Informational | N/A |
777788889999 |
eu-west-1 |
AC-01 |
AgentCore VPC Configuration Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
AC-04 |
AgentCore Observability Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
AC-05 |
AgentCore Encryption Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
AC-06 |
AgentCore Browser Tool Recording Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
AC-07 |
AgentCore Memory Configuration Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
AC-13 |
AgentCore Gateway Configuration Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
AC-08 |
AgentCore VPC Endpoints Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
AC-10 |
AgentCore Resource-Based Policies Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
AC-11 |
AgentCore Policy Engine Encryption Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
AC-12 |
AgentCore Gateway Encryption Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
AG-24 |
Agentic AI Gateway Inbound Authorization
|
Informational | N/A |
777788889999 |
eu-west-1 |
AG-25 |
Agentic AI Gateway Tool Policy Enforcement
|
Informational | N/A |
777788889999 |
eu-west-1 |
AG-26 |
Agentic AI Gateway Error Detail Exposure
|
Informational | N/A |
777788889999 |
eu-west-1 |
AG-27 |
Agentic AI Gateway WAF Protection
|
Informational | N/A |
777788889999 |
eu-west-1 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
Informational | N/A |
777788889999 |
eu-west-1 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Informational | N/A |
777788889999 |
eu-west-1 |
AG-19 |
Agentic AI Memory Data Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found Resolution
Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions. |
Informational | N/A |
777788889999 |
eu-west-1 |
AG-20 |
Agentic AI Private AgentCore Connectivity
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found Resolution
Create required VPC endpoints for AgentCore services and validate endpoint availability. |
Informational | N/A |
777788889999 |
eu-west-1 |
AG-21 |
Agentic AI Resource Policy Boundary
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies Resolution
Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources. |
Informational | N/A |
777788889999 |
eu-west-1 |
AG-22 |
Agentic AI Policy Engine Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found Resolution
Configure policy engines with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
777788889999 |
eu-west-1 |
AG-23 |
Agentic AI Gateway Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found Resolution
Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
777788889999 |
us-east-1 |
OW-01 |
OWASP LLM01: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: Model invocation logging is not enabled. This limits your ability to track and audit model usage. Resolution
Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis. |
Medium | Failed |
777788889999 |
us-east-1 |
OW-07 |
OWASP LLM07: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-04: Model invocation logging is not enabled. This limits your ability to track and audit model usage. Resolution
Enable Bedrock model invocation logging so prompt-extraction attempts against the system prompt are auditable after the fact. |
Medium | Failed |
777788889999 |
us-east-1 |
OW-07 |
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management is being used with 1 prompts Resolution
Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident. |
Low | Passed |
777788889999 |
us-east-1 |
OW-07 |
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-16: Guardrail 'aiml-sec-test-test-guardrail' (ID: jkceg2tprvwh) could not be assessed because GetGuardrail returned AccessDeniedException. Resolution
Set guardrail contentPolicy.tier.tierName to STANDARD; Standard tier additionally detects prompt-leakage attacks. |
Informational | N/A |
777788889999 |
us-east-1 |
OW-09 |
OWASP LLM09: Model Evaluation Jobs
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check BR-18: No Bedrock model evaluation jobs found. Model evaluation helps assess toxicity, accuracy, semantic robustness, and other safety metrics before production deployment. Resolution
Run Bedrock model evaluation jobs that include correctness and safety datasets. |
Medium | Failed |
777788889999 |
us-east-1 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: Knowledge base 'knowledge-base-prowler-findings' (ID: 9K2QZLVCZW) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption. |
Informational | N/A |
777788889999 |
us-east-1 |
OW-10 |
OWASP LLM10: Service Quota Throttling Limits
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-22: 9 custom throttling quotas are configured. Regular quota review helps maintain appropriate rate limits. Resolution
Customise Bedrock TPM / RPM service quotas above the account default to establish an explicit consumption ceiling. |
Low | Passed |
777788889999 |
us-east-1 |
OW-01 |
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: Guardrail 'aiml-sec-test-test-guardrail' (ID: jkceg2tprvwh) could not be assessed because GetGuardrail returned AccessDeniedException. Resolution
Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier. |
Informational | N/A |
777788889999 |
us-east-1 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: Knowledge base 'knowledge-base-prowler-findings' (ID: 9K2QZLVCZW) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context. |
Low | Failed |
777788889999 |
us-east-1 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check BR-25: Knowledge base 'knowledge-base-prowler-findings' (ID: 9K2QZLVCZW) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates. |
Low | Failed |
777788889999 |
us-east-1 |
OW-02 |
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check BR-26: Guardrail 'aiml-sec-test-test-guardrail' (ID: jkceg2tprvwh) could not be assessed because GetGuardrail returned AccessDeniedException. Resolution
Configure guardrail sensitiveInformationPolicy with PII entities and regex patterns; set outputAction=ANONYMIZE or BLOCK. |
Informational | N/A |
777788889999 |
us-east-1 |
OW-01 |
OWASP LLM01: Contextual Grounding Guardrail
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-27: Guardrail 'aiml-sec-test-test-guardrail' (ID: jkceg2tprvwh) could not be assessed because GetGuardrail returned AccessDeniedException. Resolution
Enable Bedrock guardrail contextual grounding checks to reduce the surface for indirect prompt injection through retrieved context. |
Informational | N/A |
777788889999 |
us-east-1 |
OW-04 |
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-27: Guardrail 'aiml-sec-test-test-guardrail' (ID: jkceg2tprvwh) could not be assessed because GetGuardrail returned AccessDeniedException. Resolution
Enable contextual grounding guardrail filters so retrieved context that diverges from ground truth is filtered before reaching the model. |
Informational | N/A |
777788889999 |
us-east-1 |
OW-09 |
OWASP LLM09: Contextual Grounding for Faithfulness
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check BR-27: Guardrail 'aiml-sec-test-test-guardrail' (ID: jkceg2tprvwh) could not be assessed because GetGuardrail returned AccessDeniedException. Resolution
Set the contextual grounding filter threshold to at least 0.70 to reduce hallucinated responses. |
Informational | N/A |
777788889999 |
us-east-1 |
OW-06 |
OWASP LLM06: Bedrock Agent Guardrail Association
|
Low | Passed |
777788889999 |
us-east-1 |
OW-03 |
OWASP LLM03: Imported-Model KMS Provenance
|
Informational | N/A |
777788889999 |
us-east-1 |
OW-10 |
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-32: No CloudWatch alarms are configured on Amazon Bedrock runtime metrics (AWS/Bedrock namespace). Without alarms, abuse, denial-of-wallet, sustained throttling, and content-filter spikes can go undetected. Resolution
Create CloudWatch alarms on Bedrock InvocationThrottles, InputTokenCount, OutputTokenCount, and EstimatedTPMQuotaUsage. |
Medium | Failed |
777788889999 |
us-east-1 |
OW-03 |
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check BR-33: Amazon Inspector Lambda standard scanning and Lambda code scanning are both ENABLED in us-east-1. Detected 1 Lambda function(s) with Bedrock indicators: aiml-security-aiml-security-mgmt-BedrockAssessment. Resolution
Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain. |
Medium | Passed |
777788889999 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Internet Exposure
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-01: SageMaker notebook instance 'aiml-sec-test-notebook-with-internet' has direct internet access enabled Resolution
Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths. |
High | Failed |
777788889999 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Internet Exposure
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-01: SageMaker domain 'd-ilmtsfeenavc' (aiml-sec-test-domain-fail-028e1010-52cbf970) is not configured for VPC-only access Resolution
Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths. |
High | Failed |
777788889999 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Internet Exposure
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-01: SageMaker domain 'd-cmz7ohkxxop3' (aiml-sec-test-domain-fail-fef4e7f0-bb429d11) is not configured for VPC-only access Resolution
Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths. |
High | Failed |
777788889999 |
us-east-1 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: Notebook Instance 'aiml-sec-test-notebook-with-internet' - No KMS key configured Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
High | Failed |
777788889999 |
us-east-1 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: Domain 'aiml-sec-test-domain-fail-028e1010-52cbf970' - No KMS key configured Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
High | Failed |
777788889999 |
us-east-1 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: Domain 'aiml-sec-test-domain-fail-fef4e7f0-bb429d11' - No KMS key configured Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
High | Failed |
777788889999 |
us-east-1 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: Training Job 'aiml-sec-test-training-no-encryption-028e1010-e2fb8765' - No output encryption configured Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
High | Failed |
777788889999 |
us-east-1 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: Training Job 'aiml-sec-test-training-no-encryption-028e1010-e2fb8765' - Inter-container traffic encryption not enabled Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
Medium | Failed |
777788889999 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Clarify Evaluation
|
Informational | N/A |
777788889999 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation |
Informational | N/A |
777788889999 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Model Monitor Coverage
|
Informational | N/A |
777788889999 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Notebook VPC Deployment
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-10: Notebook instance 'aiml-sec-test-notebook-with-internet' is not deployed in a custom VPC. This uses SageMaker's service VPC with reduced network isolation. Resolution
Deploy SageMaker notebook instances inside a VPC so package, data, and model artifact access can be controlled through private network paths. |
High | Failed |
777788889999 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Model Network Isolation
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-11: Model 'SageMakerModelNoIsolation-yQ7EpJeL7pgI' does not have network isolation enabled. Model containers can make outbound network calls, potentially exfiltrating data. Resolution
Enable network isolation on SageMaker models so inference containers cannot make unmanaged outbound calls that alter dependencies or exfiltrate model artifacts. |
High | Failed |
777788889999 |
us-east-1 |
OW-10 |
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check SM-11: Model 'SageMakerModelNoIsolation-yQ7EpJeL7pgI' does not have network isolation enabled. Model containers can make outbound network calls, potentially exfiltrating data. Resolution
Enable SageMaker model network isolation to prevent deployed model containers from making uncontrolled outbound calls that can amplify consumption or abuse downstream services. |
High | Failed |
777788889999 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Container Repository Access
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-14: Model 'SageMakerModelWithIsolation-JASFpUHjajdk' uses Platform repository access mode. Container images are pulled from public/external registries, exposing supply chain risks. Resolution
Configure SageMaker models to pull container images from private ECR repositories through VPC repository access instead of platform or public registry paths. |
Medium | Failed |
777788889999 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Container Repository Access
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-14: Model 'SageMakerModelNoIsolation-yQ7EpJeL7pgI' uses Platform repository access mode. Container images are pulled from public/external registries, exposing supply chain risks. Resolution
Configure SageMaker models to pull container images from private ECR repositories through VPC repository access instead of platform or public registry paths. |
Medium | Failed |
777788889999 |
us-east-1 |
OW-02 |
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-15: Feature group 'aiml-sec-test-feature-group' offline store does not have KMS encryption configured. Feature data in S3 may not be encrypted with customer-managed keys. Resolution
Encrypt SageMaker Feature Store offline stores with customer-managed KMS keys so sensitive feature data is protected at rest. |
Medium | Failed |
777788889999 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker AutoML Network Isolation
|
Informational | N/A |
777788889999 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: Checked 1 model package groups. Approval workflows appear to be properly configured. Resolution
Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically. |
Medium | Passed |
777788889999 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check SM-22: Checked 1 model package groups. Approval workflows appear to be properly configured. Resolution
Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release. |
Medium | Passed |
777788889999 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
777788889999 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
777788889999 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain. |
Informational | N/A |
777788889999 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated. |
Informational | N/A |
777788889999 |
Global |
OW-06 |
OWASP LLM06: AgentCore IAM Least Privilege
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check AC-02: The following roles have wildcard AgentCore permissions on all resources: aiml-sec-test-resources-AgentCoreOverlyPermissiveRo-IQso7VQN0jOV Resolution
Remove AmazonBedrockAgentCoreFullAccess (or equivalents) from identities that only need read/execute permissions. |
High | Failed |
777788889999 |
us-east-1 |
OW-06 |
OWASP LLM06: AgentCore Resource-Based Policies
|
Informational | N/A |
777788889999 |
us-east-1 |
OW-10 |
OWASP LLM10: WAF Rate-Based & Shield Protection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-01: AWS Shield Advanced is not subscribed. GenAI API endpoints are vulnerable to volumetric DDoS attacks that can exhaust token quotas and inflate costs. Resolution
Add a WAF RateBasedStatement plus a SizeConstraintStatement on the GenAI ingress and subscribe to AWS Shield Advanced. |
Low | Failed |
777788889999 |
us-east-1 |
OW-10 |
OWASP LLM10: WAF Rate-Based & Shield Protection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-01: No AWS WAF regional Web ACLs found. Without WAF, GenAI endpoints lack rate-based rules to block abusive callers. Resolution
Add a WAF RateBasedStatement plus a SizeConstraintStatement on the GenAI ingress and subscribe to AWS Shield Advanced. |
Medium | Failed |
777788889999 |
us-east-1 |
OW-10 |
OWASP LLM10: API Gateway Usage Plans
|
Informational | N/A |
777788889999 |
us-east-1 |
OW-10 |
OWASP LLM10: Bedrock TPM/RPM Quotas Customised
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-03: Found 240 Bedrock token-based quota(s); at least one applied value exceeds the AWS default, indicating quotas have been reviewed and raised. Resolution
Customise Bedrock service quotas above the account default so consumption is explicitly bounded. |
Medium | Passed |
777788889999 |
us-east-1 |
OW-10 |
OWASP LLM10: Cost Anomaly Detection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-04: No AWS Cost Anomaly Detection monitors found. Unexpected spikes in Bedrock/SageMaker usage (e.g., from prompt injection loops) will go undetected. Resolution
Configure AWS Cost Anomaly Detection monitors that include Bedrock and SageMaker. |
Medium | Failed |
777788889999 |
us-east-1 |
OW-10 |
OWASP LLM10: Token / Throttle Alarms
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-05: No CloudWatch alarms found for Bedrock metrics. Token exhaustion and throttling events will not trigger operational alerts. Resolution
Create CloudWatch alarms on the Bedrock namespace for InvocationThrottles and token counters. |
Medium | Failed |
777788889999 |
us-east-1 |
OW-10 |
OWASP LLM10: AWS Budgets with Bedrock Filters
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-06: No AWS Budgets found scoped to Bedrock or SageMaker. Unbounded GenAI spend can go undetected until the monthly bill. Resolution
Configure AWS Budgets with FilterExpression / CostFilters targeting Bedrock or SageMaker spend, with an alerting SNS action. |
Medium | Failed |
777788889999 |
us-east-1 |
OW-06 |
OWASP LLM06: Agent Execution Role Least Privilege
|
High | Passed |
777788889999 |
us-east-1 |
OW-06 |
OWASP LLM06: AgentCore Gateway Policy Engine
|
Informational | N/A |
777788889999 |
us-east-1 |
OW-06 |
OWASP LLM06: Agent Tool Concurrency Limits
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check FS-09: Agent-related Lambda functions without reserved concurrency: aiml-security-aiml-security-mgmt-FinServAssessment, aiml-sec-test-resources-SageMakerJobCustomResource-ZA5QCAi0pN3d, AIMLSecurityAssessment-CodeBuildStartBuildLambda-VYOqtzWoNo3m, aiml-security-aiml-security-mgmt-CleanupBucket, aiml-security-aiml-security-mgmt-SagemakerAssessment, aiml-security-aiml-security-mgmt-GenerateReport, aiml-security-aiml-security-mgmt-OWASPAssessment, aiml-security-aiml-security-mgmt-IAMPermissionCaching, aiml-security-aiml-security-mgmt-AgentCoreAssessment, aiml-security-aiml-security-mgmt-BedrockAssessment. Unlimited concurrency allows runaway agent loops to exhaust account limits. Resolution
Set reserved concurrency on agent action-group Lambdas so a runaway agent cannot exhaust downstream capacity. |
Medium | Failed |
777788889999 |
us-east-1 |
OW-06 |
OWASP LLM06: Human-in-the-Loop Callback States
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check FS-10: No Step Functions state machines with agent/approval naming found. Verify that high-risk agent actions (e.g., fund transfers, account changes) have human approval gates. Resolution
Insert Step Functions .waitForTaskToken callback states before any high-risk agent-triggered action. |
Informational | N/A |
777788889999 |
us-east-1 |
OW-03 |
OWASP LLM03: SCP-Enforced Model Allowlist
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check FS-12: No Service Control Policies reference Bedrock. Without SCPs, any account in the organization can access any Bedrock model, including unapproved third-party models. Resolution
Attach an Organizations SCP that denies bedrock:InvokeModel* except for allowlisted bedrock:ModelId values. |
High | Failed |
777788889999 |
us-east-1 |
OW-03 |
OWASP LLM03: Custom-Model Provenance Tags
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check FS-13: 2 model(s) missing required provenance tags: - SageMaker model 'SageMakerModelWithIsolation-JASFpUHjajdk' missing tags: {'approval-date', 'source', 'version'} - SageMaker model 'SageMakerModelNoIsolation-yQ7EpJeL7pgI' missing tags: {'approval-date', 'source', 'version'} Resolution
Tag every Bedrock custom model with model-source, model-version, approval-date, and risk-tier so provenance is auditable. |
Medium | Failed |
777788889999 |
us-east-1 |
OW-03 |
OWASP LLM03: Config Rules for Model Onboarding
|
Medium | Passed |
777788889999 |
us-east-1 |
OW-03 |
OWASP LLM03: Adversarial Evaluation Coverage
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check FS-15: No Bedrock Model Evaluation jobs found. Models have not been evaluated for adversarial robustness. FinServ model-risk management (SR 11-7) expects documented model validation/evaluation. Resolution
Run Bedrock evaluation jobs that include adversarial and safety datasets before promoting a model to production. |
Medium | Failed |
777788889999 |
us-east-1 |
OW-03 |
OWASP LLM03: ECR Image Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check FS-16: 2 ECR repo(s) without scan-on-push: cdk-hnb659fds-container-assets-777788889999-us-east-1, aiml-sec-test-agentcore-no-encryption. Resolution
Enable Amazon Inspector enhanced scanning or scan-on-push on ECR repositories that hold model / agent container images. |
High | Failed |
777788889999 |
us-east-1 |
OW-04 |
OWASP LLM04: Feature Store Offline Recovery
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check FS-20: 1 feature group(s) lack an active offline store: aiml-sec-test-feature-group. Without offline store, historical feature data cannot be used for rollback. Resolution
Enable OfflineStoreConfig on SageMaker Feature Groups so features have a durable, point-in-time record for rollback after a poisoning event. |
Medium | Failed |
777788889999 |
us-east-1 |
OW-04 |
OWASP LLM04: Training-Data Versioning
|
High | Passed |
777788889999 |
us-east-1 |
OW-08 |
OWASP LLM08: KB IAM Scope
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-22: 825 role(s) with wildcard KB permissions: - Role 'Admin' allows '*' - Role 'aiml-sec-test-resources-BedrockAgentRole-RScmoTZfp2sC' allows 'bedrock:InvokeModel' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-test-resources-BedrockAgentRole-RScmoTZfp2sC' allows 'bedrock:InvokeModelWithResponseStream' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-test-resources-BedrockAgentRoleWithoutGuar-Z3kN5ANhP89G' allows 'bedrock:InvokeModel' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-test-resources-BedrockAgentRoleWithoutGuar-Z3kN5ANhP89G' allows 'bedrock:InvokeModelWithResponseStream' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-test-resources-BedrockFullAccessRole-zAFkGLkWQ61a' allows 'bedrock:*' - Role 'aiml-security-mgmt-BedrockSecurityAssessmentFunctio-a7GKJ6O4151K' allows 'bedrock:ListGuardrails' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-mgmt-BedrockSecurityAssessmentFunctio-a7GKJ6O4151K' allows 'bedrock:GetGuardrail' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-mgmt-BedrockSecurityAssessmentFunctio-a7GKJ6O4151K' allows 'bedrock:ListModelInvocationJobs' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-mgmt-BedrockSecurityAssessmentFunctio-a7GKJ6O4151K' allows 'bedrock:GetModelInvocationLoggingConfiguration' on Resource '*' (no ARN scoping to specific Knowledge Bases) Resolution
Scope Knowledge Base IAM roles to specific KB ARNs; remove wildcard bedrock:* on KB actions. |
High | Failed |
777788889999 |
us-east-1 |
OW-08 |
OWASP LLM08: KB Metadata Filtering
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-24: Found 1 Knowledge Base(s). Tenant-isolation metadata filtering is a design pattern that cannot be verified via API — manual review required. Verify that metadata attributes (e.g., tenantId, classification) are indexed and that Retrieve calls include RetrievalFilter conditions for tenant isolation. Resolution
Define Knowledge Base metadata fields so tenant / document-level filtering can be applied at retrieval time. |
Informational | N/A |
777788889999 |
us-east-1 |
OW-08 |
OWASP LLM08: OpenSearch Serverless Encryption
Details and remediation |
High | Passed |
777788889999 |
us-east-1 |
OW-08 |
OWASP LLM08: OpenSearch Serverless Network Policy
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-26: Found 1 network policy(ies) but none restrict to VPC. Vector stores may be accessible from the public internet. Resolution
Set AllowFromPublic=false on the OpenSearch Serverless network policy and restrict access to bedrock.amazonaws.com or a specific VPC endpoint. |
High | Failed |
777788889999 |
us-east-1 |
OW-09 |
OWASP LLM09: Knowledge-Base Ingestion Freshness
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check FS-31: 1 data source(s) not synced in >7 days (a configurable review threshold, NOT an AWS-mandated limit): - KB 'knowledge-base-prowler-findings' source 'knowledge-base-quick-start-9lb68-data-source' last synced 432 days ago Confirm this age is acceptable for each data source's currency requirement — slow-changing reference data may legitimately sync infrequently. Resolution
Sync Knowledge Base data sources on a schedule (weekly at most); stale KB content increases hallucination risk. |
Medium | Failed |
777788889999 |
us-east-1 |
OW-09 |
OWASP LLM09: Source Attribution
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check FS-32: Source attribution in GenAI responses cannot be verified via AWS APIs. Manual review required to confirm responses include citations. Resolution
Return citations in RetrieveAndGenerate responses so end users can verify grounding. |
Informational | N/A |
777788889999 |
us-east-1 |
OW-09 |
OWASP LLM09: KB S3 Data-Source Integrity
|
Medium | Passed |
777788889999 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker Model Card Documentation
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check FS-42: No SageMaker Model Cards found. Production AI models lack documented intended use, limitations, and bias evaluations. Resolution
Create SageMaker Model Cards for production models that document intended use, training data provenance, and bias/fairness evaluations so poisoned or drifted models are detectable against a documented baseline. |
Medium | Failed |
777788889999 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Model Card Documentation
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check FS-42: No SageMaker Model Cards found. Production AI models lack documented intended use, limitations, and bias evaluations. Resolution
Document each production model's intended use, known limitations, and evaluation results in a SageMaker Model Card so misinformation risks tied to model behaviour are traceable to a reviewed system card. |
Medium | Failed |
777788889999 |
us-east-1 |
OW-02 |
OWASP LLM02: CloudWatch Log Data Protection Policies
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-43: No CloudWatch Logs data protection policies found. PII (SSN, account numbers, credit card numbers) in Bedrock invocation logs may be stored in plaintext. Resolution
Apply a CloudWatch Logs data protection policy to log groups that receive Bedrock invocation logs. |
High | Failed |
777788889999 |
us-east-1 |
OW-02 |
OWASP LLM02: Macie Sensitive-Data Discovery
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-44: Amazon Macie is not enabled. S3 buckets containing training data and KB data sources are not being scanned for PII/sensitive data. Resolution
Enable Amazon Macie with automated discovery on S3 buckets that hold training or knowledge-base data. |
High | Failed |
777788889999 |
us-east-1 |
OW-02 |
OWASP LLM02: Guardrail PII Entities Coverage
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-45: This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved. Resolution
Add the required PII entity types to the guardrail sensitiveInformationPolicy so PII in prompts/responses is filtered. |
Informational | N/A |
777788889999 |
us-east-1 |
OW-02 |
OWASP LLM02: S3 Data-Classification Tagging
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-46: 3 AI/ML bucket(s) without data-classification tags: aiml-sec-test-resources-bedrockloggingbucket-wtuvpinrlpmd, aiml-sec-test-resources-sagemakerbucket-6zzmxxaxco6g, aiml-security-mgmt-aimlassessmentbucket-kbitsdgexylv. Resolution
Tag training and knowledge-base S3 buckets with a data-classification tag so downstream automations enforce controls consistent with the sensitivity level. |
Medium | Failed |
777788889999 |
us-east-1 |
OW-09 |
OWASP LLM09: Grounding Filter Threshold
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check FS-47: This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved. Resolution
Set the contextual grounding filter threshold to at least 0.70 on guardrails used for RAG workflows. |
Informational | N/A |
777788889999 |
us-east-1 |
OW-09 |
OWASP LLM09: Active Knowledge Base Present
|
Medium | Passed |
777788889999 |
us-east-1 |
OW-01 |
OWASP LLM01: PROMPT_ATTACK Filter at Standard Tier
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check FS-51: This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved. Resolution
Set guardrail PROMPT_ATTACK filter to Standard tier with inputStrength=HIGH. |
Informational | N/A |
777788889999 |
us-east-1 |
OW-01 |
OWASP LLM01: Bedrock-Calling Lambda Runtimes
|
Medium | Passed |
777788889999 |
us-east-1 |
OW-01 |
OWASP LLM01: WAF SQLi & KnownBadInputs Coverage
|
Informational | N/A |
777788889999 |
us-east-1 |
OW-01 |
OWASP LLM01: Adversarial Testing Evidence
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check FS-54: Penetration testing evidence cannot be verified via AWS APIs. Manual review required to confirm GenAI applications have been tested. Resolution
Track adversarial / red-team penetration test evidence for the GenAI application via resource tags or an equivalent audit trail. |
Informational | N/A |
777788889999 |
us-east-1 |
OW-05 |
OWASP LLM05: Output-Validation Lambda
Details and remediationDetails
OWASP category: LLM05:2025 Improper Output Handling. Source check FS-55: No Lambda functions with output validation/sanitization naming found. GenAI outputs may be passed directly to downstream systems without validation. Resolution
Deploy an output-validation / sanitisation Lambda between the model response and any downstream consumer to filter injection payloads in generated output. |
Medium | Failed |
777788889999 |
us-east-1 |
OW-05 |
OWASP LLM05: WAF XSS Protection
|
Informational | N/A |
777788889999 |
us-east-1 |
OW-05 |
OWASP LLM05: Output Encoding Libraries
Details and remediationDetails
OWASP category: LLM05:2025 Improper Output Handling. Source check FS-57: Output encoding practices cannot be verified via AWS APIs. Manual code review required. Resolution
Ensure Lambdas that render model output use a well-known output-encoding library appropriate to the downstream sink (HTML, SQL, shell, etc.). |
Informational | N/A |
777788889999 |
us-east-1 |
OW-05 |
OWASP LLM05: Step Functions Output Schema Validation
Details and remediationDetails
OWASP category: LLM05:2025 Improper Output Handling. Source check FS-58: Found 0 Lambda function(s) whose names suggest schema/validation handling. Structured-output / JSON-schema validation of GenAI responses is an application-layer control that cannot be verified automatically — manual review required. Resolution
Add explicit schema-validation states in Step Functions workflows that consume model output. |
Informational | N/A |
777788889999 |
us-east-1 |
OW-06 |
OWASP LLM06: Agent Transaction Thresholds
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check FS-67: The following agent action-group Lambda functions have no environment variables whose names suggest transaction-value threshold configuration (this is a best-effort heuristic — a threshold enforced in code or in an AgentCore Policy Engine rule would not be detected here, so treat this as a prompt for manual verification rather than a definitive gap). Without explicit limits, agents could initiate unbounded financial transactions: - aiml-security-aiml-security-mgmt-FinServAssessment - aiml-security-aiml-security-mgmt-AgentCoreAssessment - aiml-security-aiml-security-mgmt-BedrockAssessment Resolution
Encode agent transaction thresholds in Cedar policies or Lambda configuration so per-action limits are enforced. |
High | Failed |
777788889999 |
us-east-1 |
OW-10 |
OWASP LLM10: API Gateway Request Body Size Limits
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-68: No API Gateway REST APIs and no regional WAF Web ACLs were found in this region. There is no input-payload surface to assess for body-size limits. Resolution
Configure API Gateway request validation or an equivalent ingress control so GenAI endpoints reject oversized request bodies before they can drive excessive model consumption. |
Informational | N/A |
777788889999 |
us-east-1 |
OW-01 |
OWASP LLM01: Prompt-Input Validation Lambda
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check FS-69: Found 1 Lambda function(s) with input validation/sanitization naming patterns: aiml-security-aiml-security-mgmt-CleanupBucket. Resolution
Deploy a prompt-input validation Lambda in front of Bedrock invocations to sanitise untrusted input before it reaches the model. |
Medium | Passed |
777788889999 |
us-east-1 |
OW-11 |
OWASP LLM07: System Prompt Embedded in Lambda Env Var
|
Medium | Passed |
777788889999 |
us-east-1 |
OW-12 |
OWASP LLM07: System-Prompt-Disclosure Denied Topic
Details and remediationDetails
Could not inspect 1 of 1 Bedrock guardrail(s) in us-east-1 for system-prompt-disclosure DENY topics. Readable guardrails inspected: 0. Sample unreadable guardrails: jkceg2tprvwh (AccessDeniedException). Resolution
Grant bedrock:GetGuardrail for the listed guardrails or resolve the read errors, then rerun the assessment. Do not treat this as proof that a DENY topic is absent. |
Informational | N/A |
777788889999 |
Global |
AC-02 |
AgentCore IAM Wildcard Permissions
|
High | Failed |
777788889999 |
Global |
AC-03 |
AgentCore Unused Permissions
Details and remediationDetails
The following principals have AgentCore permissions but have never accessed the service: role 'aiml-sec-test-resources-AgentCoreOverlyPermissiveRo-IQso7VQN0jOV', role 'AIMLSecurityMemberRole', role 'CloudSeerTrustedServiceRole' Resolution
Review and remove unused AgentCore permissions following least privilege principle |
Informational | N/A |
777788889999 |
Global |
AC-09 |
AgentCore Service-Linked Role Missing
Details and remediationDetails
Service-linked role 'AWSServiceRoleForBedrockAgentCoreNetwork' does not exist. VPC configuration for AgentCore Runtimes will fail without this role. Resolution
The service-linked role is automatically created when you configure VPC for an AgentCore Runtime. Ensure IAM permissions allow service-linked role creation. |
Medium | Failed |
777788889999 |
us-east-1 |
AC-01 |
AgentCore VPC Configuration Check
|
Informational | N/A |
777788889999 |
us-east-1 |
AC-04 |
AgentCore Observability Check
|
Informational | N/A |
777788889999 |
us-east-1 |
AC-05 |
AgentCore ECR Repository AWS-Managed Keys
|
Low | Failed |
777788889999 |
us-east-1 |
AC-06 |
AgentCore Browser Tool Recording Check
|
Informational | N/A |
777788889999 |
us-east-1 |
AC-07 |
AgentCore Memory Configuration Check
|
Informational | N/A |
777788889999 |
us-east-1 |
AC-13 |
AgentCore Gateway Configuration Check
|
Informational | N/A |
777788889999 |
us-east-1 |
AC-08 |
AgentCore VPC Endpoints Check
|
Informational | N/A |
777788889999 |
us-east-1 |
AC-10 |
AgentCore Resource-Based Policies Check
|
Informational | N/A |
777788889999 |
us-east-1 |
AC-11 |
AgentCore Policy Engine Encryption Check
|
Informational | N/A |
777788889999 |
us-east-1 |
AC-12 |
AgentCore Gateway Encryption Check
|
Informational | N/A |
777788889999 |
us-east-1 |
AG-24 |
Agentic AI Gateway Inbound Authorization
|
Informational | N/A |
777788889999 |
us-east-1 |
AG-25 |
Agentic AI Gateway Tool Policy Enforcement
|
Informational | N/A |
777788889999 |
us-east-1 |
AG-26 |
Agentic AI Gateway Error Detail Exposure
|
Informational | N/A |
777788889999 |
us-east-1 |
AG-27 |
Agentic AI Gateway WAF Protection
|
Informational | N/A |
777788889999 |
Global |
AG-16 |
Agentic AI AgentCore Least Privilege
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Over-permissive AgentCore principals can let agents or operators bypass intended autonomy and tool boundaries. Source check AC-02: The following roles have wildcard AgentCore permissions on all resources: aiml-sec-test-resources-AgentCoreOverlyPermissiveRo-IQso7VQN0jOV Resolution
Replace full-access AgentCore permissions with least-privilege IAM policies scoped to required resources and actions. |
High | Failed |
777788889999 |
Global |
AG-17 |
Agentic AI Stale AgentCore Access
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Unused AgentCore permissions increase the blast radius of compromised principals. Source check AC-03: The following principals have AgentCore permissions but have never accessed the service: role 'aiml-sec-test-resources-AgentCoreOverlyPermissiveRo-IQso7VQN0jOV', role 'AIMLSecurityMemberRole', role 'CloudSeerTrustedServiceRole' Resolution
Remove or restrict stale AgentCore permissions for principals that no longer need access. |
Informational | N/A |
777788889999 |
us-east-1 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
Informational | N/A |
777788889999 |
us-east-1 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Informational | N/A |
777788889999 |
us-east-1 |
AG-19 |
Agentic AI Memory Data Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found Resolution
Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions. |
Informational | N/A |
777788889999 |
us-east-1 |
AG-20 |
Agentic AI Private AgentCore Connectivity
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found Resolution
Create required VPC endpoints for AgentCore services and validate endpoint availability. |
Informational | N/A |
777788889999 |
us-east-1 |
AG-21 |
Agentic AI Resource Policy Boundary
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies Resolution
Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources. |
Informational | N/A |
777788889999 |
us-east-1 |
AG-22 |
Agentic AI Policy Engine Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found Resolution
Configure policy engines with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
777788889999 |
us-east-1 |
AG-23 |
Agentic AI Gateway Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found Resolution
Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
777788889999 |
us-west-2 |
BR-02 |
Amazon Bedrock private connectivity check
|
Informational | N/A |
777788889999 |
us-west-2 |
BR-04 |
Bedrock Model Invocation Logging Check
|
Informational | N/A |
777788889999 |
us-west-2 |
BR-05 |
Bedrock Guardrails Check
|
Informational | N/A |
777788889999 |
us-west-2 |
BR-06 |
Bedrock CloudTrail Logging Check
|
Informational | N/A |
777788889999 |
us-west-2 |
BR-07 |
Bedrock Prompt Management Check
Details and remediationDetails
Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates |
Informational | N/A |
777788889999 |
us-west-2 |
BR-08 |
Bedrock Agent IAM Roles Check
|
Informational | N/A |
777788889999 |
us-west-2 |
BR-09 |
Bedrock Knowledge Base Encryption Check
|
Informational | N/A |
777788889999 |
us-west-2 |
BR-10 |
Bedrock Guardrail IAM Enforcement Check
|
Informational | N/A |
777788889999 |
us-west-2 |
BR-11 |
Bedrock Custom Model Encryption Check
|
Informational | N/A |
777788889999 |
us-west-2 |
BR-12 |
Bedrock Invocation Log Encryption Check
|
Informational | N/A |
777788889999 |
us-west-2 |
BR-13 |
Bedrock Flows Guardrails Check
|
Informational | N/A |
777788889999 |
us-west-2 |
BR-16 |
Guardrail Tier Validation Check
|
Medium | N/A |
777788889999 |
us-west-2 |
BR-17 |
Custom Model Customer-Managed KMS Encryption Check
|
High | N/A |
777788889999 |
us-west-2 |
BR-18 |
Model Evaluation Implementation Check
|
Informational | N/A |
777788889999 |
us-west-2 |
BR-19 |
Prompt Flow Validation Check
|
Medium | N/A |
777788889999 |
us-west-2 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Check
|
High | N/A |
777788889999 |
us-west-2 |
BR-21 |
Agent Action Group IAM Least Privilege Check
|
High | N/A |
777788889999 |
us-west-2 |
BR-22 |
Model Invocation Throttling Limits Check
|
Informational | N/A |
777788889999 |
us-west-2 |
BR-23 |
Guardrail Content Filter Coverage Check
|
High | N/A |
777788889999 |
us-west-2 |
BR-24 |
Automated Reasoning Policy Implementation Check
|
Medium | N/A |
777788889999 |
us-west-2 |
BR-25 |
RAG Evaluation Jobs Check
|
Low | N/A |
777788889999 |
us-west-2 |
BR-26 |
Guardrail Sensitive Information Filter Check
|
High | N/A |
777788889999 |
us-west-2 |
BR-27 |
Guardrail Contextual Grounding Check
|
Medium | N/A |
777788889999 |
us-west-2 |
BR-28 |
Agent Guardrail Association Check
|
High | N/A |
777788889999 |
us-west-2 |
BR-29 |
Agent Idle Session TTL Check
|
Low | N/A |
777788889999 |
us-west-2 |
BR-30 |
Imported Model Customer-Managed KMS Encryption Check
|
High | N/A |
777788889999 |
us-west-2 |
BR-31 |
Batch Inference Output Encryption Check
|
Medium | N/A |
777788889999 |
us-west-2 |
BR-32 |
Bedrock CloudWatch Alarm Check
|
Informational | N/A |
777788889999 |
us-west-2 |
BR-33 |
Amazon Inspector Lambda Code Scanning Check
Details and remediationDetails
No Lambda functions with Bedrock indicators were found in us-west-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
No action required. If Bedrock-calling Lambda functions exist, ensure their function name, ARN, description, handler, role, or environment variables contain a Bedrock identifier that the assessment can detect, or evaluate Inspector coverage manually. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-07 |
Agentic AI Model Invocation Logging
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-08 |
Agentic AI API Audit Trail
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage Resolution
Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-10 |
Agentic AI Adversarial Evaluation Coverage
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs Resolution
Configure model or application evaluations that include adversarial, safety, and security-relevant test cases. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-11 |
Agentic AI Prompt Flow Validation
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region Resolution
Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-06 |
Agentic AI Tool Execution Least Privilege
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region Resolution
Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-12 |
Agentic AI Invocation Abuse Controls
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas Resolution
Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-02 |
Agentic AI Harmful Content Guardrail Coverage
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-04 |
Agentic AI Automated Reasoning Guardrails
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: No Bedrock guardrails configured in this region Resolution
Configure automated reasoning policies on guardrails where formal response validation is required. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-03 |
Agentic AI Sensitive Information Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: No Bedrock guardrails configured in this region Resolution
Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-05 |
Agentic AI Grounding Controls
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: No Bedrock guardrails configured in this region Resolution
Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-01 |
Agentic AI Agent Guardrail Association
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region Resolution
Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-13 |
Agentic AI Session Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region Resolution
Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-14 |
Agentic AI Operational Abuse Alarms
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms Resolution
Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available. |
Informational | N/A |
777788889999 |
us-east-2 |
BR-02 |
Amazon Bedrock private connectivity check
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-04 |
Bedrock Model Invocation Logging Check
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-05 |
Bedrock Guardrails Check
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-06 |
Bedrock CloudTrail Logging Check
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-07 |
Bedrock Prompt Management Check
Details and remediationDetails
Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates |
Informational | N/A |
777788889999 |
us-east-2 |
BR-08 |
Bedrock Agent IAM Roles Check
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-09 |
Bedrock Knowledge Base Encryption Check
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-10 |
Bedrock Guardrail IAM Enforcement Check
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-11 |
Bedrock Custom Model Encryption Check
|
Low | N/A |
777788889999 |
us-east-2 |
BR-12 |
Bedrock Invocation Log Encryption Check
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-13 |
Bedrock Flows Guardrails Check
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-16 |
Guardrail Tier Validation Check
|
Medium | N/A |
777788889999 |
us-east-2 |
BR-17 |
Custom Model Customer-Managed KMS Encryption Check
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-18 |
Model Evaluation Implementation Check
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-19 |
Prompt Flow Validation Check
|
Medium | N/A |
777788889999 |
us-east-2 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Check
|
High | N/A |
777788889999 |
us-east-2 |
BR-21 |
Agent Action Group IAM Least Privilege Check
|
High | N/A |
777788889999 |
us-east-2 |
BR-22 |
Model Invocation Throttling Limits Check
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-23 |
Guardrail Content Filter Coverage Check
|
High | N/A |
777788889999 |
us-east-2 |
BR-24 |
Automated Reasoning Policy Implementation Check
|
Medium | N/A |
777788889999 |
us-east-2 |
BR-25 |
RAG Evaluation Jobs Check
|
Low | N/A |
777788889999 |
us-east-2 |
BR-26 |
Guardrail Sensitive Information Filter Check
|
High | N/A |
777788889999 |
us-east-2 |
BR-27 |
Guardrail Contextual Grounding Check
|
Medium | N/A |
777788889999 |
us-east-2 |
BR-28 |
Agent Guardrail Association Check
|
High | N/A |
777788889999 |
us-east-2 |
BR-29 |
Agent Idle Session TTL Check
|
Low | N/A |
777788889999 |
us-east-2 |
BR-30 |
Imported Model Customer-Managed KMS Encryption Check
|
High | N/A |
777788889999 |
us-east-2 |
BR-31 |
Batch Inference Output Encryption Check
|
Medium | N/A |
777788889999 |
us-east-2 |
BR-32 |
Bedrock CloudWatch Alarm Check
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-33 |
Amazon Inspector Lambda Code Scanning Check
Details and remediationDetails
No Lambda functions with Bedrock indicators were found in us-east-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
No action required. If Bedrock-calling Lambda functions exist, ensure their function name, ARN, description, handler, role, or environment variables contain a Bedrock identifier that the assessment can detect, or evaluate Inspector coverage manually. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-07 |
Agentic AI Model Invocation Logging
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-08 |
Agentic AI API Audit Trail
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage Resolution
Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-10 |
Agentic AI Adversarial Evaluation Coverage
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs Resolution
Configure model or application evaluations that include adversarial, safety, and security-relevant test cases. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-11 |
Agentic AI Prompt Flow Validation
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region Resolution
Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-06 |
Agentic AI Tool Execution Least Privilege
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region Resolution
Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-12 |
Agentic AI Invocation Abuse Controls
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas Resolution
Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-02 |
Agentic AI Harmful Content Guardrail Coverage
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-04 |
Agentic AI Automated Reasoning Guardrails
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: No Bedrock guardrails configured in this region Resolution
Configure automated reasoning policies on guardrails where formal response validation is required. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-03 |
Agentic AI Sensitive Information Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: No Bedrock guardrails configured in this region Resolution
Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-05 |
Agentic AI Grounding Controls
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: No Bedrock guardrails configured in this region Resolution
Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-01 |
Agentic AI Agent Guardrail Association
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region Resolution
Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-13 |
Agentic AI Session Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region Resolution
Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-14 |
Agentic AI Operational Abuse Alarms
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms Resolution
Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available. |
Informational | N/A |
777788889999 |
us-east-2 |
AC-01 |
AgentCore VPC Configuration Check
|
Informational | N/A |
777788889999 |
us-east-2 |
AC-04 |
AgentCore Observability Check
|
Informational | N/A |
777788889999 |
us-east-2 |
AC-05 |
AgentCore Encryption Check
|
Informational | N/A |
777788889999 |
us-east-2 |
AC-06 |
AgentCore Browser Tool Recording Check
|
Informational | N/A |
777788889999 |
us-east-2 |
AC-07 |
AgentCore Memory Configuration Check
|
Informational | N/A |
777788889999 |
us-east-2 |
AC-13 |
AgentCore Gateway Configuration Check
|
Informational | N/A |
777788889999 |
us-east-2 |
AC-08 |
AgentCore VPC Endpoints Check
|
Informational | N/A |
777788889999 |
us-east-2 |
AC-10 |
AgentCore Resource-Based Policies Check
|
Informational | N/A |
777788889999 |
us-east-2 |
AC-11 |
AgentCore Policy Engine Encryption Check
|
Informational | N/A |
777788889999 |
us-east-2 |
AC-12 |
AgentCore Gateway Encryption Check
|
Informational | N/A |
777788889999 |
us-east-2 |
AG-24 |
Agentic AI Gateway Inbound Authorization
|
Informational | N/A |
777788889999 |
us-east-2 |
AG-25 |
Agentic AI Gateway Tool Policy Enforcement
|
Informational | N/A |
777788889999 |
us-east-2 |
AG-26 |
Agentic AI Gateway Error Detail Exposure
|
Informational | N/A |
777788889999 |
us-east-2 |
AG-27 |
Agentic AI Gateway WAF Protection
|
Informational | N/A |
777788889999 |
us-east-2 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-19 |
Agentic AI Memory Data Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found Resolution
Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-20 |
Agentic AI Private AgentCore Connectivity
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found Resolution
Create required VPC endpoints for AgentCore services and validate endpoint availability. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-21 |
Agentic AI Resource Policy Boundary
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies Resolution
Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-22 |
Agentic AI Policy Engine Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found Resolution
Configure policy engines with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-23 |
Agentic AI Gateway Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found Resolution
Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
777788889999 |
us-west-2 |
OW-01 |
OWASP LLM01: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis. |
Informational | N/A |
777788889999 |
us-west-2 |
OW-07 |
OWASP LLM07: Model Invocation Logging
Details and remediation |
Informational | N/A |
777788889999 |
us-west-2 |
OW-07 |
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident. |
Informational | N/A |
777788889999 |
us-west-2 |
OW-07 |
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-09 |
OWASP LLM09: Model Evaluation Jobs
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-06 |
OWASP LLM06: Agent Action-Group Least Privilege
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-10 |
OWASP LLM10: Service Quota Throttling Limits
Details and remediation |
Informational | N/A |
777788889999 |
us-west-2 |
OW-01 |
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier. |
Informational | N/A |
777788889999 |
us-west-2 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-02 |
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation |
Informational | N/A |
777788889999 |
us-west-2 |
OW-01 |
OWASP LLM01: Contextual Grounding Guardrail
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-04 |
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation |
Informational | N/A |
777788889999 |
us-west-2 |
OW-09 |
OWASP LLM09: Contextual Grounding for Faithfulness
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-06 |
OWASP LLM06: Bedrock Agent Guardrail Association
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-06 |
OWASP LLM06: Agent Idle Session TTL
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-03 |
OWASP LLM03: Imported-Model KMS Provenance
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-10 |
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation |
Informational | N/A |
777788889999 |
us-west-2 |
OW-03 |
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check BR-33: No Lambda functions with Bedrock indicators were found in us-west-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain. |
Informational | N/A |
777788889999 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker Internet Exposure
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-01: No SageMaker notebook instances or domains found to check Resolution
Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths. |
Informational | N/A |
777788889999 |
us-west-2 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: No SageMaker resources found to check for data protection Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
Informational | N/A |
777788889999 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Clarify Evaluation
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation |
Informational | N/A |
777788889999 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Model Monitor Coverage
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker Notebook VPC Deployment
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker Model Network Isolation
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-10 |
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation |
Informational | N/A |
777788889999 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker Container Repository Access
Details and remediation |
Informational | N/A |
777788889999 |
us-west-2 |
OW-02 |
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation |
Informational | N/A |
777788889999 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker AutoML Network Isolation
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically. |
Informational | N/A |
777788889999 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release. |
Informational | N/A |
777788889999 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
777788889999 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
777788889999 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain. |
Informational | N/A |
777788889999 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated. |
Informational | N/A |
777788889999 |
us-west-2 |
OW-06 |
OWASP LLM06: AgentCore Resource-Based Policies
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-11 |
OWASP LLM07: System Prompt Embedded in Lambda Env Var
|
Medium | Passed |
777788889999 |
us-west-2 |
OW-12 |
OWASP LLM07: System-Prompt-Disclosure Denied Topic
|
Informational | N/A |
777788889999 |
eu-west-1 |
OW-01 |
OWASP LLM01: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis. |
Informational | N/A |
777788889999 |
eu-west-1 |
OW-07 |
OWASP LLM07: Model Invocation Logging
Details and remediation |
Informational | N/A |
777788889999 |
eu-west-1 |
OW-07 |
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident. |
Informational | N/A |
777788889999 |
eu-west-1 |
OW-07 |
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
|
Informational | N/A |
777788889999 |
eu-west-1 |
OW-09 |
OWASP LLM09: Model Evaluation Jobs
|
Informational | N/A |
777788889999 |
eu-west-1 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
|
Informational | N/A |
777788889999 |
eu-west-1 |
OW-06 |
OWASP LLM06: Agent Action-Group Least Privilege
|
Informational | N/A |
777788889999 |
eu-west-1 |
OW-10 |
OWASP LLM10: Service Quota Throttling Limits
Details and remediation |
Informational | N/A |
777788889999 |
eu-west-1 |
OW-01 |
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier. |
Informational | N/A |
777788889999 |
eu-west-1 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
|
Informational | N/A |
777788889999 |
eu-west-1 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
|
Informational | N/A |
777788889999 |
eu-west-1 |
OW-02 |
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation |
Informational | N/A |
777788889999 |
eu-west-1 |
OW-01 |
OWASP LLM01: Contextual Grounding Guardrail
|
Informational | N/A |
777788889999 |
eu-west-1 |
OW-04 |
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation |
Informational | N/A |
777788889999 |
eu-west-1 |
OW-09 |
OWASP LLM09: Contextual Grounding for Faithfulness
|
Informational | N/A |
777788889999 |
eu-west-1 |
OW-06 |
OWASP LLM06: Bedrock Agent Guardrail Association
|
Informational | N/A |
777788889999 |
eu-west-1 |
OW-06 |
OWASP LLM06: Agent Idle Session TTL
|
Informational | N/A |
777788889999 |
eu-west-1 |
OW-03 |
OWASP LLM03: Imported-Model KMS Provenance
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check BR-30: Unable to check Imported model encryption check: An error occurred (AccessDeniedException) when calling the ListImportedModels operation: Your account is not authorized to invoke this API operation. Resolution
Encrypt imported Bedrock models with a customer-managed KMS key to preserve provenance and access control across model artefacts. |
Informational | N/A |
777788889999 |
eu-west-1 |
OW-10 |
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation |
Informational | N/A |
777788889999 |
eu-west-1 |
OW-03 |
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check BR-33: No Lambda functions with Bedrock indicators were found in eu-west-1; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain. |
Informational | N/A |
777788889999 |
eu-west-1 |
OW-03 |
OWASP LLM03: SageMaker Internet Exposure
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-01: No SageMaker notebook instances or domains found to check Resolution
Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths. |
Informational | N/A |
777788889999 |
eu-west-1 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: No SageMaker resources found to check for data protection Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
Informational | N/A |
777788889999 |
eu-west-1 |
OW-09 |
OWASP LLM09: SageMaker Clarify Evaluation
|
Informational | N/A |
777788889999 |
eu-west-1 |
OW-04 |
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation |
Informational | N/A |
777788889999 |
eu-west-1 |
OW-09 |
OWASP LLM09: SageMaker Model Monitor Coverage
|
Informational | N/A |
777788889999 |
eu-west-1 |
OW-03 |
OWASP LLM03: SageMaker Notebook VPC Deployment
|
Informational | N/A |
777788889999 |
eu-west-1 |
OW-03 |
OWASP LLM03: SageMaker Model Network Isolation
|
Informational | N/A |
777788889999 |
eu-west-1 |
OW-10 |
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation |
Informational | N/A |
777788889999 |
eu-west-1 |
OW-03 |
OWASP LLM03: SageMaker Container Repository Access
Details and remediation |
Informational | N/A |
777788889999 |
eu-west-1 |
OW-02 |
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation |
Informational | N/A |
777788889999 |
eu-west-1 |
OW-03 |
OWASP LLM03: SageMaker AutoML Network Isolation
|
Informational | N/A |
777788889999 |
eu-west-1 |
OW-04 |
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically. |
Informational | N/A |
777788889999 |
eu-west-1 |
OW-09 |
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release. |
Informational | N/A |
777788889999 |
eu-west-1 |
OW-04 |
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
777788889999 |
eu-west-1 |
OW-09 |
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
777788889999 |
eu-west-1 |
OW-03 |
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain. |
Informational | N/A |
777788889999 |
eu-west-1 |
OW-04 |
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated. |
Informational | N/A |
777788889999 |
eu-west-1 |
OW-06 |
OWASP LLM06: AgentCore Resource-Based Policies
|
Informational | N/A |
777788889999 |
eu-west-1 |
OW-11 |
OWASP LLM07: System Prompt Embedded in Lambda Env Var
|
Medium | Passed |
777788889999 |
eu-west-1 |
OW-12 |
OWASP LLM07: System-Prompt-Disclosure Denied Topic
|
Informational | N/A |
777788889999 |
us-west-2 |
AC-01 |
AgentCore VPC Configuration Check
|
Informational | N/A |
777788889999 |
us-west-2 |
AC-04 |
AgentCore Observability Check
|
Informational | N/A |
777788889999 |
us-west-2 |
AC-05 |
AgentCore Encryption Check
|
Informational | N/A |
777788889999 |
us-west-2 |
AC-06 |
AgentCore Browser Tool Recording Check
|
Informational | N/A |
777788889999 |
us-west-2 |
AC-07 |
AgentCore Memory Configuration Check
|
Informational | N/A |
777788889999 |
us-west-2 |
AC-13 |
AgentCore Gateway Configuration Check
|
Informational | N/A |
777788889999 |
us-west-2 |
AC-08 |
AgentCore VPC Endpoints Check
|
Informational | N/A |
777788889999 |
us-west-2 |
AC-10 |
AgentCore Resource-Based Policies Check
|
Informational | N/A |
777788889999 |
us-west-2 |
AC-11 |
AgentCore Policy Engine Encryption Check
|
Informational | N/A |
777788889999 |
us-west-2 |
AC-12 |
AgentCore Gateway Encryption Check
|
Informational | N/A |
777788889999 |
us-west-2 |
AG-24 |
Agentic AI Gateway Inbound Authorization
|
Informational | N/A |
777788889999 |
us-west-2 |
AG-25 |
Agentic AI Gateway Tool Policy Enforcement
|
Informational | N/A |
777788889999 |
us-west-2 |
AG-26 |
Agentic AI Gateway Error Detail Exposure
|
Informational | N/A |
777788889999 |
us-west-2 |
AG-27 |
Agentic AI Gateway WAF Protection
|
Informational | N/A |
777788889999 |
us-west-2 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-19 |
Agentic AI Memory Data Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found Resolution
Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-20 |
Agentic AI Private AgentCore Connectivity
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found Resolution
Create required VPC endpoints for AgentCore services and validate endpoint availability. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-21 |
Agentic AI Resource Policy Boundary
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies Resolution
Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-22 |
Agentic AI Policy Engine Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found Resolution
Configure policy engines with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-23 |
Agentic AI Gateway Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found Resolution
Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
777788889999 |
us-east-1 |
FS-01 |
AWS Shield Advanced Not Enabled
Details and remediationDetails
AWS Shield Advanced is not subscribed. GenAI API endpoints are vulnerable to volumetric DDoS attacks that can exhaust token quotas and inflate costs. Resolution
1. Subscribe to AWS Shield Advanced for DDoS protection. 2. After subscribing, explicitly add resource protections in the Shield Advanced console for each Bedrock-facing resource (API Gateway stages, ALBs, CloudFront distributions, Route 53 hosted zones). Shield Advanced subscription alone does NOT automatically protect resources — each resource must be individually added to receive protection. 3. Enable Shield Response Team (SRT) access and configure proactive engagement. 4. Alternatively, use AWS Firewall Manager with a Shield Advanced policy to automate resource protection based on tags or resource types. |
Low | Failed |
777788889999 |
us-east-1 |
FS-01 |
No Regional WAF Web ACLs Found
Details and remediationDetails
No AWS WAF regional Web ACLs found. Without WAF, GenAI endpoints lack rate-based rules to block abusive callers. Resolution
1. Create a WAF Web ACL with rate-based rules (e.g., 1000 req/5 min per IP). 2. Associate the ACL with API Gateway stages or ALBs fronting Bedrock. 3. Add AWS Managed Rules for known bad inputs. |
Medium | Failed |
777788889999 |
us-east-1 |
FS-02 |
No API Gateway Usage Plans Found
|
Informational | N/A |
777788889999 |
us-east-1 |
FS-03 |
Bedrock Token Quotas Customized
|
Medium | Passed |
777788889999 |
us-east-1 |
FS-04 |
No Cost Anomaly Detection Monitors
Details and remediationDetails
No AWS Cost Anomaly Detection monitors found. Unexpected spikes in Bedrock/SageMaker usage (e.g., from prompt injection loops) will go undetected. Resolution
1. Create a Cost Anomaly Detection monitor scoped to AWS/Bedrock and AWS/SageMaker. 2. Configure alert subscriptions (SNS/email) for anomalies above threshold. 3. Set daily spend budgets with AWS Budgets as a secondary control. |
Medium | Failed |
777788889999 |
us-east-1 |
FS-05 |
No Bedrock CloudWatch Alarms Found
Details and remediationDetails
No CloudWatch alarms found for Bedrock metrics. Token exhaustion and throttling events will not trigger operational alerts. Resolution
Create CloudWatch alarms for: - AWS/Bedrock InvocationThrottles (threshold > 0) - AWS/Bedrock TokensProcessed (threshold based on quota) - Custom application-level token counters via EMF |
Medium | Failed |
777788889999 |
us-east-1 |
FS-06 |
No AI/ML Service Budgets Configured
Details and remediationDetails
No AWS Budgets found scoped to Bedrock or SageMaker. Unbounded GenAI spend can go undetected until the monthly bill. Resolution
1. Create cost budgets for AWS Bedrock and SageMaker with 80%/100% alert thresholds. 2. Add SNS notifications to on-call channels. 3. Consider budget actions to apply IAM deny policies when thresholds are breached. |
Medium | Failed |
777788889999 |
us-east-1 |
FS-07 |
Agent Action Boundaries Look Appropriate
|
High | Passed |
777788889999 |
us-east-1 |
FS-08 |
No AgentCore Runtimes Found
|
Informational | N/A |
777788889999 |
us-east-1 |
FS-09 |
Agent Lambda Functions Without Concurrency Limits
Details and remediationDetails
Agent-related Lambda functions without reserved concurrency: aiml-security-aiml-security-mgmt-FinServAssessment, aiml-sec-test-resources-SageMakerJobCustomResource-ZA5QCAi0pN3d, AIMLSecurityAssessment-CodeBuildStartBuildLambda-VYOqtzWoNo3m, aiml-security-aiml-security-mgmt-CleanupBucket, aiml-security-aiml-security-mgmt-SagemakerAssessment, aiml-security-aiml-security-mgmt-GenerateReport, aiml-security-aiml-security-mgmt-OWASPAssessment, aiml-security-aiml-security-mgmt-IAMPermissionCaching, aiml-security-aiml-security-mgmt-AgentCoreAssessment, aiml-security-aiml-security-mgmt-BedrockAssessment. Unlimited concurrency allows runaway agent loops to exhaust account limits. Resolution
1. Set reserved concurrency on agent Lambda functions. 2. Implement maximum iteration counts in agent orchestration logic. 3. Use Step Functions with MaxConcurrency and timeout states. 4. Add circuit-breaker patterns to agent tool invocations. |
Medium | Failed |
777788889999 |
us-east-1 |
FS-10 |
Human-in-the-Loop Check — No Agent Workflows Found
Details and remediationDetails
No Step Functions state machines with agent/approval naming found. Verify that high-risk agent actions (e.g., fund transfers, account changes) have human approval gates. Resolution
Implement Step Functions .waitForTaskToken patterns for high-risk agent actions. Route approval requests to human reviewers via SNS/SES/Slack. |
Informational | N/A |
777788889999 |
us-east-1 |
FS-11 |
No Agent Rate Alarms Found
Details and remediationDetails
No CloudWatch alarms found for agent invocation rates. Looping or runaway agents will not trigger operational alerts. Resolution
Create CloudWatch alarms on: - Bedrock agent invocation counts (threshold based on expected max) - Lambda invocation errors for agent functions - Step Functions execution failures and timeouts |
Medium | Failed |
777788889999 |
us-east-1 |
FS-12 |
No Bedrock-Scoped SCPs Found
Details and remediationDetails
No Service Control Policies reference Bedrock. Without SCPs, any account in the organization can access any Bedrock model, including unapproved third-party models. Resolution
1. Create an SCP that denies bedrock:InvokeModel for model IDs not on the approved list. 2. Use bedrock:ModelId condition key to allowlist approved models. 3. Maintain a model inventory and update the SCP when models are approved/retired. |
High | Failed |
777788889999 |
us-east-1 |
FS-13 |
Models Missing Provenance Tags
Details and remediationDetails
2 model(s) missing required provenance tags: - SageMaker model 'SageMakerModelWithIsolation-JASFpUHjajdk' missing tags: {'approval-date', 'source', 'version'} - SageMaker model 'SageMakerModelNoIsolation-yQ7EpJeL7pgI' missing tags: {'approval-date', 'source', 'version'} Resolution
Tag all models with: source (e.g., 'aws-marketplace', 'internal'), version, and approval-date. Enforce tagging via SCP or AWS Config rule. |
Medium | Failed |
777788889999 |
us-east-1 |
FS-14 |
Model Governance Config Rules Present
|
Medium | Passed |
777788889999 |
us-east-1 |
FS-15 |
No Bedrock Evaluation Jobs Found
Details and remediationDetails
No Bedrock Model Evaluation jobs found. Models have not been evaluated for adversarial robustness. FinServ model-risk management (SR 11-7) expects documented model validation/evaluation. Resolution
1. Run Bedrock Model Evaluation with adversarial/red-team datasets. 2. Use FMEval library for automated robustness testing. 3. Schedule periodic re-evaluation after model updates. |
Medium | Failed |
777788889999 |
us-east-1 |
FS-16 |
ECR Repositories Without Image Scanning
Details and remediation |
High | Failed |
777788889999 |
us-east-1 |
FS-20 |
Feature Groups Without Offline Store
Details and remediationDetails
1 feature group(s) lack an active offline store: aiml-sec-test-feature-group. Without offline store, historical feature data cannot be used for rollback. Resolution
1. Enable offline store (S3-backed) for all production feature groups. 2. Enable S3 versioning on the offline store bucket. 3. Document rollback procedures for poisoned feature data. |
Medium | Failed |
777788889999 |
us-east-1 |
FS-21 |
Training Data Buckets Have Versioning
|
High | Passed |
777788889999 |
us-east-1 |
FS-22 |
Overly Permissive Knowledge Base IAM Roles
Details and remediationDetails
825 role(s) with wildcard KB permissions: - Role 'Admin' allows '*' - Role 'aiml-sec-test-resources-BedrockAgentRole-RScmoTZfp2sC' allows 'bedrock:InvokeModel' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-test-resources-BedrockAgentRole-RScmoTZfp2sC' allows 'bedrock:InvokeModelWithResponseStream' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-test-resources-BedrockAgentRoleWithoutGuar-Z3kN5ANhP89G' allows 'bedrock:InvokeModel' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-test-resources-BedrockAgentRoleWithoutGuar-Z3kN5ANhP89G' allows 'bedrock:InvokeModelWithResponseStream' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-test-resources-BedrockFullAccessRole-zAFkGLkWQ61a' allows 'bedrock:*' - Role 'aiml-security-mgmt-BedrockSecurityAssessmentFunctio-a7GKJ6O4151K' allows 'bedrock:ListGuardrails' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-mgmt-BedrockSecurityAssessmentFunctio-a7GKJ6O4151K' allows 'bedrock:GetGuardrail' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-mgmt-BedrockSecurityAssessmentFunctio-a7GKJ6O4151K' allows 'bedrock:ListModelInvocationJobs' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-mgmt-BedrockSecurityAssessmentFunctio-a7GKJ6O4151K' allows 'bedrock:GetModelInvocationLoggingConfiguration' on Resource '*' (no ARN scoping to specific Knowledge Bases) Resolution
Replace wildcard bedrock:* with specific actions such as bedrock:Retrieve, bedrock:RetrieveAndGenerate. Scope resources to specific Knowledge Base ARNs. |
High | Failed |
777788889999 |
us-east-1 |
FS-24 |
ADVISORY: Knowledge Base Metadata Filtering — Manual Review Required
Details and remediationDetails
Found 1 Knowledge Base(s). Tenant-isolation metadata filtering is a design pattern that cannot be verified via API — manual review required. Verify that metadata attributes (e.g., tenantId, classification) are indexed and that Retrieve calls include RetrievalFilter conditions for tenant isolation. Resolution
1. Add metadata fields (tenantId, dataClassification) to KB data sources. 2. Pass RetrievalFilter in all Retrieve/RetrieveAndGenerate calls. 3. Validate filters in integration tests to prevent cross-tenant data leakage. |
Informational | N/A |
777788889999 |
us-east-1 |
FS-25 |
OpenSearch Serverless Encryption Policies Present
|
High | Passed |
777788889999 |
us-east-1 |
FS-26 |
OpenSearch Serverless Collections Not VPC-Restricted
|
High | Failed |
777788889999 |
us-east-1 |
FS-27 |
COULD NOT ASSESS: Guardrail Contextual Grounding Check
Details and remediationDetails
This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved. Resolution
1. Confirm the assessment role grants the actions this check requires (see the documented IAM permission set in the README). 2. Confirm the service/feature is supported in the assessed region. 3. Ensure botocore meets the version floor in requirements.txt. 4. Re-run the assessment; assess this control manually until it succeeds. |
Low | N/A |
777788889999 |
us-east-1 |
FS-27 |
No Automated Reasoning Policies Found
Details and remediationDetails
No Bedrock Automated Reasoning policies have been created. ARC (GA August 2025) uses formal verification to guarantee that GenAI outputs comply with authored business rules — e.g., loan criteria, regulatory thresholds, policy constraints. Without ARC policies, factual accuracy of outputs is not formally verified, only heuristically filtered by contextual grounding thresholds. Resolution
1. In the Amazon Bedrock console → Guardrails → Automated Reasoning, create a policy document encoding your FinServ business rules (e.g., eligibility criteria, rate limits, regulatory thresholds). 2. Associate the ARC policy with your guardrail (automatedReasoningPolicy.policies field in CreateGuardrail/UpdateGuardrail). 3. Set confidenceThreshold on the policy to control strictness. 4. ARC requires cross-Region inference — ensure your guardrail has a guardrailProfileArn configured (crossRegionDetails in GetGuardrail response). 5. Reference: AWS Announcement — Automated Reasoning checks GA (August 2025). |
Medium | Failed |
777788889999 |
us-east-1 |
FS-28 |
COULD NOT ASSESS: Financial Denied Topics Check
Details and remediationDetails
This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved. Resolution
1. Confirm the assessment role grants the actions this check requires (see the documented IAM permission set in the README). 2. Confirm the service/feature is supported in the assessed region. 3. Ensure botocore meets the version floor in requirements.txt. 4. Re-run the assessment; assess this control manually until it succeeds. |
Low | N/A |
777788889999 |
us-east-1 |
FS-29 |
ADVISORY: Compliance Disclaimer — Manual Review Required
Details and remediationDetails
Application-level compliance disclaimers cannot be verified via AWS APIs. Manual review required to confirm GenAI outputs include required regulatory disclosures. Resolution
1. Implement post-processing to append required disclaimers to GenAI outputs. 2. Use Bedrock Guardrails word filters to block outputs that omit required disclosures. 3. Document disclaimer requirements in the AI use case register. 4. Test disclaimer presence in QA/UAT before production deployment. |
Informational | N/A |
777788889999 |
us-east-1 |
FS-30 |
ADVISORY: Compliance Dataset Coverage — Manual Review Required
Details and remediationDetails
Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation jobs include compliance-specific datasets (fair lending/ECOA, Fair Housing Act, UDAP/UDAAP, AML/KYC edge cases). Whether any evaluation jobs exist at all is assessed by FS-15. Resolution
Run Bedrock Model Evaluation with compliance-specific datasets: - Fair lending test cases (ECOA, Fair Housing Act) - UDAP/UDAAP unfair/deceptive practice scenarios - AML/KYC edge cases |
Informational | N/A |
777788889999 |
us-east-1 |
FS-31 |
Knowledge Base Data Sources Past Review Threshold
Details and remediationDetails
1 data source(s) not synced in >7 days (a configurable review threshold, NOT an AWS-mandated limit): - KB 'knowledge-base-prowler-findings' source 'knowledge-base-quick-start-9lb68-data-source' last synced 432 days ago Confirm this age is acceptable for each data source's currency requirement — slow-changing reference data may legitimately sync infrequently. Resolution
1. Define the maximum acceptable data age per use case (e.g., intraday for market data, daily for product terms, weekly/monthly for regulatory guidance) and adjust the review threshold to match. 2. Configure automated sync (EventBridge Scheduler → StartIngestionJob) at that cadence — see FS-61. 3. Set CloudWatch alarms on sync job failures. |
Medium | Failed |
777788889999 |
us-east-1 |
FS-32 |
ADVISORY: Source Attribution — Manual Review Required
Details and remediationDetails
Source attribution in GenAI responses cannot be verified via AWS APIs. Manual review required to confirm responses include citations. Resolution
1. Use Bedrock RetrieveAndGenerate with citations enabled. 2. Include source document references in response post-processing. 3. Test citation accuracy in QA before production deployment. 4. Consider Bedrock Guardrails grounding checks to validate response accuracy. |
Informational | N/A |
777788889999 |
us-east-1 |
FS-33 |
KB Data Source Buckets Have Versioning
|
Medium | Passed |
777788889999 |
us-east-1 |
FS-34 |
Legacy Foundation Models Available in Region
Details and remediationDetails
Legacy/deprecated foundation models are available in this account/region: anthropic.claude-sonnet-4-20250514-v1:0, twelvelabs.marengo-embed-2-7-v1:0, anthropic.claude-opus-4-1-20250805-v1:0, amazon.nova-premier-v1:0:8k, amazon.nova-premier-v1:0:20k, amazon.nova-premier-v1:0:1000k, amazon.nova-premier-v1:0:mm, amazon.nova-premier-v1:0, amazon.nova-canvas-v1:0, amazon.nova-reel-v1:0. This API reports model *availability*, not actual usage — it cannot determine which models your applications invoke. Legacy models have older training-data cutoffs and may produce outdated information if used. Review whether any are in active use. Resolution
1. Identify which (if any) of these legacy models your applications invoke (e.g., via CloudTrail InvokeModel events or application config). 2. Migrate active usage to current model versions. 3. Document training-data cutoff dates for all models in use. 4. Add data-currency disclaimers to outputs from models with old cutoffs. |
Informational | N/A |
777788889999 |
us-east-1 |
FS-35 |
ADVISORY: Harmful-Content Test Coverage — Manual Review Required
Details and remediationDetails
Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation/FMEval jobs include harmful-content datasets (toxicity, hate speech, violence/self-harm). Whether any evaluation jobs exist at all is assessed by FS-15. Resolution
Run Bedrock Model Evaluation or FMEval with harmful content datasets: - Toxicity detection - Hate speech classification - Violence/self-harm content |
Informational | N/A |
777788889999 |
us-east-1 |
FS-36 |
COULD NOT ASSESS: Guardrail Content Filters Check
Details and remediationDetails
This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved. Resolution
1. Confirm the assessment role grants the actions this check requires (see the documented IAM permission set in the README). 2. Confirm the service/feature is supported in the assessed region. 3. Ensure botocore meets the version floor in requirements.txt. 4. Re-run the assessment; assess this control manually until it succeeds. |
Low | N/A |
777788889999 |
us-east-1 |
FS-37 |
ADVISORY: User Feedback Mechanism — Manual Review Required
Details and remediationDetails
User feedback mechanisms for harmful outputs cannot be verified via AWS APIs. Manual review required. Resolution
1. Implement thumbs-up/down or flag-for-review UI in GenAI applications. 2. Route flagged outputs to human reviewers via SQS/SNS. 3. Log feedback to DynamoDB/S3 for model improvement. 4. Define SLAs for reviewing flagged content. |
Informational | N/A |
777788889999 |
us-east-1 |
FS-38 |
COULD NOT ASSESS: Guardrail Word Filters Check
Details and remediationDetails
This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved. Resolution
1. Confirm the assessment role grants the actions this check requires (see the documented IAM permission set in the README). 2. Confirm the service/feature is supported in the assessed region. 3. Ensure botocore meets the version floor in requirements.txt. 4. Re-run the assessment; assess this control manually until it succeeds. |
Low | N/A |
777788889999 |
us-east-1 |
FS-39 |
No SageMaker Clarify Bias Monitoring
Details and remediationDetails
No SageMaker Clarify model bias monitoring schedules found. Models making financial decisions (credit, insurance) may exhibit discriminatory bias without detection. Resolution
1. Configure SageMaker Clarify bias detection for all models making credit, insurance, or employment decisions. 2. Define protected attributes (age, gender, race proxies). 3. Set bias metric thresholds and alert on violations. 4. Document bias testing results for regulatory examination. |
High | Failed |
777788889999 |
us-east-1 |
FS-40 |
ADVISORY: Bias Dataset Coverage — Manual Review Required
Details and remediationDetails
Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation jobs include bias/fairness datasets (demographic parity, equal-opportunity, counterfactual fairness) for any GenAI models used in financial decisions (ECOA/Fair Housing). Whether any evaluation jobs exist at all is assessed by FS-15. Resolution
Run Bedrock Model Evaluation with bias test datasets: - Demographic parity test cases - Equal opportunity scenarios - Counterfactual fairness tests |
Informational | N/A |
777788889999 |
us-east-1 |
FS-41 |
No SageMaker Clarify Explainability Monitoring
Details and remediationDetails
No SageMaker Clarify explainability monitoring found. Models making adverse financial decisions may not provide required explanations (ECOA adverse action notices). Resolution
1. Configure SageMaker Clarify explainability for credit/lending models. 2. Generate SHAP values for feature importance. 3. Map top features to human-readable adverse action reason codes. 4. Store explanations for regulatory examination. |
High | Failed |
777788889999 |
us-east-1 |
FS-42 |
No SageMaker Model Cards Found
Details and remediationDetails
No SageMaker Model Cards found. Production AI models lack documented intended use, limitations, and bias evaluations. Resolution
1. Create SageMaker Model Cards for all production models. 2. Document: intended use, out-of-scope uses, training data, bias evaluations. 3. Include regulatory compliance attestations. 4. Review and update cards at each model version release. |
Medium | Failed |
777788889999 |
us-east-1 |
FS-43 |
No CloudWatch Logs Data Protection Policies
Details and remediationDetails
No CloudWatch Logs data protection policies found. PII (SSN, account numbers, credit card numbers) in Bedrock invocation logs may be stored in plaintext. Resolution
1. Create CloudWatch Logs data protection policies to mask PII. 2. Enable masking for: SSN, credit card numbers, bank account numbers, email. 3. Apply policies to Bedrock invocation log groups. 4. Test masking with synthetic PII before production deployment. |
High | Failed |
777788889999 |
us-east-1 |
FS-44 |
Amazon Macie Not Enabled
Details and remediationDetails
Amazon Macie is not enabled. S3 buckets containing training data and KB data sources are not being scanned for PII/sensitive data. Resolution
1. Enable Amazon Macie in all regions where AI/ML data is stored. 2. Create Macie classification jobs for training data and KB buckets. 3. Configure Macie findings to route to Security Hub and SNS. 4. Remediate PII findings before using data for model training. |
High | Failed |
777788889999 |
us-east-1 |
FS-45 |
COULD NOT ASSESS: Guardrail PII Filters Check
Details and remediationDetails
This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved. Resolution
1. Confirm the assessment role grants the actions this check requires (see the documented IAM permission set in the README). 2. Confirm the service/feature is supported in the assessed region. 3. Ensure botocore meets the version floor in requirements.txt. 4. Re-run the assessment; assess this control manually until it succeeds. |
Low | N/A |
777788889999 |
us-east-1 |
FS-46 |
AI/ML Buckets Without Data Classification Tags
Details and remediationDetails
3 AI/ML bucket(s) without data-classification tags: aiml-sec-test-resources-bedrockloggingbucket-wtuvpinrlpmd, aiml-sec-test-resources-sagemakerbucket-6zzmxxaxco6g, aiml-security-mgmt-aimlassessmentbucket-kbitsdgexylv. Resolution
Tag all AI/ML data buckets with 'data-classification' key. Values: Public, Internal, Confidential, Restricted. Enforce via SCP or AWS Config rule. |
Medium | Failed |
777788889999 |
us-east-1 |
FS-47 |
COULD NOT ASSESS: Guardrail Grounding Threshold Check
Details and remediationDetails
This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved. Resolution
1. Confirm the assessment role grants the actions this check requires (see the documented IAM permission set in the README). 2. Confirm the service/feature is supported in the assessed region. 3. Ensure botocore meets the version floor in requirements.txt. 4. Re-run the assessment; assess this control manually until it succeeds. |
Low | N/A |
777788889999 |
us-east-1 |
FS-48 |
Active Knowledge Bases for RAG Present
|
Medium | Passed |
777788889999 |
us-east-1 |
FS-49 |
ADVISORY: Hallucination Disclaimer — Manual Review Required
Details and remediationDetails
Application-level hallucination disclaimers cannot be verified via AWS APIs. Manual review required. Resolution
1. Add disclaimers to GenAI outputs: 'AI-generated content may contain errors. Verify with authoritative sources before acting.' 2. Implement post-processing to append disclaimers. 3. Test disclaimer presence in QA before production. |
Informational | N/A |
777788889999 |
us-east-1 |
FS-50 |
COULD NOT ASSESS: Guardrail Relevance Grounding Check
Details and remediationDetails
This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved. Resolution
1. Confirm the assessment role grants the actions this check requires (see the documented IAM permission set in the README). 2. Confirm the service/feature is supported in the assessed region. 3. Ensure botocore meets the version floor in requirements.txt. 4. Re-run the assessment; assess this control manually until it succeeds. |
Low | N/A |
777788889999 |
us-east-1 |
FS-51 |
COULD NOT ASSESS: Prompt Injection Input Validation Check
Details and remediationDetails
This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved. Resolution
1. Confirm the assessment role grants the actions this check requires (see the documented IAM permission set in the README). 2. Confirm the service/feature is supported in the assessed region. 3. Ensure botocore meets the version floor in requirements.txt. 4. Re-run the assessment; assess this control manually until it succeeds. |
Low | N/A |
777788889999 |
us-east-1 |
FS-52 |
Bedrock Lambda Functions on Current Runtimes
|
Medium | Passed |
777788889999 |
us-east-1 |
FS-53 |
No WAF Web ACLs — Injection Rules Not Applicable
|
Informational | N/A |
777788889999 |
us-east-1 |
FS-54 |
ADVISORY: Penetration Testing — Manual Review Required
Details and remediationDetails
Penetration testing evidence cannot be verified via AWS APIs. Manual review required to confirm GenAI applications have been tested. Resolution
1. Conduct penetration testing of GenAI applications at least annually and before major releases. 2. Include AI-specific test cases: prompt injection, jailbreak, indirect (cross-domain) injection, system-prompt leakage, and data-extraction attempts. 3. Consider AWS Security Agent for on-demand, AI-driven penetration testing (GA March 2026; available in US East N. Virginia, US West Oregon, Europe Ireland, Europe Frankfurt, Asia Pacific Sydney, Asia Pacific Tokyo, with cross-account shared-VPC testing via AWS RAM). Open-source tools such as Garak or PyRIT and manual red-teaming are complementary options. Verify current regional availability on the AWS Security Agent page before relying on it. 4. Document findings and remediation for regulatory examination, and tag tested resources with a last-pentest-date for audit trail. 5. For DORA compliance, include GenAI in TLPT (Threat-Led Penetration Testing) scope. |
Informational | N/A |
777788889999 |
us-east-1 |
FS-55 |
No Output Validation Functions Found
Details and remediationDetails
No Lambda functions with output validation/sanitization naming found. GenAI outputs may be passed directly to downstream systems without validation. Resolution
1. Implement output validation Lambda functions in GenAI pipelines. 2. Validate output schema, length, and content before downstream use. 3. Sanitize outputs before rendering in web UIs (XSS prevention). 4. Encode outputs appropriately for the target context (HTML, SQL, JSON). |
Medium | Failed |
777788889999 |
us-east-1 |
FS-56 |
No WAF ACLs — XSS Prevention Not Applicable
|
Informational | N/A |
777788889999 |
us-east-1 |
FS-57 |
ADVISORY: Output Encoding — Manual Review Required
Details and remediationDetails
Output encoding practices cannot be verified via AWS APIs. Manual code review required. Resolution
1. HTML-encode GenAI outputs before rendering in web UIs. 2. Use parameterized queries when GenAI output is used in database operations. 3. JSON-encode outputs before embedding in JavaScript contexts. 4. Validate output length and format before passing to downstream APIs. |
Informational | N/A |
777788889999 |
us-east-1 |
FS-58 |
ADVISORY: Output Schema Validation — Manual Review Required
Details and remediationDetails
Found 0 Lambda function(s) whose names suggest schema/validation handling. Structured-output / JSON-schema validation of GenAI responses is an application-layer control that cannot be verified automatically — manual review required. Resolution
1. Use Bedrock structured output (response schemas) where supported. 2. Implement JSON schema validation on Lambda output processors. 3. Reject malformed outputs and return safe error responses. 4. Log schema validation failures to CloudWatch for monitoring. |
Informational | N/A |
777788889999 |
us-east-1 |
FS-59 |
COULD NOT ASSESS: Guardrail Topic Allowlist Check
Details and remediationDetails
This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved. Resolution
1. Confirm the assessment role grants the actions this check requires (see the documented IAM permission set in the README). 2. Confirm the service/feature is supported in the assessed region. 3. Ensure botocore meets the version floor in requirements.txt. 4. Re-run the assessment; assess this control manually until it succeeds. |
Low | N/A |
777788889999 |
us-east-1 |
FS-60 |
ADVISORY: Contextual Grounding for Off-Topic Prevention
Details and remediationDetails
Contextual grounding for off-topic prevention is covered by guardrail grounding checks (FS-47) and RAG configuration (FS-48). Additionally verify system prompts explicitly scope the assistant's role. Resolution
1. Include explicit scope instructions in system prompts. 2. Use Bedrock Guardrails relevance grounding filter. 3. Test with off-topic prompts in QA to verify rejection behavior. |
Informational | N/A |
777788889999 |
us-east-1 |
FS-61 |
No Automated KB Sync Schedules Detected
Details and remediationDetails
Found 1 Knowledge Base(s) but no EventBridge Scheduler schedules or EventBridge rules with 'bedrock'/'knowledge' naming were found. Note: this check uses a name/target heuristic — sync automation with other naming conventions, AWS Step Functions-based orchestration, or native Bedrock API-triggered syncs (StartIngestionJob called directly) will not be detected. Verify sync automation manually if applicable. Resolution
1. Use EventBridge Scheduler (the AWS-recommended approach) to create a recurring schedule (e.g., rate(1 day) or a cron expression) that triggers a Lambda function calling the Bedrock StartIngestionJob API for each data source. Classic EventBridge scheduled rules also work but are a legacy feature. 2. As of December 2024, Bedrock Knowledge Bases supports custom connectors and streaming data ingestion — use direct document ingestion (KnowledgeBaseDocuments API) for real-time updates without a full S3 sync. 3. Set sync frequency based on data currency requirements (e.g., hourly for market data, daily for regulatory guidance). 4. Configure CloudWatch alarms or SNS notifications on IngestionJob FAILED status for sync failure alerting. |
Medium | Failed |
777788889999 |
us-east-1 |
FS-62 |
ADVISORY: Data Currency Disclaimer — Manual Review Required
Details and remediationDetails
Data currency disclaimers cannot be verified via AWS APIs. Manual review required. Resolution
1. Add data currency disclaimers to GenAI outputs: 'Information based on data current as of [KB last sync date].' 2. Expose KB last sync timestamp in application responses. 3. Alert users when KB data is older than defined threshold. |
Informational | N/A |
777788889999 |
us-east-1 |
FS-63 |
Foundation Model Lifecycle Management
|
Medium | Passed |
777788889999 |
us-east-1 |
FS-65 |
KB Data Source Buckets Missing S3 Event Notifications
Details and remediationDetails
The following KB data-source S3 buckets have no event notifications configured. Unauthorized document modifications will not be detected in real time: - sat2-prowler-2025-prowlerfindingsbucket-wc1k0mza7lpk Resolution
1. Enable Amazon EventBridge notifications on each KB data-source S3 bucket. 2. Create an EventBridge rule to route s3:ObjectCreated, s3:ObjectRemoved, and s3:ObjectModified events to an SNS topic or Lambda for alerting. 3. Integrate alerts into your security incident response workflow. |
Medium | Failed |
777788889999 |
us-east-1 |
FS-66 |
No AgentCore Runtimes Found
|
Informational | N/A |
777788889999 |
us-east-1 |
FS-67 |
Agent Action-Group Lambdas May Lack Transaction Thresholds
Details and remediationDetails
The following agent action-group Lambda functions have no environment variables whose names suggest transaction-value threshold configuration (this is a best-effort heuristic — a threshold enforced in code or in an AgentCore Policy Engine rule would not be detected here, so treat this as a prompt for manual verification rather than a definitive gap). Without explicit limits, agents could initiate unbounded financial transactions: - aiml-security-aiml-security-mgmt-FinServAssessment - aiml-security-aiml-security-mgmt-AgentCoreAssessment - aiml-security-aiml-security-mgmt-BedrockAssessment Resolution
1. Add transaction-value threshold environment variables (e.g., MAX_TRANSACTION_AMOUNT) to each agent action-group Lambda. 2. Implement threshold enforcement logic in the Lambda handler. 3. Configure AgentCore Policy Engine rules to cap financial transaction amounts. 4. Route transactions exceeding thresholds to a human-in-the-loop approval step. |
High | Failed |
777788889999 |
us-east-1 |
FS-68 |
API Gateway Request Body Size Limits — Not Applicable
Details and remediationDetails
No API Gateway REST APIs and no regional WAF Web ACLs were found in this region. There is no input-payload surface to assess for body-size limits. Resolution
If GenAI endpoints are fronted by API Gateway or WAF in another region, run the assessment there. Otherwise no action is required. |
Informational | N/A |
777788889999 |
us-east-1 |
FS-69 |
Prompt Input Validation Functions Present
Details and remediation |
Medium | Passed |
777788889999 |
us-east-2 |
FS-00 |
FinServ Regional Scope Not Applicable
|
Informational | N/A |
777788889999 |
us-west-2 |
FS-00 |
FinServ Regional Scope Not Applicable
|
Informational | N/A |
777788889999 |
eu-west-1 |
FS-00 |
FinServ Regional Scope Not Applicable
|
Informational | N/A |
777788889999 |
eu-west-1 |
BR-02 |
Amazon Bedrock private connectivity check
|
Informational | N/A |
777788889999 |
eu-west-1 |
BR-04 |
Bedrock Model Invocation Logging Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
BR-05 |
Bedrock Guardrails Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
BR-06 |
Bedrock CloudTrail Logging Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
BR-07 |
Bedrock Prompt Management Check
Details and remediationDetails
Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates |
Informational | N/A |
777788889999 |
eu-west-1 |
BR-08 |
Bedrock Agent IAM Roles Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
BR-09 |
Bedrock Knowledge Base Encryption Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
BR-10 |
Bedrock Guardrail IAM Enforcement Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
BR-11 |
Bedrock Custom Model Encryption Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
BR-12 |
Bedrock Invocation Log Encryption Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
BR-13 |
Bedrock Flows Guardrails Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
BR-16 |
Guardrail Tier Validation Check
|
Medium | N/A |
777788889999 |
eu-west-1 |
BR-17 |
Custom Model Customer-Managed KMS Encryption Check
|
High | N/A |
777788889999 |
eu-west-1 |
BR-18 |
Model Evaluation Implementation Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
BR-19 |
Prompt Flow Validation Check
|
Medium | N/A |
777788889999 |
eu-west-1 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Check
|
High | N/A |
777788889999 |
eu-west-1 |
BR-21 |
Agent Action Group IAM Least Privilege Check
|
High | N/A |
777788889999 |
eu-west-1 |
BR-22 |
Model Invocation Throttling Limits Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
BR-23 |
Guardrail Content Filter Coverage Check
|
High | N/A |
777788889999 |
eu-west-1 |
BR-24 |
Automated Reasoning Policy Implementation Check
|
Medium | N/A |
777788889999 |
eu-west-1 |
BR-25 |
RAG Evaluation Jobs Check
|
Low | N/A |
777788889999 |
eu-west-1 |
BR-26 |
Guardrail Sensitive Information Filter Check
|
High | N/A |
777788889999 |
eu-west-1 |
BR-27 |
Guardrail Contextual Grounding Check
|
Medium | N/A |
777788889999 |
eu-west-1 |
BR-28 |
Agent Guardrail Association Check
|
High | N/A |
777788889999 |
eu-west-1 |
BR-29 |
Agent Idle Session TTL Check
|
Low | N/A |
777788889999 |
eu-west-1 |
BR-30 |
Imported Model Customer-Managed KMS Encryption Check
Details and remediationDetails
Unable to check Imported model encryption check: An error occurred (AccessDeniedException) when calling the ListImportedModels operation: Your account is not authorized to invoke this API operation. Resolution
Amazon Bedrock Custom Model Import is not enabled or available for this account in this region. No IAM change is required; the check applies only once model import is in use. |
Low | N/A |
777788889999 |
eu-west-1 |
BR-31 |
Batch Inference Output Encryption Check
|
Medium | N/A |
777788889999 |
eu-west-1 |
BR-32 |
Bedrock CloudWatch Alarm Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
BR-33 |
Amazon Inspector Lambda Code Scanning Check
Details and remediationDetails
No Lambda functions with Bedrock indicators were found in eu-west-1; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
No action required. If Bedrock-calling Lambda functions exist, ensure their function name, ARN, description, handler, role, or environment variables contain a Bedrock identifier that the assessment can detect, or evaluate Inspector coverage manually. |
Informational | N/A |
777788889999 |
eu-west-1 |
AG-07 |
Agentic AI Model Invocation Logging
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements. |
Informational | N/A |
777788889999 |
eu-west-1 |
AG-08 |
Agentic AI API Audit Trail
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage Resolution
Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured. |
Informational | N/A |
777788889999 |
eu-west-1 |
AG-10 |
Agentic AI Adversarial Evaluation Coverage
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs Resolution
Configure model or application evaluations that include adversarial, safety, and security-relevant test cases. |
Informational | N/A |
777788889999 |
eu-west-1 |
AG-11 |
Agentic AI Prompt Flow Validation
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region Resolution
Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions. |
Informational | N/A |
777788889999 |
eu-west-1 |
AG-06 |
Agentic AI Tool Execution Least Privilege
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region Resolution
Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required. |
Informational | N/A |
777788889999 |
eu-west-1 |
AG-12 |
Agentic AI Invocation Abuse Controls
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas Resolution
Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns. |
Informational | N/A |
777788889999 |
eu-west-1 |
AG-02 |
Agentic AI Harmful Content Guardrail Coverage
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads. |
Informational | N/A |
777788889999 |
eu-west-1 |
AG-04 |
Agentic AI Automated Reasoning Guardrails
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: No Bedrock guardrails configured in this region Resolution
Configure automated reasoning policies on guardrails where formal response validation is required. |
Informational | N/A |
777788889999 |
eu-west-1 |
AG-03 |
Agentic AI Sensitive Information Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: No Bedrock guardrails configured in this region Resolution
Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns. |
Informational | N/A |
777788889999 |
eu-west-1 |
AG-05 |
Agentic AI Grounding Controls
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: No Bedrock guardrails configured in this region Resolution
Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows. |
Informational | N/A |
777788889999 |
eu-west-1 |
AG-01 |
Agentic AI Agent Guardrail Association
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region Resolution
Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating. |
Informational | N/A |
777788889999 |
eu-west-1 |
AG-13 |
Agentic AI Session Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region Resolution
Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements. |
Informational | N/A |
777788889999 |
eu-west-1 |
AG-14 |
Agentic AI Operational Abuse Alarms
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms Resolution
Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available. |
Informational | N/A |
777788889999 |
Global |
BR-01 |
AmazonBedrockFullAccess role check
|
High | Failed |
777788889999 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
Role 'aiml-sec-test-resources-BedrockFullAccessRole-zAFkGLkWQ61a' has overly permissive marketplace subscription access through policy 'AmazonBedrockFullAccess' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | Failed |
777788889999 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
Role 'aiml-sec-test-resources-MarketplaceOverlyPermissive-igL3hGIapee1' has overly permissive marketplace subscription access through policy 'OverlyPermissiveMarketplace' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | Failed |
777788889999 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
Role 'ProwlerApp-EC2-Role' has overly permissive marketplace subscription access through policy 'AWSElasticBeanstalkMulticontainerDocker' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | Failed |
777788889999 |
us-east-1 |
BR-02 |
Amazon Bedrock private connectivity
|
High | Passed |
777788889999 |
us-east-1 |
BR-04 |
Bedrock Model Invocation Logging Check
Details and remediationDetails
Model invocation logging is not enabled. This limits your ability to track and audit model usage. Resolution
Enable model invocation logging to collect invocation logs, model input data, and model output data. Configure logging to deliver to Amazon S3, CloudWatch Logs, or both for comprehensive monitoring. |
Medium | Failed |
777788889999 |
us-east-1 |
BR-05 |
Bedrock Guardrails Check
|
High | Passed |
777788889999 |
us-east-1 |
BR-06 |
Bedrock CloudTrail Logging Check
|
Medium | Passed |
777788889999 |
us-east-1 |
BR-07 |
Bedrock Prompt Management Check
|
Low | Passed |
777788889999 |
us-east-1 |
BR-08 |
Bedrock Agent IAM Roles Check
|
Informational | N/A |
777788889999 |
us-east-1 |
BR-09 |
Bedrock Knowledge Base Encryption Review
Details and remediationDetails
Knowledge Base 'knowledge-base-prowler-findings' (9K2QZLVCZW) uses 'OPENSEARCH_SERVERLESS' storage. Encryption is managed at the storage layer and cannot be validated from the KB API. Verify encryption configuration on the underlying storage resource. Resolution
1. For OpenSearch Serverless: Verify encryption with CMK at collection level 2. For S3 data sources: Verify CMK-encrypted S3 buckets 3. For RDS: Verify KMS encryption on the database 4. Consider using CMK for transient data during ingestion |
Informational | N/A |
777788889999 |
us-east-1 |
BR-10 |
Bedrock Guardrail IAM Enforcement Missing
Details and remediationDetails
The following roles can invoke Bedrock models without enforced guardrails: aiml-sec-test-resources-BedrockAgentRoleWithoutGuar-Z3kN5ANhP89G, aiml-sec-test-resources-BedrockFullAccessRole-zAFkGLkWQ61a, aiml-sec-test-resources-BedrockKnowledgeBaseRole-6NNC1i9FuTbM, AmazonBedrockExecutionRoleForKnowledgeBase_7erx6, ProwlerApp-EC2-Role Resolution
Add IAM policy conditions to enforce guardrail usage: 1. Use 'bedrock:GuardrailIdentifier' condition key 2. Specify required guardrail ARN or ID 3. Example: "Condition": {"StringEquals": {"bedrock:GuardrailIdentifier": "arn:aws:bedrock:region:account:guardrail/guardrail-id"}} |
High | Failed |
777788889999 |
us-east-1 |
BR-11 |
Bedrock Custom Model Encryption Check
|
Informational | N/A |
777788889999 |
us-east-1 |
BR-12 |
Bedrock Invocation Log Encryption Check
|
Informational | N/A |
777788889999 |
us-east-1 |
BR-13 |
Bedrock Flows Guardrails Check
|
Informational | N/A |
777788889999 |
Global |
BR-15 |
Cross-Account Guardrails Enforcement Check
|
Medium | N/A |
777788889999 |
us-east-1 |
BR-16 |
Guardrail Tier Validation Check
|
Informational | N/A |
777788889999 |
us-east-1 |
BR-17 |
Custom Model Customer-Managed KMS Encryption Check
|
High | N/A |
777788889999 |
us-east-1 |
BR-18 |
Model Evaluation Implementation Check
Details and remediationDetails
No Bedrock model evaluation jobs found. Model evaluation helps assess toxicity, accuracy, semantic robustness, and other safety metrics before production deployment. Resolution
Create model evaluation jobs using Amazon Bedrock Evaluations to assess foundation model performance against safety and quality metrics. Use built-in datasets or custom test sets. Enable LLM-as-a-judge evaluation for comprehensive assessment. |
Medium | Failed |
777788889999 |
us-east-1 |
BR-19 |
Prompt Flow Validation Check
|
Medium | N/A |
777788889999 |
us-east-1 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Review
Details and remediationDetails
Knowledge base 'knowledge-base-prowler-findings' (ID: 9K2QZLVCZW) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
1. For OpenSearch Serverless: verify the collection uses a customer-managed KMS key 2. For Amazon RDS/Aurora: verify KMS encryption on the database 3. For third-party stores (Pinecone, Redis, MongoDB): verify the provider's encryption configuration 4. Verify the customer-managed KMS key used for transient data during ingestion |
Informational | N/A |
777788889999 |
us-east-1 |
BR-22 |
Model Invocation Throttling Limits Check
|
Low | Passed |
777788889999 |
us-east-1 |
BR-23 |
Guardrail Content Filter Coverage Check
|
Informational | N/A |
777788889999 |
us-east-1 |
BR-25 |
RAG Evaluation Jobs Check
Details and remediationDetails
Knowledge base 'knowledge-base-prowler-findings' (ID: 9K2QZLVCZW) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Create RAG evaluation jobs for knowledge bases using Amazon Bedrock Model Evaluation. Configure evaluations to test context relevance, answer correctness, and faithfulness metrics. Run evaluations regularly (monthly or after significant KB updates) to maintain quality. |
Low | Failed |
777788889999 |
us-east-1 |
BR-26 |
Guardrail Sensitive Information Filter Check
|
Informational | N/A |
777788889999 |
us-east-1 |
BR-27 |
Guardrail Contextual Grounding Check
|
Informational | N/A |
777788889999 |
us-east-1 |
BR-28 |
Agent Guardrail Association Check
|
Low | Passed |
777788889999 |
us-east-1 |
BR-30 |
Imported Model Customer-Managed KMS Encryption Check
|
High | N/A |
777788889999 |
us-east-1 |
BR-31 |
Batch Inference Output Encryption Check
|
Medium | N/A |
777788889999 |
us-east-1 |
BR-32 |
Bedrock CloudWatch Alarm Check
Details and remediationDetails
No CloudWatch alarms are configured on Amazon Bedrock runtime metrics (AWS/Bedrock namespace). Without alarms, abuse, denial-of-wallet, sustained throttling, and content-filter spikes can go undetected. Resolution
Create CloudWatch alarms on AWS/Bedrock runtime metrics such as Invocations, InvocationThrottles, InputTokenCount, OutputTokenCount, and ContentFilteredCount, and route them to an Amazon SNS topic for notification. |
Medium | Failed |
777788889999 |
us-east-1 |
BR-33 |
Amazon Inspector Lambda Code Scanning Check
|
Medium | Passed |
777788889999 |
us-east-1 |
AG-07 |
Agentic AI Model Invocation Logging
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: Model invocation logging is not enabled. This limits your ability to track and audit model usage. Resolution
Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements. |
Medium | Failed |
777788889999 |
us-east-1 |
AG-08 |
Agentic AI API Audit Trail
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: CloudTrail is properly configured to log Bedrock API activity in trails: IsengardTrail-DO-NOT-DELETE Resolution
Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured. |
Medium | Passed |
777788889999 |
Global |
AG-09 |
Agentic AI Guardrail Enforcement Boundary
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Organization-level guardrail enforcement helps prevent agents from bypassing required safety controls across accounts. Source check BR-15: Check must run in AWS Organizations management account to evaluate organizational policies Resolution
Use IAM and organization controls to require approved guardrails for model and agent invocations where supported. |
Informational | N/A |
777788889999 |
us-east-1 |
AG-10 |
Agentic AI Adversarial Evaluation Coverage
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No Bedrock model evaluation jobs found. Model evaluation helps assess toxicity, accuracy, semantic robustness, and other safety metrics before production deployment. Resolution
Configure model or application evaluations that include adversarial, safety, and security-relevant test cases. |
Medium | Failed |
777788889999 |
us-east-1 |
AG-11 |
Agentic AI Prompt Flow Validation
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region Resolution
Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions. |
Informational | N/A |
777788889999 |
us-east-1 |
AG-12 |
Agentic AI Invocation Abuse Controls
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: 9 custom throttling quotas are configured. Regular quota review helps maintain appropriate rate limits. Resolution
Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns. |
Low | Passed |
777788889999 |
us-east-1 |
AG-02 |
Agentic AI Harmful Content Guardrail Coverage
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: Guardrail 'aiml-sec-test-test-guardrail' (ID: jkceg2tprvwh) could not be assessed because GetGuardrail returned AccessDeniedException. Resolution
Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads. |
Informational | N/A |
777788889999 |
us-east-1 |
AG-03 |
Agentic AI Sensitive Information Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: Guardrail 'aiml-sec-test-test-guardrail' (ID: jkceg2tprvwh) could not be assessed because GetGuardrail returned AccessDeniedException. Resolution
Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns. |
Informational | N/A |
777788889999 |
us-east-1 |
AG-05 |
Agentic AI Grounding Controls
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: Guardrail 'aiml-sec-test-test-guardrail' (ID: jkceg2tprvwh) could not be assessed because GetGuardrail returned AccessDeniedException. Resolution
Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows. |
Informational | N/A |
777788889999 |
us-east-1 |
AG-01 |
Agentic AI Agent Guardrail Association
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: 1 agents have an associated guardrail Resolution
Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating. |
Low | Passed |
777788889999 |
us-east-1 |
AG-14 |
Agentic AI Operational Abuse Alarms
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No CloudWatch alarms are configured on Amazon Bedrock runtime metrics (AWS/Bedrock namespace). Without alarms, abuse, denial-of-wallet, sustained throttling, and content-filter spikes can go undetected. Resolution
Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available. |
Medium | Failed |
777788889999 |
us-east-2 |
OW-01 |
OWASP LLM01: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis. |
Informational | N/A |
777788889999 |
us-east-2 |
OW-07 |
OWASP LLM07: Model Invocation Logging
Details and remediation |
Informational | N/A |
777788889999 |
us-east-2 |
OW-07 |
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident. |
Informational | N/A |
777788889999 |
us-east-2 |
OW-07 |
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-09 |
OWASP LLM09: Model Evaluation Jobs
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-06 |
OWASP LLM06: Agent Action-Group Least Privilege
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-10 |
OWASP LLM10: Service Quota Throttling Limits
Details and remediation |
Informational | N/A |
777788889999 |
us-east-2 |
OW-01 |
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier. |
Informational | N/A |
777788889999 |
us-east-2 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-02 |
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation |
Informational | N/A |
777788889999 |
us-east-2 |
OW-01 |
OWASP LLM01: Contextual Grounding Guardrail
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-04 |
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation |
Informational | N/A |
777788889999 |
us-east-2 |
OW-09 |
OWASP LLM09: Contextual Grounding for Faithfulness
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-06 |
OWASP LLM06: Bedrock Agent Guardrail Association
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-06 |
OWASP LLM06: Agent Idle Session TTL
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-03 |
OWASP LLM03: Imported-Model KMS Provenance
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-10 |
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation |
Informational | N/A |
777788889999 |
us-east-2 |
OW-03 |
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check BR-33: No Lambda functions with Bedrock indicators were found in us-east-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain. |
Informational | N/A |
777788889999 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker Internet Exposure
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-01: No SageMaker notebook instances or domains found to check Resolution
Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths. |
Informational | N/A |
777788889999 |
us-east-2 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: No SageMaker resources found to check for data protection Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
Informational | N/A |
777788889999 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Clarify Evaluation
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation |
Informational | N/A |
777788889999 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Model Monitor Coverage
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker Notebook VPC Deployment
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker Model Network Isolation
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-10 |
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation |
Informational | N/A |
777788889999 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker Container Repository Access
Details and remediation |
Informational | N/A |
777788889999 |
us-east-2 |
OW-02 |
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation |
Informational | N/A |
777788889999 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker AutoML Network Isolation
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically. |
Informational | N/A |
777788889999 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release. |
Informational | N/A |
777788889999 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
777788889999 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
777788889999 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain. |
Informational | N/A |
777788889999 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated. |
Informational | N/A |
777788889999 |
us-east-2 |
OW-06 |
OWASP LLM06: AgentCore Resource-Based Policies
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-11 |
OWASP LLM07: System Prompt Embedded in Lambda Env Var
|
Medium | Passed |
777788889999 |
us-east-2 |
OW-12 |
OWASP LLM07: System-Prompt-Disclosure Denied Topic
|
Informational | N/A |
777788889999 |
eu-west-1 |
SM-01 |
SageMaker Internet Access Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
SM-02 |
SageMaker SSO Configuration Check
|
Medium | Passed |
777788889999 |
eu-west-1 |
SM-03 |
Data Protection Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
SM-04 |
GuardDuty Enabled
|
Medium | Passed |
777788889999 |
eu-west-1 |
SM-05 |
SageMaker Model Registry Issue
|
Informational | N/A |
777788889999 |
eu-west-1 |
SM-05 |
SageMaker Feature Store Issue
|
Informational | N/A |
777788889999 |
eu-west-1 |
SM-05 |
SageMaker Pipelines Issue
|
Informational | N/A |
777788889999 |
eu-west-1 |
SM-06 |
SageMaker Clarify No Clarify Usage
|
Informational | N/A |
777788889999 |
eu-west-1 |
SM-07 |
SageMaker Model Monitor No Model Monitoring
|
Informational | N/A |
777788889999 |
eu-west-1 |
SM-08 |
Model Registry Registry Not Used
|
Informational | N/A |
777788889999 |
eu-west-1 |
SM-09 |
SageMaker Notebook Root Access Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
SM-10 |
SageMaker Notebook VPC Deployment Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
SM-11 |
SageMaker Model Network Isolation Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
SM-12 |
SageMaker Endpoint Instance Count Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
SM-13 |
SageMaker Monitoring Network Isolation Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
SM-14 |
SageMaker Model Repository Access Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
SM-15 |
SageMaker Feature Store Encryption Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
SM-16 |
SageMaker Data Quality Job Encryption Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
SM-17 |
SageMaker Processing Job Encryption Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
SM-18 |
SageMaker Transform Job Encryption Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
SM-19 |
SageMaker Hyperparameter Tuning Job Encryption Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
SM-20 |
SageMaker Compilation Job Encryption Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
SM-21 |
SageMaker AutoML Job Network Isolation Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
SM-22 |
Model Approval Workflow Check
|
Informational | N/A |
777788889999 |
eu-west-1 |
SM-23 |
Model Drift Detection Check
|
Medium | Passed |
777788889999 |
eu-west-1 |
SM-24 |
A/B Testing and Shadow Deployment Check
|
Low | Passed |
777788889999 |
eu-west-1 |
SM-25 |
ML Lineage Tracking - Experiments Not Used
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-01 |
SageMaker Internet Access Check
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-02 |
SageMaker SSO Configuration Check
|
Medium | Passed |
777788889999 |
us-east-2 |
SM-03 |
Data Protection Check
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-04 |
GuardDuty Enabled
|
Medium | Passed |
777788889999 |
us-east-2 |
SM-05 |
SageMaker Model Registry Issue
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-05 |
SageMaker Feature Store Issue
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-05 |
SageMaker Pipelines Issue
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-06 |
SageMaker Clarify No Clarify Usage
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-07 |
SageMaker Model Monitor No Model Monitoring
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-08 |
Model Registry Registry Not Used
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-09 |
SageMaker Notebook Root Access Check
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-10 |
SageMaker Notebook VPC Deployment Check
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-11 |
SageMaker Model Network Isolation Check
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-12 |
SageMaker Endpoint Instance Count Check
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-13 |
SageMaker Monitoring Network Isolation Check
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-14 |
SageMaker Model Repository Access Check
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-15 |
SageMaker Feature Store Encryption Check
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-16 |
SageMaker Data Quality Job Encryption Check
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-17 |
SageMaker Processing Job Encryption Check
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-18 |
SageMaker Transform Job Encryption Check
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-19 |
SageMaker Hyperparameter Tuning Job Encryption Check
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-20 |
SageMaker Compilation Job Encryption Check
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-21 |
SageMaker AutoML Job Network Isolation Check
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-22 |
Model Approval Workflow Check
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-23 |
Model Drift Detection Check
|
Medium | Passed |
777788889999 |
us-east-2 |
SM-24 |
A/B Testing and Shadow Deployment Check
|
Low | Passed |
777788889999 |
us-east-2 |
SM-25 |
ML Lineage Tracking - Experiments Not Used
|
Informational | N/A |
777788889999 |
Global |
SM-02 |
SageMaker Full Access Policy Used
|
High | Failed |
777788889999 |
us-east-1 |
SM-01 |
Direct Internet Access Enabled
|
High | Failed |
777788889999 |
us-east-1 |
SM-01 |
Non-VPC Only Network Access
|
High | Failed |
777788889999 |
us-east-1 |
SM-01 |
Non-VPC Only Network Access
|
High | Failed |
777788889999 |
us-east-1 |
SM-02 |
SSO Not Properly Configured
Details and remediation |
Medium | Failed |
777788889999 |
us-east-1 |
SM-02 |
SSO Not Properly Configured
Details and remediation |
Medium | Failed |
777788889999 |
us-east-1 |
SM-02 |
SSO Not Properly Configured
Details and remediation |
Medium | Failed |
777788889999 |
us-east-1 |
SM-02 |
SSO Not Properly Configured
Details and remediation |
Medium | Failed |
777788889999 |
us-east-1 |
SM-03 |
Missing Encryption Configuration
|
High | Failed |
777788889999 |
us-east-1 |
SM-03 |
Missing Encryption Configuration
|
High | Failed |
777788889999 |
us-east-1 |
SM-03 |
Missing Encryption Configuration
|
High | Failed |
777788889999 |
us-east-1 |
SM-03 |
Missing Encryption Configuration
|
High | Failed |
777788889999 |
us-east-1 |
SM-03 |
Missing VPC Encryption
|
Medium | Failed |
777788889999 |
us-east-1 |
SM-04 |
GuardDuty Enabled
|
Medium | Passed |
777788889999 |
us-east-1 |
SM-05 |
SageMaker Model Registry Issue
|
Low | Failed |
777788889999 |
us-east-1 |
SM-05 |
SageMaker Pipelines Issue
|
Informational | N/A |
777788889999 |
us-east-1 |
SM-06 |
SageMaker Clarify No Clarify Usage
|
Informational | N/A |
777788889999 |
us-east-1 |
SM-07 |
SageMaker Model Monitor No Model Monitoring
|
Informational | N/A |
777788889999 |
us-east-1 |
SM-08 |
Model Registry Empty Model Group
|
Low | Failed |
777788889999 |
us-east-1 |
SM-09 |
SageMaker Notebook Root Access Enabled
Details and remediationDetails
Notebook instance 'aiml-sec-test-notebook-with-internet' has root access enabled. Root access allows users to install arbitrary software, modify system configurations, and potentially escalate privileges. Resolution
Disable root access by updating the notebook instance with RootAccess=Disabled. Note: Lifecycle configurations will still run with root access. |
High | Failed |
777788889999 |
us-east-1 |
SM-10 |
SageMaker Notebook Not in VPC
Details and remediationDetails
Notebook instance 'aiml-sec-test-notebook-with-internet' is not deployed in a custom VPC. This uses SageMaker's service VPC with reduced network isolation. Resolution
Create the notebook instance within a custom VPC by specifying SubnetId and SecurityGroupIds. This provides network isolation and allows use of VPC endpoints. |
High | Failed |
777788889999 |
us-east-1 |
SM-11 |
SageMaker Model Network Isolation Disabled
Details and remediationDetails
Model 'SageMakerModelNoIsolation-yQ7EpJeL7pgI' does not have network isolation enabled. Model containers can make outbound network calls, potentially exfiltrating data. Resolution
Enable network isolation by setting EnableNetworkIsolation=True when creating models. This prevents containers from making outbound network calls. |
High | Failed |
777788889999 |
us-east-1 |
SM-12 |
SageMaker Endpoint Instance Count Check
|
Informational | N/A |
777788889999 |
us-east-1 |
SM-13 |
SageMaker Monitoring Network Isolation Check
|
Informational | N/A |
777788889999 |
us-east-1 |
SM-14 |
SageMaker Model Platform Repository Access
Details and remediationDetails
Model 'SageMakerModelWithIsolation-JASFpUHjajdk' uses Platform repository access mode. Container images are pulled from public/external registries, exposing supply chain risks. Resolution
Configure RepositoryAccessMode=Vpc in ImageConfig to pull images from private ECR repositories through VPC. This provides supply chain security. |
Medium | Failed |
777788889999 |
us-east-1 |
SM-14 |
SageMaker Model Platform Repository Access
Details and remediationDetails
Model 'SageMakerModelNoIsolation-yQ7EpJeL7pgI' uses Platform repository access mode. Container images are pulled from public/external registries, exposing supply chain risks. Resolution
Configure RepositoryAccessMode=Vpc in ImageConfig to pull images from private ECR repositories through VPC. This provides supply chain security. |
Medium | Failed |
777788889999 |
us-east-1 |
SM-15 |
SageMaker Feature Store Offline Encryption Missing
Details and remediationDetails
Feature group 'aiml-sec-test-feature-group' offline store does not have KMS encryption configured. Feature data in S3 may not be encrypted with customer-managed keys. Resolution
Configure KmsKeyId in OfflineStoreConfig.S3StorageConfig when creating feature groups to encrypt offline store data with customer-managed KMS keys. |
Medium | Failed |
777788889999 |
us-east-1 |
SM-16 |
SageMaker Data Quality Job Encryption Check
|
Informational | N/A |
777788889999 |
us-east-1 |
SM-17 |
SageMaker Processing Job Encryption Check
|
Medium | Passed |
777788889999 |
us-east-1 |
SM-18 |
SageMaker Transform Job Encryption Check
|
Medium | Passed |
777788889999 |
us-east-1 |
SM-19 |
SageMaker Hyperparameter Tuning Job Encryption Check
|
Informational | N/A |
777788889999 |
us-east-1 |
SM-20 |
SageMaker Compilation Job Encryption Check
|
Informational | N/A |
777788889999 |
us-east-1 |
SM-21 |
SageMaker AutoML Job Network Isolation Check
|
Informational | N/A |
777788889999 |
us-east-1 |
SM-22 |
Model Approval Workflow Check
|
Medium | Passed |
777788889999 |
us-east-1 |
SM-23 |
Model Drift Detection Check
|
Medium | Passed |
777788889999 |
us-east-1 |
SM-24 |
A/B Testing and Shadow Deployment Check
|
Low | Passed |
777788889999 |
us-east-1 |
SM-25 |
ML Lineage Tracking - Experiments Not Used
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-01 |
SageMaker Internet Access Check
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-02 |
SageMaker SSO Configuration Check
|
Medium | Passed |
777788889999 |
us-west-2 |
SM-03 |
Data Protection Check
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-04 |
GuardDuty Enabled
|
Medium | Passed |
777788889999 |
us-west-2 |
SM-05 |
SageMaker Model Registry Issue
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-05 |
SageMaker Feature Store Issue
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-05 |
SageMaker Pipelines Issue
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-06 |
SageMaker Clarify No Clarify Usage
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-07 |
SageMaker Model Monitor No Model Monitoring
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-08 |
Model Registry Registry Not Used
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-09 |
SageMaker Notebook Root Access Check
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-10 |
SageMaker Notebook VPC Deployment Check
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-11 |
SageMaker Model Network Isolation Check
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-12 |
SageMaker Endpoint Instance Count Check
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-13 |
SageMaker Monitoring Network Isolation Check
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-14 |
SageMaker Model Repository Access Check
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-15 |
SageMaker Feature Store Encryption Check
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-16 |
SageMaker Data Quality Job Encryption Check
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-17 |
SageMaker Processing Job Encryption Check
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-18 |
SageMaker Transform Job Encryption Check
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-19 |
SageMaker Hyperparameter Tuning Job Encryption Check
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-20 |
SageMaker Compilation Job Encryption Check
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-21 |
SageMaker AutoML Job Network Isolation Check
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-22 |
Model Approval Workflow Check
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-23 |
Model Drift Detection Check
|
Medium | Passed |
777788889999 |
us-west-2 |
SM-24 |
A/B Testing and Shadow Deployment Check
|
Low | Passed |
777788889999 |
us-west-2 |
SM-25 |
ML Lineage Tracking - Experiments Not Used
|
Informational | N/A |
Scope: API-provable Agentic AI security controls mapped to the AWS Well-Architected Agentic AI Lens security guidance. Human-in-the-loop governance is referenced in methodology but not scored automatically unless an AWS API can prove the control.
Scope: this assessment records findings against each resolved CloudFormation TargetRegions entry. These checks are based on the AWS User Guide to Governance, Risk, and Compliance for Responsible AI Adoption. Severities follow a documented Likelihood × Impact methodology.
Scope: mapping-based derivation from existing BR/SM/AC/AG/FS checks plus two net-new checks for LLM07 (System Prompt Leakage). Each finding's OWASP category (LLM01–LLM10) is encoded in the Finding_Details text. Preliminary and illustrative — validate mappings with your Security/Compliance team before using as evidence.
Assessment Notes
Assessment Scope
Bedrock, SageMaker, and AgentCore checks are based on the AWS Well-Architected Framework Generative AI Lens. Agentic AI Security references the AWS Well-Architected Agentic AI Lens. Controls that cannot be proven using AWS APIs, including semantic human-in-the-loop workflow quality, are not automatically scored. Financial Services GenAI Risk checks are based on the AWS User Guide to Governance, Risk, and Compliance for Responsible AI Adoption. OWASP Top 10 LLM references OWASP Top 10 LLM.