Security Assessment Overview
Priority Recommendations
Severity Legend
View full methodology| Severity | Meaning | Recommended Action |
|---|---|---|
| High | Direct security risk - IAM/access control gaps, missing audit trails, guardrail bypasses that could lead to unauthorized access or data exposure | Remediate within 7 days |
| Medium | Defense-in-depth gaps - encryption, logging, or configuration issues that reduce security posture | Remediate within 30 days |
| Low | Best practice deviations - optimization opportunities that improve security hygiene | Remediate within 90 days |
| Informational | Not applicable, unavailable, no resources found, or advisory-only rows | No action required |
Direct Service Scored Control Results by Severity
Direct Failed Rows by Account
Direct Failed Rows by Region / Scope
Findings by Assessment Area
| Account ID | Region | Check ID | Finding | Severity | Status |
|---|---|---|---|---|---|
111122223333 |
us-east-2 |
AR-03 |
AWS Agent Registry Publication Approval Governance Incomplete
|
Informational | N/A |
111122223333 |
us-east-2 |
AR-04 |
AWS Agent Registry Discovery Authorization Incomplete
|
Informational | N/A |
111122223333 |
us-east-2 |
AR-05 |
AWS Agent Registry Customer-Managed KMS Encryption Incomplete
|
Informational | N/A |
111122223333 |
us-east-2 |
AR-06 |
AWS Agent Registry Organization Auto-Detection Incomplete
|
Informational | N/A |
111122223333 |
us-east-2 |
AR-07 |
AWS Agent Registry Record Lifecycle Governance Incomplete
|
Informational | N/A |
111122223333 |
us-east-2 |
AR-08 |
AWS Agent Registry Record Provenance Incomplete
|
Informational | N/A |
111122223333 |
us-east-2 |
AG-33 |
Agentic AI Registry Publication Approval Governance
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry approval workflows control which agents, tools, and skills become discoverable to consumers. Source check AR-03: Assessment could not enumerate AWS Agent Registry registries: AccessDeniedException (Unauthorized access). Resolution
Require manual review for registry publication where organizational policy does not permit automatic approval. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-34 |
Agentic AI Registry Discovery Authorization
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry discovery authorization requires review against intended callers and effective access boundaries. Source check AR-04: Assessment could not enumerate AWS Agent Registry registries: AccessDeniedException (Unauthorized access). Resolution
Review effective IAM access or compare custom JWT audiences, clients, scopes, and claims with approved registry consumers. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-35 |
Agentic AI Registry Metadata Encryption
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Registry records can contain agent, tool, endpoint, and ownership metadata that benefits from customer-controlled encryption. Source check AR-05: Assessment could not enumerate AWS Agent Registry registries: AccessDeniedException (Unauthorized access). Resolution
Create the registry with a customer-managed KMS key when organizational policy requires customer-controlled encryption. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-36 |
Agentic AI Organization Discovery Coverage
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Organization-wide auto-detection provides visibility into unmanaged agent resources. Source check AR-06: Assessment could not enumerate AWS Agent Registry registries: AccessDeniedException (Unauthorized access). Resolution
Enable organization-scoped registry auto-detection where centralized discovery is required. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-37 |
Agentic AI Registry Record Lifecycle Governance
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry lifecycle states provide operational visibility but do not independently prove a security control. Source check AR-07: Assessment could not enumerate AWS Agent Registry registries: AccessDeniedException (Unauthorized access). Resolution
Review failed or unknown record lifecycle states operationally. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-38 |
Agentic AI Registry Record Provenance
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Consumers need attributable record origin and source lineage to understand which account and resource produced an entry. Source check AR-08: Assessment could not enumerate AWS Agent Registry registries: AccessDeniedException (Unauthorized access). Resolution
Ensure records retain creator attribution and auto-detected records retain source provenance. |
Informational | N/A |
111122223333 |
Global |
AR-01 |
AWS Agent Registry IAM Full Access Check
|
High | Passed |
111122223333 |
Global |
AR-02 |
AWS Agent Registry Unused Permissions
|
Informational | N/A |
111122223333 |
us-east-1 |
AR-03 |
AWS Agent Registry Publication Approval Governance
|
Informational | N/A |
111122223333 |
us-east-1 |
AR-04 |
AWS Agent Registry Discovery Authorization
|
Informational | N/A |
111122223333 |
us-east-1 |
AR-05 |
AWS Agent Registry Customer-Managed KMS Encryption
|
Informational | N/A |
111122223333 |
us-east-1 |
AR-06 |
AWS Agent Registry Organization Auto-Detection
|
Informational | N/A |
111122223333 |
us-east-1 |
AR-07 |
AWS Agent Registry Record Lifecycle Governance
|
Informational | N/A |
111122223333 |
us-east-1 |
AR-08 |
AWS Agent Registry Record Provenance
|
Informational | N/A |
111122223333 |
us-east-1 |
AG-33 |
Agentic AI Registry Publication Approval Governance
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry approval workflows control which agents, tools, and skills become discoverable to consumers. Source check AR-03: No AWS Agent Registry registries found. Resolution
Require manual review for registry publication where organizational policy does not permit automatic approval. |
Informational | N/A |
111122223333 |
us-east-1 |
AG-34 |
Agentic AI Registry Discovery Authorization
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry discovery authorization requires review against intended callers and effective access boundaries. Source check AR-04: No AWS Agent Registry registries found. Resolution
Review effective IAM access or compare custom JWT audiences, clients, scopes, and claims with approved registry consumers. |
Informational | N/A |
111122223333 |
us-east-1 |
AG-35 |
Agentic AI Registry Metadata Encryption
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Registry records can contain agent, tool, endpoint, and ownership metadata that benefits from customer-controlled encryption. Source check AR-05: No AWS Agent Registry registries found. Resolution
Create the registry with a customer-managed KMS key when organizational policy requires customer-controlled encryption. |
Informational | N/A |
111122223333 |
us-east-1 |
AG-36 |
Agentic AI Organization Discovery Coverage
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Organization-wide auto-detection provides visibility into unmanaged agent resources. Source check AR-06: No AWS Agent Registry registries found. Resolution
Enable organization-scoped registry auto-detection where centralized discovery is required. |
Informational | N/A |
111122223333 |
us-east-1 |
AG-37 |
Agentic AI Registry Record Lifecycle Governance
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry lifecycle states provide operational visibility but do not independently prove a security control. Source check AR-07: No AWS Agent Registry registries found. Resolution
Review failed or unknown record lifecycle states operationally. |
Informational | N/A |
111122223333 |
us-east-1 |
AG-38 |
Agentic AI Registry Record Provenance
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Consumers need attributable record origin and source lineage to understand which account and resource produced an entry. Source check AR-08: No AWS Agent Registry registries found. Resolution
Ensure records retain creator attribution and auto-detected records retain source provenance. |
Informational | N/A |
111122223333 |
us-west-2 |
OW-01 |
OWASP LLM01: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: Model invocation logging is not enabled. This limits your ability to track and audit model usage. Resolution
Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis. |
Medium | Failed |
111122223333 |
us-west-2 |
OW-07 |
OWASP LLM07: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-04: Model invocation logging is not enabled. This limits your ability to track and audit model usage. Resolution
Enable Bedrock model invocation logging so prompt-extraction attempts against the system prompt are auditable after the fact. |
Medium | Failed |
111122223333 |
us-west-2 |
OW-07 |
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident. |
Informational | N/A |
111122223333 |
us-west-2 |
OW-07 |
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-16: Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) could not be assessed because GetGuardrail did not report contentPolicy.tier.tierName; tier unknown and was not assumed to be CLASSIC. Resolution
Set guardrail contentPolicy.tier.tierName to STANDARD; Standard tier additionally detects prompt-leakage attacks. |
Informational | N/A |
111122223333 |
us-west-2 |
OW-09 |
OWASP LLM09: Model Evaluation Jobs
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check BR-18: No Bedrock model evaluation jobs found. Model evaluation helps assess toxicity, accuracy, semantic robustness, and other safety metrics before production deployment. Resolution
Run Bedrock model evaluation jobs that include correctness and safety datasets. |
Medium | Failed |
111122223333 |
us-west-2 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: Knowledge base 'knowledge-base-bedrock-agent' (ID: XSPYLN4FQL) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption. |
Informational | N/A |
111122223333 |
us-west-2 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: Knowledge base 'IDP-DOCUMENTBEDROCKKB-CY8N0Q7N4YDT' (ID: SUGAG7RGYD) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption. |
Informational | N/A |
111122223333 |
us-west-2 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: Knowledge base 'promptfoo-rag-workshop-111122223333-kb' (ID: N74ZIKTUFL) uses 'RDS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption. |
Informational | N/A |
111122223333 |
us-west-2 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: Knowledge base 'InvestmentResearchKB' (ID: M1GMUG3BP0) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption. |
Informational | N/A |
111122223333 |
us-west-2 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: Knowledge base 'knowledge-base-quick-start-xtwwd' (ID: ENFHSBBLMV) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption. |
Informational | N/A |
111122223333 |
us-west-2 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: Knowledge base 'kb-s3-vector-store' (ID: 116IXQU5VP) uses 'S3_VECTORS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption. |
Informational | N/A |
111122223333 |
us-west-2 |
OW-06 |
OWASP LLM06: Agent Action-Group Least Privilege
|
Informational | N/A |
111122223333 |
us-west-2 |
OW-10 |
OWASP LLM10: Service Quota Throttling Limits
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-22: 8 custom throttling quotas are configured. Regular quota review helps maintain appropriate rate limits. Resolution
Customise Bedrock TPM / RPM service quotas above the account default to establish an explicit consumption ceiling. |
Low | Passed |
111122223333 |
us-west-2 |
OW-01 |
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) is missing content filters: HATE, INSULTS, SEXUAL, VIOLENCE. Resolution
Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier. |
High | Failed |
111122223333 |
us-west-2 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: Knowledge base 'knowledge-base-bedrock-agent' (ID: XSPYLN4FQL) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context. |
Low | Failed |
111122223333 |
us-west-2 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check BR-25: Knowledge base 'knowledge-base-bedrock-agent' (ID: XSPYLN4FQL) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates. |
Low | Failed |
111122223333 |
us-west-2 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: Knowledge base 'IDP-DOCUMENTBEDROCKKB-CY8N0Q7N4YDT' (ID: SUGAG7RGYD) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context. |
Low | Failed |
111122223333 |
us-west-2 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check BR-25: Knowledge base 'IDP-DOCUMENTBEDROCKKB-CY8N0Q7N4YDT' (ID: SUGAG7RGYD) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates. |
Low | Failed |
111122223333 |
us-west-2 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: Knowledge base 'promptfoo-rag-workshop-111122223333-kb' (ID: N74ZIKTUFL) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context. |
Low | Failed |
111122223333 |
us-west-2 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check BR-25: Knowledge base 'promptfoo-rag-workshop-111122223333-kb' (ID: N74ZIKTUFL) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates. |
Low | Failed |
111122223333 |
us-west-2 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: Knowledge base 'InvestmentResearchKB' (ID: M1GMUG3BP0) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context. |
Low | Failed |
111122223333 |
us-west-2 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check BR-25: Knowledge base 'InvestmentResearchKB' (ID: M1GMUG3BP0) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates. |
Low | Failed |
111122223333 |
us-west-2 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: Knowledge base 'knowledge-base-quick-start-xtwwd' (ID: ENFHSBBLMV) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context. |
Low | Failed |
111122223333 |
us-west-2 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check BR-25: Knowledge base 'knowledge-base-quick-start-xtwwd' (ID: ENFHSBBLMV) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates. |
Low | Failed |
111122223333 |
us-west-2 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: Knowledge base 'kb-s3-vector-store' (ID: 116IXQU5VP) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context. |
Low | Failed |
111122223333 |
us-west-2 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check BR-25: Knowledge base 'kb-s3-vector-store' (ID: 116IXQU5VP) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates. |
Low | Failed |
111122223333 |
us-west-2 |
OW-02 |
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check BR-26: Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) has no sensitive-information filters configured (no PII entities or regex patterns). Prompts and model responses are not screened for sensitive data such as PII. Resolution
Configure guardrail sensitiveInformationPolicy with PII entities and regex patterns; set outputAction=ANONYMIZE or BLOCK. |
High | Failed |
111122223333 |
us-west-2 |
OW-01 |
OWASP LLM01: Contextual Grounding Guardrail
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-27: Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) does not have contextual grounding checks enabled. Without grounding and relevance checks, the guardrail cannot detect hallucinated (ungrounded) or off-topic model responses. Resolution
Enable Bedrock guardrail contextual grounding checks to reduce the surface for indirect prompt injection through retrieved context. |
Medium | Failed |
111122223333 |
us-west-2 |
OW-04 |
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-27: Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) does not have contextual grounding checks enabled. Without grounding and relevance checks, the guardrail cannot detect hallucinated (ungrounded) or off-topic model responses. Resolution
Enable contextual grounding guardrail filters so retrieved context that diverges from ground truth is filtered before reaching the model. |
Medium | Failed |
111122223333 |
us-west-2 |
OW-09 |
OWASP LLM09: Contextual Grounding for Faithfulness
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check BR-27: Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) does not have contextual grounding checks enabled. Without grounding and relevance checks, the guardrail cannot detect hallucinated (ungrounded) or off-topic model responses. Resolution
Set the contextual grounding filter threshold to at least 0.70 to reduce hallucinated responses. |
Medium | Failed |
111122223333 |
us-west-2 |
OW-06 |
OWASP LLM06: Bedrock Agent Guardrail Association
|
Informational | N/A |
111122223333 |
us-west-2 |
OW-06 |
OWASP LLM06: Agent Idle Session TTL
|
Informational | N/A |
111122223333 |
us-west-2 |
OW-03 |
OWASP LLM03: Imported-Model KMS Provenance
|
Informational | N/A |
111122223333 |
us-west-2 |
OW-10 |
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-32: No CloudWatch alarms are configured on Amazon Bedrock runtime metrics (AWS/Bedrock namespace). Without alarms, abuse, denial-of-wallet, sustained throttling, and content-filter spikes can go undetected. Resolution
Create CloudWatch alarms on Bedrock InvocationThrottles, InputTokenCount, OutputTokenCount, and EstimatedTPMQuotaUsage. |
Medium | Failed |
111122223333 |
us-west-2 |
OW-03 |
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check BR-33: Amazon Inspector Lambda scanning is not fully enabled in us-west-2. Lambda standard scan status: DISABLED. Lambda code scan status: DISABLED. Detected 6 Lambda function(s) with Bedrock indicators: IDP-DOCUMENTBEDROCKKB-CY8-GetAdjustedStackNameFunc-MFYZSG0nWqdj, IDP-DOCUMENTBEDROCKKB-CY8-StartIngestionJobFunctio-QGtm6KrDTRYu, IDP-DOCUMENTBEDROCKKB-CY8N0Q7N-GetSeedUrlsFunction-vCBSeTw4AdDV, IDP-PATTERN1STACK-TNHNKPKJY-ProcessResultsFunction-xLOdarbvGDm7, IDP-QueryKnowledgeBaseResolverFunction-tkmkVZ4lgxf8 (and 1 more). Without both scan types enabled, vulnerable dependencies and hardcoded secrets in these in-scope functions will not be detected. Resolution
Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain. |
Medium | Failed |
111122223333 |
us-west-2 |
OW-01 |
OWASP LLM01: Preventive Prompt Attack Filter
Details and remediation |
High | Failed |
111122223333 |
us-west-2 |
OW-02 |
OWASP LLM02: Bedrock Data Retention Boundary
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check BR-37: Bedrock account data retention is inherit; this does not establish an explicit account-level zero-data-retention setting. Resolution
Configure Bedrock account data retention as none and disable provider data sharing when prompts or responses may contain sensitive information. |
High | Failed |
111122223333 |
us-west-2 |
OW-02 |
OWASP LLM02: Automated Reasoning Policy Encryption
Details and remediation |
Informational | N/A |
111122223333 |
us-west-2 |
OW-03 |
OWASP LLM03: Marketplace Endpoint VPC Isolation
Details and remediation |
Informational | N/A |
111122223333 |
us-west-2 |
OW-02 |
OWASP LLM02: Marketplace Endpoint CMK Encryption
|
Informational | N/A |
111122223333 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker Internet Exposure
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-01: SageMaker domain 'd-krxh4fmtaxjl' (PromptEvaluationDomain) is not configured for VPC-only access Resolution
Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths. |
High | Failed |
111122223333 |
us-west-2 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: Domain 'PromptEvaluationDomain' - No KMS key configured Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
High | Failed |
111122223333 |
us-west-2 |
OW-01 |
OWASP LLM01: GuardDuty AI Protection
|
High | Failed |
111122223333 |
us-west-2 |
OW-10 |
OWASP LLM10: GuardDuty AI Protection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check SM-26: GuardDuty is enabled, but the AI Protection detector feature is not enabled. Resolution
Enable the GuardDuty AI_PROTECTION detector feature to detect supported anomalous model invocation and cost-harvesting activity. |
High | Failed |
111122223333 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Clarify Evaluation
|
Informational | N/A |
111122223333 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation |
Informational | N/A |
111122223333 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Model Monitor Coverage
|
Informational | N/A |
111122223333 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker Notebook VPC Deployment
|
Informational | N/A |
111122223333 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker Model Network Isolation
|
Informational | N/A |
111122223333 |
us-west-2 |
OW-10 |
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation |
Informational | N/A |
111122223333 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker Container Repository Access
Details and remediation |
Informational | N/A |
111122223333 |
us-west-2 |
OW-02 |
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation |
Informational | N/A |
111122223333 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker AutoML Network Isolation
|
Informational | N/A |
111122223333 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically. |
Informational | N/A |
111122223333 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release. |
Informational | N/A |
111122223333 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
111122223333 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
111122223333 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain. |
Informational | N/A |
111122223333 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated. |
Informational | N/A |
111122223333 |
us-west-2 |
OW-02 |
OWASP LLM02: HyperPod Volume CMK Encryption
Details and remediation |
Informational | N/A |
111122223333 |
us-west-2 |
OW-03 |
OWASP LLM03: HyperPod VPC Boundary
Details and remediation |
Informational | N/A |
111122223333 |
us-west-2 |
OW-03 |
OWASP LLM03: Model Registry Resource Policy Boundary
|
Informational | N/A |
111122223333 |
us-west-2 |
OW-06 |
OWASP LLM06: AgentCore Resource-Based Policies
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check AC-10: The following AgentCore resources do not have resource-based policies: Gateway 'aws-news-mcp'. Without RBPs, access control relies solely on identity-based policies. Resolution
Attach resource-based policies to AgentCore runtimes and gateways so caller identities are constrained. |
High | Failed |
111122223333 |
us-west-2 |
OW-02 |
OWASP LLM02: AgentCore Token Vault CMK Encryption
Details and remediation |
High | Failed |
111122223333 |
us-west-2 |
OW-06 |
OWASP LLM06: Code Interpreter Network Isolation
|
Informational | N/A |
111122223333 |
us-west-2 |
OW-06 |
OWASP LLM06: Browser Tool Network Isolation
|
Informational | N/A |
111122223333 |
us-west-2 |
OW-11 |
OWASP LLM07: System Prompt Embedded in Lambda Env Var
|
Medium | Passed |
111122223333 |
us-west-2 |
OW-12 |
OWASP LLM07: System-Prompt-Disclosure Denied Topic
Details and remediationDetails
No readable Bedrock guardrail in us-west-2 has a DENY topic covering system-prompt disclosure. Attackers can craft prompts that ask the agent to reveal its system prompt or instructions. Resolution
Add a DENY topic to at least one guardrail. Suggested topic name: 'SystemPromptDisclosure'. Suggested definition: 'Requests to reveal, describe, or summarise the system prompt, instructions, or internal role definition given to the assistant.' |
Medium | Failed |
111122223333 |
us-east-2 |
OW-01 |
OWASP LLM01: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis. |
Informational | N/A |
111122223333 |
us-east-2 |
OW-07 |
OWASP LLM07: Model Invocation Logging
Details and remediation |
Informational | N/A |
111122223333 |
us-east-2 |
OW-07 |
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident. |
Informational | N/A |
111122223333 |
us-east-2 |
OW-07 |
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-09 |
OWASP LLM09: Model Evaluation Jobs
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-06 |
OWASP LLM06: Agent Action-Group Least Privilege
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-10 |
OWASP LLM10: Service Quota Throttling Limits
Details and remediation |
Informational | N/A |
111122223333 |
us-east-2 |
OW-01 |
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier. |
Informational | N/A |
111122223333 |
us-east-2 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-02 |
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation |
Informational | N/A |
111122223333 |
us-east-2 |
OW-01 |
OWASP LLM01: Contextual Grounding Guardrail
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-04 |
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation |
Informational | N/A |
111122223333 |
us-east-2 |
OW-09 |
OWASP LLM09: Contextual Grounding for Faithfulness
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-06 |
OWASP LLM06: Bedrock Agent Guardrail Association
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-06 |
OWASP LLM06: Agent Idle Session TTL
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-03 |
OWASP LLM03: Imported-Model KMS Provenance
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-10 |
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation |
Informational | N/A |
111122223333 |
us-east-2 |
OW-03 |
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check BR-33: No Lambda functions with Bedrock indicators were found in us-east-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain. |
Informational | N/A |
111122223333 |
us-east-2 |
OW-01 |
OWASP LLM01: Preventive Prompt Attack Filter
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-02 |
OWASP LLM02: Bedrock Data Retention Boundary
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check BR-37: Bedrock account data retention is inherit; this does not establish an explicit account-level zero-data-retention setting. Resolution
Configure Bedrock account data retention as none and disable provider data sharing when prompts or responses may contain sensitive information. |
High | Failed |
111122223333 |
us-east-2 |
OW-02 |
OWASP LLM02: Automated Reasoning Policy Encryption
Details and remediation |
Informational | N/A |
111122223333 |
us-east-2 |
OW-03 |
OWASP LLM03: Marketplace Endpoint VPC Isolation
Details and remediation |
Informational | N/A |
111122223333 |
us-east-2 |
OW-02 |
OWASP LLM02: Marketplace Endpoint CMK Encryption
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker Internet Exposure
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-01: No SageMaker notebook instances or domains found to check Resolution
Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths. |
Informational | N/A |
111122223333 |
us-east-2 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: Training Job 'xgboost-2021-12-19-01-07-45-798' - No output encryption configured Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
High | Failed |
111122223333 |
us-east-2 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: Training Job 'xgboost-2021-12-19-01-07-45-798' - Inter-container traffic encryption not enabled Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
Medium | Failed |
111122223333 |
us-east-2 |
OW-01 |
OWASP LLM01: GuardDuty AI Protection
|
High | Failed |
111122223333 |
us-east-2 |
OW-10 |
OWASP LLM10: GuardDuty AI Protection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check SM-26: GuardDuty is enabled, but the AI Protection detector feature is not enabled. Resolution
Enable the GuardDuty AI_PROTECTION detector feature to detect supported anomalous model invocation and cost-harvesting activity. |
High | Failed |
111122223333 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Clarify Evaluation
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation |
Informational | N/A |
111122223333 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Model Monitor Coverage
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker Notebook VPC Deployment
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker Model Network Isolation
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-11: Model 'xgboost-2021-12-19-01-25-44-527' does not have network isolation enabled. Model containers can make outbound network calls, potentially exfiltrating data. Resolution
Enable network isolation on SageMaker models so inference containers cannot make unmanaged outbound calls that alter dependencies or exfiltrate model artifacts. |
High | Failed |
111122223333 |
us-east-2 |
OW-10 |
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check SM-11: Model 'xgboost-2021-12-19-01-25-44-527' does not have network isolation enabled. Model containers can make outbound network calls, potentially exfiltrating data. Resolution
Enable SageMaker model network isolation to prevent deployed model containers from making uncontrolled outbound calls that can amplify consumption or abuse downstream services. |
High | Failed |
111122223333 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker Container Repository Access
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-14: Model 'xgboost-2021-12-19-01-25-44-527' uses Platform repository access mode. Container images are pulled from public/external registries, exposing supply chain risks. Resolution
Configure SageMaker models to pull container images from private ECR repositories through VPC repository access instead of platform or public registry paths. |
Medium | Failed |
111122223333 |
us-east-2 |
OW-02 |
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation |
Informational | N/A |
111122223333 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker AutoML Network Isolation
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically. |
Informational | N/A |
111122223333 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release. |
Informational | N/A |
111122223333 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
111122223333 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
111122223333 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain. |
Informational | N/A |
111122223333 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated. |
Informational | N/A |
111122223333 |
us-east-2 |
OW-02 |
OWASP LLM02: HyperPod Volume CMK Encryption
Details and remediation |
Informational | N/A |
111122223333 |
us-east-2 |
OW-03 |
OWASP LLM03: HyperPod VPC Boundary
Details and remediation |
Informational | N/A |
111122223333 |
us-east-2 |
OW-03 |
OWASP LLM03: Model Registry Resource Policy Boundary
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-06 |
OWASP LLM06: AgentCore Resource-Based Policies
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-02 |
OWASP LLM02: AgentCore Token Vault CMK Encryption
Details and remediation |
Informational | N/A |
111122223333 |
us-east-2 |
OW-06 |
OWASP LLM06: Code Interpreter Network Isolation
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-06 |
OWASP LLM06: Browser Tool Network Isolation
|
Informational | N/A |
111122223333 |
us-east-2 |
OW-11 |
OWASP LLM07: System Prompt Embedded in Lambda Env Var
|
Medium | Passed |
111122223333 |
us-east-2 |
OW-12 |
OWASP LLM07: System-Prompt-Disclosure Denied Topic
|
Informational | N/A |
111122223333 |
Global |
BR-01 |
AmazonBedrockFullAccess role check
|
High | Failed |
111122223333 |
Global |
BR-01 |
AmazonBedrockFullAccess role check
|
High | Failed |
111122223333 |
Global |
BR-01 |
AmazonBedrockFullAccess role check
|
High | Failed |
111122223333 |
Global |
BR-01 |
AmazonBedrockFullAccess role check
|
High | Failed |
111122223333 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
Role 'AmazonBedrockAgentCoreSDKRuntime-us-east-1-a6ddf3fc76' has overly permissive marketplace subscription access through policy 'BedrockAgentCoreRuntimeExecutionPolicy-cdk_agent_core' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | Failed |
111122223333 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
Role 'AmazonBedrockAgentCoreSDKRuntime-us-east-1-ed660add8b' has overly permissive marketplace subscription access through policy 'BedrockAgentCoreRuntimeExecutionPolicy-neoCyan_Agent' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | Failed |
111122223333 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
Role 'AmazonBedrockExecutionRoleForKnowledgeBase_knnc9' has overly permissive marketplace subscription access through policy 'AmazonBedrockFoundationModelPolicyForKnowledgeBase_knnc9' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | Failed |
111122223333 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
Role 'AmazonBedrockExecutionRoleForKnowledgeBase_qxqw2' has overly permissive marketplace subscription access through policy 'AmazonBedrockFoundationModelPolicyForKnowledgeBase_qxqw2' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | Failed |
111122223333 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
Role 'AmazonSageMaker-ExecutionRole-20250525T153161' has overly permissive marketplace subscription access through policy 'AmazonBedrockLimitedAccess' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | Failed |
111122223333 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
Role 'ClaudeCodeWorkshop-BedrockAccessLambdaRole-W3h1ES7F7R7K' has overly permissive marketplace subscription access through policy 'BedrockModelAccessGrant' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | Failed |
111122223333 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
Role 'ClaudeCodeWorkshop-CodeEditorInstanceBootstrapRole-GWdiq3M0J6tF' has overly permissive marketplace subscription access through policy 'AmazonBedrockFullAccess' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | Failed |
111122223333 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
Role 'IDPSageMakerCfnStack-SageMakerExecutionRole-aqrHz6dVkoHC' has overly permissive marketplace subscription access through policy 'AmazonBedrockFullAccess' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | Failed |
111122223333 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
Role 'LLMEvaluationPromptfoo-SageMakerExecutionRole-M69xCHJ9c3LU' has overly permissive marketplace subscription access through policy 'AmazonBedrockFullAccess' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | Failed |
111122223333 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
Role 'myAskMeAnything-role-kmsizqwf' has overly permissive marketplace subscription access through policy 'AmazonBedrockFullAccess' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | Failed |
111122223333 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
User 'BedrockAPIKey-20pp' has overly permissive marketplace subscription access through policy 'AmazonBedrockLimitedAccess' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | Failed |
111122223333 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
User 'BedrockAPIKey-yhc3' has overly permissive marketplace subscription access through policy 'AmazonBedrockLimitedAccess' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | Failed |
111122223333 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
User 'BedrockClientUser' has overly permissive marketplace subscription access through policy 'AmazonBedrockFullAccess' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | Failed |
111122223333 |
us-east-1 |
BR-02 |
Amazon Bedrock private connectivity not used
Details and remediationDetails
No Bedrock service VPC endpoints found in VPCs: vpc-03472be90d65c2f68, vpc-39319f44, vpc-064f3e808e378cbc8, vpc-02d020a365a06c7fe Resolution
Create a VPC endpoint in your VPC with any of the following Bedrock service endpoints that your application may be using: - com.amazonaws.region.bedrock - com.amazonaws.region.bedrock-runtime - com.amazonaws.region.bedrock-agent - com.amazonaws.region.bedrock-agent-runtime |
Medium | Failed |
111122223333 |
us-east-1 |
BR-04 |
Bedrock Model Invocation Logging Check
Details and remediationDetails
Model invocation logging is not enabled. This limits your ability to track and audit model usage. Resolution
Enable model invocation logging to collect invocation logs, model input data, and model output data. Configure logging to deliver to Amazon S3, CloudWatch Logs, or both for comprehensive monitoring. |
Medium | Failed |
111122223333 |
us-east-1 |
BR-05 |
Bedrock Guardrails Check
Details and remediationDetails
No Amazon Bedrock Guardrails are configured. This may expose your application to potential risks such as harmful content, sensitive information disclosure, or hallucinations. Resolution
Configure Bedrock Guardrails to implement safeguards such as: - Content filters to block harmful content - Denied topics to prevent undesirable discussions - Sensitive information filters to protect PII - Contextual grounding checks to prevent hallucinations |
Medium | Failed |
111122223333 |
us-east-1 |
BR-06 |
Bedrock CloudTrail Logging Check
|
Medium | Passed |
111122223333 |
us-east-1 |
BR-07 |
Bedrock Prompt Management Check
Details and remediationDetails
Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates |
Informational | N/A |
111122223333 |
us-east-1 |
BR-08 |
Bedrock Agent IAM Roles Check
|
Informational | N/A |
111122223333 |
us-east-1 |
BR-09 |
Bedrock Knowledge Base Encryption Review
Details and remediationDetails
Knowledge Base 'knowledge-base-semiconductors' (RQYFDSE1LT) uses 'OPENSEARCH_SERVERLESS' storage. Encryption is managed at the storage layer and cannot be validated from the KB API. Verify encryption configuration on the underlying storage resource. Resolution
1. For OpenSearch Serverless: Verify encryption with CMK at collection level 2. For S3 data sources: Verify CMK-encrypted S3 buckets 3. For RDS: Verify KMS encryption on the database 4. Consider using CMK for transient data during ingestion |
Informational | N/A |
111122223333 |
us-east-1 |
BR-09 |
Bedrock Knowledge Base Encryption Review
Details and remediationDetails
Knowledge Base '111122223333-us-east-1-kb' (PAJOKBSIMQ) uses 'S3_VECTORS' storage. Encryption is managed at the storage layer and cannot be validated from the KB API. Verify encryption configuration on the underlying storage resource. Resolution
1. For OpenSearch Serverless: Verify encryption with CMK at collection level 2. For S3 data sources: Verify CMK-encrypted S3 buckets 3. For RDS: Verify KMS encryption on the database 4. Consider using CMK for transient data during ingestion |
Informational | N/A |
111122223333 |
us-east-1 |
BR-09 |
Bedrock Knowledge Base Encryption Review
Details and remediationDetails
Knowledge Base 'e2e-rag-knowledgebase' (ESIYAYSYTJ) uses 'OPENSEARCH_SERVERLESS' storage. Encryption is managed at the storage layer and cannot be validated from the KB API. Verify encryption configuration on the underlying storage resource. Resolution
1. For OpenSearch Serverless: Verify encryption with CMK at collection level 2. For S3 data sources: Verify CMK-encrypted S3 buckets 3. For RDS: Verify KMS encryption on the database 4. Consider using CMK for transient data during ingestion |
Informational | N/A |
111122223333 |
us-east-1 |
BR-10 |
Bedrock Guardrail IAM Enforcement Check
|
Informational | N/A |
111122223333 |
us-east-1 |
BR-11 |
Bedrock Custom Model Encryption Check
|
Informational | N/A |
111122223333 |
us-east-1 |
BR-12 |
Bedrock Invocation Log Encryption Check
|
Informational | N/A |
111122223333 |
us-east-1 |
BR-13 |
Bedrock Flows Guardrails Check
|
Informational | N/A |
111122223333 |
Global |
BR-15 |
Cross-Account Guardrails Enforcement Check
Details and remediationDetails
No account-level enforced guardrail configuration was observed, and organization policy inheritance cannot be fully established from this member account. Resolution
Run the assessment from the management or delegated administrator account, or configure account-level enforced guardrails. |
Informational | N/A |
111122223333 |
us-east-1 |
BR-16 |
Guardrail Tier Validation Check
|
Medium | N/A |
111122223333 |
us-east-1 |
BR-17 |
Custom Model Customer-Managed KMS Encryption Check
|
High | N/A |
111122223333 |
us-east-1 |
BR-18 |
Model Evaluation Implementation Check
Details and remediationDetails
No Bedrock model evaluation jobs found. Model evaluation helps assess toxicity, accuracy, semantic robustness, and other safety metrics before production deployment. Resolution
Create model evaluation jobs using Amazon Bedrock Evaluations to assess foundation model performance against safety and quality metrics. Use built-in datasets or custom test sets. Enable LLM-as-a-judge evaluation for comprehensive assessment. |
Medium | Failed |
111122223333 |
us-east-1 |
BR-19 |
Prompt Flow Validation Check
|
Medium | N/A |
111122223333 |
us-east-1 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Review
Details and remediationDetails
Knowledge base 'knowledge-base-semiconductors' (ID: RQYFDSE1LT) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
1. For OpenSearch Serverless: verify the collection uses a customer-managed KMS key 2. For Amazon RDS/Aurora: verify KMS encryption on the database 3. For third-party stores (Pinecone, Redis, MongoDB): verify the provider's encryption configuration 4. Verify the customer-managed KMS key used for transient data during ingestion |
Informational | N/A |
111122223333 |
us-east-1 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Review
Details and remediationDetails
Knowledge base '111122223333-us-east-1-kb' (ID: PAJOKBSIMQ) uses 'S3_VECTORS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
1. For OpenSearch Serverless: verify the collection uses a customer-managed KMS key 2. For Amazon RDS/Aurora: verify KMS encryption on the database 3. For third-party stores (Pinecone, Redis, MongoDB): verify the provider's encryption configuration 4. Verify the customer-managed KMS key used for transient data during ingestion |
Informational | N/A |
111122223333 |
us-east-1 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Review
Details and remediationDetails
Knowledge base 'e2e-rag-knowledgebase' (ID: ESIYAYSYTJ) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
1. For OpenSearch Serverless: verify the collection uses a customer-managed KMS key 2. For Amazon RDS/Aurora: verify KMS encryption on the database 3. For third-party stores (Pinecone, Redis, MongoDB): verify the provider's encryption configuration 4. Verify the customer-managed KMS key used for transient data during ingestion |
Informational | N/A |
111122223333 |
us-east-1 |
BR-21 |
Agent Action Group IAM Least Privilege Check
|
High | N/A |
111122223333 |
us-east-1 |
BR-22 |
Model Invocation Throttling Limits Check
|
Low | Passed |
111122223333 |
us-east-1 |
BR-23 |
Guardrail Content Filter Coverage Check
|
Informational | N/A |
111122223333 |
us-east-1 |
BR-24 |
Automated Reasoning Policy Implementation Check
|
Medium | N/A |
111122223333 |
us-east-1 |
BR-25 |
RAG Evaluation Jobs Check
Details and remediationDetails
Knowledge base 'knowledge-base-semiconductors' (ID: RQYFDSE1LT) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Create RAG evaluation jobs for knowledge bases using Amazon Bedrock Model Evaluation. Configure evaluations to test context relevance, answer correctness, and faithfulness metrics. Run evaluations regularly (monthly or after significant KB updates) to maintain quality. |
Low | Failed |
111122223333 |
us-east-1 |
BR-25 |
RAG Evaluation Jobs Check
Details and remediationDetails
Knowledge base '111122223333-us-east-1-kb' (ID: PAJOKBSIMQ) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Create RAG evaluation jobs for knowledge bases using Amazon Bedrock Model Evaluation. Configure evaluations to test context relevance, answer correctness, and faithfulness metrics. Run evaluations regularly (monthly or after significant KB updates) to maintain quality. |
Low | Failed |
111122223333 |
us-east-1 |
BR-25 |
RAG Evaluation Jobs Check
Details and remediationDetails
Knowledge base 'e2e-rag-knowledgebase' (ID: ESIYAYSYTJ) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Create RAG evaluation jobs for knowledge bases using Amazon Bedrock Model Evaluation. Configure evaluations to test context relevance, answer correctness, and faithfulness metrics. Run evaluations regularly (monthly or after significant KB updates) to maintain quality. |
Low | Failed |
111122223333 |
us-east-1 |
BR-26 |
Guardrail Sensitive Information Filter Check
|
High | N/A |
111122223333 |
us-east-1 |
BR-27 |
Guardrail Contextual Grounding Check
|
Medium | N/A |
111122223333 |
us-east-1 |
BR-28 |
Agent Guardrail Association Check
|
High | N/A |
111122223333 |
us-east-1 |
BR-29 |
Agent Idle Session TTL Check
|
Low | N/A |
111122223333 |
us-east-1 |
BR-30 |
Imported Model Customer-Managed KMS Encryption Check
|
High | N/A |
111122223333 |
us-east-1 |
BR-31 |
Batch Inference Output Encryption Check
|
Medium | N/A |
111122223333 |
us-east-1 |
BR-32 |
Bedrock CloudWatch Alarm Check
Details and remediationDetails
No CloudWatch alarms are configured on Amazon Bedrock runtime metrics (AWS/Bedrock namespace). Without alarms, abuse, denial-of-wallet, sustained throttling, and content-filter spikes can go undetected. Resolution
Create CloudWatch alarms on AWS/Bedrock runtime metrics such as Invocations, InvocationThrottles, InputTokenCount, OutputTokenCount, and ContentFilteredCount, and route them to an Amazon SNS topic for notification. |
Medium | Failed |
111122223333 |
us-east-1 |
BR-33 |
Amazon Inspector Lambda Code Scanning Check
Details and remediationDetails
Amazon Inspector Lambda scanning is not fully enabled in us-east-1. Lambda standard scan status: ENABLED. Lambda code scan status: DISABLED. Detected 8 Lambda function(s) with Bedrock indicators: ClaudeCoworkEnvironment-BedrockApiKeyLambda-pPWYTtBWqHtH, aiml-security-aiml-security-111122223333-BedrockAssessment, gateway_lambda, myAskMeAnything, resco-aiml-BedrockAssessment (and 3 more). Without both scan types enabled, vulnerable dependencies and hardcoded secrets in these in-scope functions will not be detected. Resolution
Enable both Lambda standard scanning and Lambda code scanning in Amazon Inspector for this account and region. Console: Inspector -> Account management -> Activate for Lambda functions and Lambda code. |
Medium | Failed |
111122223333 |
us-east-1 |
BR-34 |
Guardrail Prompt Attack Filter
|
Informational | N/A |
111122223333 |
us-east-1 |
BR-35 |
Guardrail Image Content Filter Coverage
|
Informational | N/A |
111122223333 |
us-east-1 |
BR-36 |
Application Inference Profile Governance
|
Low | Failed |
111122223333 |
us-east-1 |
BR-37 |
Bedrock Account Data Retention
|
High | Failed |
111122223333 |
us-east-1 |
BR-38 |
Automated Reasoning Policy CMK Encryption
|
Informational | N/A |
111122223333 |
us-east-1 |
BR-39 |
Marketplace Model Endpoint VPC Configuration
|
Informational | N/A |
111122223333 |
us-east-1 |
BR-40 |
Marketplace Model Endpoint CMK Encryption
|
Informational | N/A |
111122223333 |
us-east-1 |
AG-07 |
Agentic AI Model Invocation Logging
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: Model invocation logging is not enabled. This limits your ability to track and audit model usage. Resolution
Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements. |
Medium | Failed |
111122223333 |
us-east-1 |
AG-08 |
Agentic AI API Audit Trail
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: CloudTrail is properly configured to log Bedrock API activity in trails: GuardTrail-DO-NOT-DELETE Resolution
Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured. |
Medium | Passed |
111122223333 |
Global |
AG-09 |
Agentic AI Guardrail Enforcement Boundary
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Organization-level guardrail enforcement helps prevent agents from bypassing required safety controls across accounts. Source check BR-15: No account-level enforced guardrail configuration was observed, and organization policy inheritance cannot be fully established from this member account. Resolution
Use IAM and organization controls to require approved guardrails for model and agent invocations where supported. |
Informational | N/A |
111122223333 |
us-east-1 |
AG-10 |
Agentic AI Adversarial Evaluation Coverage
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No Bedrock model evaluation jobs found. Model evaluation helps assess toxicity, accuracy, semantic robustness, and other safety metrics before production deployment. Resolution
Configure model or application evaluations that include adversarial, safety, and security-relevant test cases. |
Medium | Failed |
111122223333 |
us-east-1 |
AG-11 |
Agentic AI Prompt Flow Validation
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region Resolution
Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions. |
Informational | N/A |
111122223333 |
us-east-1 |
AG-06 |
Agentic AI Tool Execution Least Privilege
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region Resolution
Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required. |
Informational | N/A |
111122223333 |
us-east-1 |
AG-12 |
Agentic AI Invocation Abuse Controls
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: 10 custom throttling quotas are configured. Regular quota review helps maintain appropriate rate limits. Resolution
Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns. |
Low | Passed |
111122223333 |
us-east-1 |
AG-02 |
Agentic AI Harmful Content Guardrail Coverage
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads. |
Informational | N/A |
111122223333 |
us-east-1 |
AG-04 |
Agentic AI Automated Reasoning Guardrails
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: No Bedrock guardrails configured in this region Resolution
Configure automated reasoning policies on guardrails where formal response validation is required. |
Informational | N/A |
111122223333 |
us-east-1 |
AG-03 |
Agentic AI Sensitive Information Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: No Bedrock guardrails configured in this region Resolution
Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns. |
Informational | N/A |
111122223333 |
us-east-1 |
AG-05 |
Agentic AI Grounding Controls
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: No Bedrock guardrails configured in this region Resolution
Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows. |
Informational | N/A |
111122223333 |
us-east-1 |
AG-01 |
Agentic AI Agent Guardrail Association
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region Resolution
Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating. |
Informational | N/A |
111122223333 |
us-east-1 |
AG-13 |
Agentic AI Session Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region Resolution
Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements. |
Informational | N/A |
111122223333 |
us-east-1 |
AG-14 |
Agentic AI Operational Abuse Alarms
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No CloudWatch alarms are configured on Amazon Bedrock runtime metrics (AWS/Bedrock namespace). Without alarms, abuse, denial-of-wallet, sustained throttling, and content-filter spikes can go undetected. Resolution
Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available. |
Medium | Failed |
111122223333 |
us-east-1 |
AG-30 |
Agentic AI Prompt Attack Protection
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agents should prevent prompt attacks before untrusted input can redirect planning or tool use. Source check BR-34: No Bedrock guardrails configured in this region Resolution
Enable a preventive PROMPT_ATTACK input filter on each guardrail and use Standard tier where prompt-leakage protection is required. |
Informational | N/A |
111122223333 |
us-east-2 |
BR-02 |
Amazon Bedrock private connectivity check
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-04 |
Bedrock Model Invocation Logging Check
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-05 |
Bedrock Guardrails Check
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-06 |
Bedrock CloudTrail Logging Check
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-07 |
Bedrock Prompt Management Check
Details and remediationDetails
Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates |
Informational | N/A |
111122223333 |
us-east-2 |
BR-08 |
Bedrock Agent IAM Roles Check
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-09 |
Bedrock Knowledge Base Encryption Check
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-10 |
Bedrock Guardrail IAM Enforcement Check
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-11 |
Bedrock Custom Model Encryption Check
|
Low | N/A |
111122223333 |
us-east-2 |
BR-12 |
Bedrock Invocation Log Encryption Check
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-13 |
Bedrock Flows Guardrails Check
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-16 |
Guardrail Tier Validation Check
|
Medium | N/A |
111122223333 |
us-east-2 |
BR-17 |
Custom Model Customer-Managed KMS Encryption Check
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-18 |
Model Evaluation Implementation Check
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-19 |
Prompt Flow Validation Check
|
Medium | N/A |
111122223333 |
us-east-2 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Check
|
High | N/A |
111122223333 |
us-east-2 |
BR-21 |
Agent Action Group IAM Least Privilege Check
|
High | N/A |
111122223333 |
us-east-2 |
BR-22 |
Model Invocation Throttling Limits Check
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-23 |
Guardrail Content Filter Coverage Check
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-24 |
Automated Reasoning Policy Implementation Check
|
Medium | N/A |
111122223333 |
us-east-2 |
BR-25 |
RAG Evaluation Jobs Check
|
Low | N/A |
111122223333 |
us-east-2 |
BR-26 |
Guardrail Sensitive Information Filter Check
|
High | N/A |
111122223333 |
us-east-2 |
BR-27 |
Guardrail Contextual Grounding Check
|
Medium | N/A |
111122223333 |
us-east-2 |
BR-28 |
Agent Guardrail Association Check
|
High | N/A |
111122223333 |
us-east-2 |
BR-29 |
Agent Idle Session TTL Check
|
Low | N/A |
111122223333 |
us-east-2 |
BR-30 |
Imported Model Customer-Managed KMS Encryption Check
|
High | N/A |
111122223333 |
us-east-2 |
BR-31 |
Batch Inference Output Encryption Check
|
Medium | N/A |
111122223333 |
us-east-2 |
BR-32 |
Bedrock CloudWatch Alarm Check
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-33 |
Amazon Inspector Lambda Code Scanning Check
Details and remediationDetails
No Lambda functions with Bedrock indicators were found in us-east-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
No action required. If Bedrock-calling Lambda functions exist, ensure their function name, ARN, description, handler, role, or environment variables contain a Bedrock identifier that the assessment can detect, or evaluate Inspector coverage manually. |
Informational | N/A |
111122223333 |
us-east-2 |
BR-34 |
Guardrail Prompt Attack Filter
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-35 |
Guardrail Image Content Filter Coverage
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-36 |
Application Inference Profile Governance
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-37 |
Bedrock Account Data Retention
|
High | Failed |
111122223333 |
us-east-2 |
BR-38 |
Automated Reasoning Policy CMK Encryption
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-39 |
Marketplace Model Endpoint VPC Configuration
|
Informational | N/A |
111122223333 |
us-east-2 |
BR-40 |
Marketplace Model Endpoint CMK Encryption
|
Informational | N/A |
111122223333 |
us-east-2 |
AG-07 |
Agentic AI Model Invocation Logging
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-08 |
Agentic AI API Audit Trail
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage Resolution
Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-10 |
Agentic AI Adversarial Evaluation Coverage
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs Resolution
Configure model or application evaluations that include adversarial, safety, and security-relevant test cases. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-11 |
Agentic AI Prompt Flow Validation
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region Resolution
Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-06 |
Agentic AI Tool Execution Least Privilege
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region Resolution
Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-12 |
Agentic AI Invocation Abuse Controls
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas Resolution
Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-02 |
Agentic AI Harmful Content Guardrail Coverage
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-04 |
Agentic AI Automated Reasoning Guardrails
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: No Bedrock guardrails configured in this region Resolution
Configure automated reasoning policies on guardrails where formal response validation is required. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-03 |
Agentic AI Sensitive Information Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: No Bedrock guardrails configured in this region Resolution
Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-05 |
Agentic AI Grounding Controls
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: No Bedrock guardrails configured in this region Resolution
Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-01 |
Agentic AI Agent Guardrail Association
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region Resolution
Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-13 |
Agentic AI Session Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region Resolution
Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-14 |
Agentic AI Operational Abuse Alarms
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms Resolution
Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-30 |
Agentic AI Prompt Attack Protection
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agents should prevent prompt attacks before untrusted input can redirect planning or tool use. Source check BR-34: No Bedrock guardrails configured in this region Resolution
Enable a preventive PROMPT_ATTACK input filter on each guardrail and use Standard tier where prompt-leakage protection is required. |
Informational | N/A |
111122223333 |
us-west-2 |
BR-02 |
Amazon Bedrock private connectivity not used
Details and remediationDetails
No Bedrock service VPC endpoints found in VPCs: vpc-0f85a6754ab37efb7, vpc-5c3b6524, vpc-03bcafcb58a3029fc Resolution
Create a VPC endpoint in your VPC with any of the following Bedrock service endpoints that your application may be using: - com.amazonaws.region.bedrock - com.amazonaws.region.bedrock-runtime - com.amazonaws.region.bedrock-agent - com.amazonaws.region.bedrock-agent-runtime |
Medium | Failed |
111122223333 |
us-west-2 |
BR-04 |
Bedrock Model Invocation Logging Check
Details and remediationDetails
Model invocation logging is not enabled. This limits your ability to track and audit model usage. Resolution
Enable model invocation logging to collect invocation logs, model input data, and model output data. Configure logging to deliver to Amazon S3, CloudWatch Logs, or both for comprehensive monitoring. |
Medium | Failed |
111122223333 |
us-west-2 |
BR-05 |
Bedrock Guardrails Check
|
High | Passed |
111122223333 |
us-west-2 |
BR-06 |
Bedrock CloudTrail Logging Check
|
Medium | Passed |
111122223333 |
us-west-2 |
BR-07 |
Bedrock Prompt Management Check
Details and remediationDetails
Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates |
Informational | N/A |
111122223333 |
us-west-2 |
BR-08 |
Bedrock Agent IAM Roles Check
|
Informational | N/A |
111122223333 |
us-west-2 |
BR-09 |
Bedrock Knowledge Base Encryption Review
Details and remediationDetails
Knowledge Base 'knowledge-base-bedrock-agent' (XSPYLN4FQL) uses 'OPENSEARCH_SERVERLESS' storage. Encryption is managed at the storage layer and cannot be validated from the KB API. Verify encryption configuration on the underlying storage resource. Resolution
1. For OpenSearch Serverless: Verify encryption with CMK at collection level 2. For S3 data sources: Verify CMK-encrypted S3 buckets 3. For RDS: Verify KMS encryption on the database 4. Consider using CMK for transient data during ingestion |
Informational | N/A |
111122223333 |
us-west-2 |
BR-09 |
Bedrock Knowledge Base Encryption Review
Details and remediationDetails
Knowledge Base 'IDP-DOCUMENTBEDROCKKB-CY8N0Q7N4YDT' (SUGAG7RGYD) uses 'OPENSEARCH_SERVERLESS' storage. Encryption is managed at the storage layer and cannot be validated from the KB API. Verify encryption configuration on the underlying storage resource. Resolution
1. For OpenSearch Serverless: Verify encryption with CMK at collection level 2. For S3 data sources: Verify CMK-encrypted S3 buckets 3. For RDS: Verify KMS encryption on the database 4. Consider using CMK for transient data during ingestion |
Informational | N/A |
111122223333 |
us-west-2 |
BR-09 |
Bedrock Knowledge Base Encryption Review
Details and remediationDetails
Knowledge Base 'promptfoo-rag-workshop-111122223333-kb' (N74ZIKTUFL) uses 'RDS' storage. Encryption is managed at the storage layer and cannot be validated from the KB API. Verify encryption configuration on the underlying storage resource. Resolution
1. For OpenSearch Serverless: Verify encryption with CMK at collection level 2. For S3 data sources: Verify CMK-encrypted S3 buckets 3. For RDS: Verify KMS encryption on the database 4. Consider using CMK for transient data during ingestion |
Informational | N/A |
111122223333 |
us-west-2 |
BR-09 |
Bedrock Knowledge Base Encryption Review
Details and remediationDetails
Knowledge Base 'InvestmentResearchKB' (M1GMUG3BP0) uses 'OPENSEARCH_SERVERLESS' storage. Encryption is managed at the storage layer and cannot be validated from the KB API. Verify encryption configuration on the underlying storage resource. Resolution
1. For OpenSearch Serverless: Verify encryption with CMK at collection level 2. For S3 data sources: Verify CMK-encrypted S3 buckets 3. For RDS: Verify KMS encryption on the database 4. Consider using CMK for transient data during ingestion |
Informational | N/A |
111122223333 |
us-west-2 |
BR-09 |
Bedrock Knowledge Base Encryption Review
Details and remediationDetails
Knowledge Base 'knowledge-base-quick-start-xtwwd' (ENFHSBBLMV) uses 'OPENSEARCH_SERVERLESS' storage. Encryption is managed at the storage layer and cannot be validated from the KB API. Verify encryption configuration on the underlying storage resource. Resolution
1. For OpenSearch Serverless: Verify encryption with CMK at collection level 2. For S3 data sources: Verify CMK-encrypted S3 buckets 3. For RDS: Verify KMS encryption on the database 4. Consider using CMK for transient data during ingestion |
Informational | N/A |
111122223333 |
us-west-2 |
BR-09 |
Bedrock Knowledge Base Encryption Review
Details and remediationDetails
Knowledge Base 'kb-s3-vector-store' (116IXQU5VP) uses 'S3_VECTORS' storage. Encryption is managed at the storage layer and cannot be validated from the KB API. Verify encryption configuration on the underlying storage resource. Resolution
1. For OpenSearch Serverless: Verify encryption with CMK at collection level 2. For S3 data sources: Verify CMK-encrypted S3 buckets 3. For RDS: Verify KMS encryption on the database 4. Consider using CMK for transient data during ingestion |
Informational | N/A |
111122223333 |
us-west-2 |
BR-10 |
Bedrock Guardrail IAM Enforcement Missing
Details and remediationDetails
The following roles can invoke Bedrock models without enforced guardrails: 111122223333-us-east-1-kb-bedrock-service-role, agentcore-wildrydes_gateway_role_ab3991f6-role, AgentCoreEvalsSDK-us-east-1-d04ba7b68b, AmazonBedrockAgentCoreSDKRuntime-us-east-1-a6ddf3fc76, AmazonBedrockAgentCoreSDKRuntime-us-east-1-ed660add8b, AmazonBedrockExecutionRoleForAgents_S0T9VNPP9D, AmazonBedrockExecutionRoleForAgents_WNCOPE29NZ, AmazonBedrockExecutionRoleForKnowledgeBase_072pr, AmazonBedrockExecutionRoleForKnowledgeBase_byjin, AmazonBedrockExecutionRoleForKnowledgeBase_h9718... Resolution
Add IAM policy conditions to enforce guardrail usage: 1. Use 'bedrock:GuardrailIdentifier' condition key 2. Specify required guardrail ARN or ID 3. Example: "Condition": {"StringEquals": {"bedrock:GuardrailIdentifier": "arn:aws:bedrock:region:account:guardrail/guardrail-id"}} |
High | Failed |
111122223333 |
us-west-2 |
BR-11 |
Bedrock Custom Model Encryption Check
|
Informational | N/A |
111122223333 |
us-west-2 |
BR-12 |
Bedrock Invocation Log Encryption Check
|
Informational | N/A |
111122223333 |
us-west-2 |
BR-13 |
Bedrock Flows Guardrails Check
|
Informational | N/A |
111122223333 |
us-west-2 |
BR-16 |
Guardrail Tier Validation Check
Details and remediationDetails
Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) could not be assessed because GetGuardrail did not report contentPolicy.tier.tierName; tier unknown and was not assumed to be CLASSIC. Resolution
Review the guardrail configuration and rerun the assessment after GetGuardrail reports the content-filter tier. |
Informational | N/A |
111122223333 |
us-west-2 |
BR-17 |
Custom Model Customer-Managed KMS Encryption Check
|
High | N/A |
111122223333 |
us-west-2 |
BR-18 |
Model Evaluation Implementation Check
Details and remediationDetails
No Bedrock model evaluation jobs found. Model evaluation helps assess toxicity, accuracy, semantic robustness, and other safety metrics before production deployment. Resolution
Create model evaluation jobs using Amazon Bedrock Evaluations to assess foundation model performance against safety and quality metrics. Use built-in datasets or custom test sets. Enable LLM-as-a-judge evaluation for comprehensive assessment. |
Medium | Failed |
111122223333 |
us-west-2 |
BR-19 |
Prompt Flow Validation Check
|
Medium | N/A |
111122223333 |
us-west-2 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Review
Details and remediationDetails
Knowledge base 'knowledge-base-bedrock-agent' (ID: XSPYLN4FQL) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
1. For OpenSearch Serverless: verify the collection uses a customer-managed KMS key 2. For Amazon RDS/Aurora: verify KMS encryption on the database 3. For third-party stores (Pinecone, Redis, MongoDB): verify the provider's encryption configuration 4. Verify the customer-managed KMS key used for transient data during ingestion |
Informational | N/A |
111122223333 |
us-west-2 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Review
Details and remediationDetails
Knowledge base 'IDP-DOCUMENTBEDROCKKB-CY8N0Q7N4YDT' (ID: SUGAG7RGYD) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
1. For OpenSearch Serverless: verify the collection uses a customer-managed KMS key 2. For Amazon RDS/Aurora: verify KMS encryption on the database 3. For third-party stores (Pinecone, Redis, MongoDB): verify the provider's encryption configuration 4. Verify the customer-managed KMS key used for transient data during ingestion |
Informational | N/A |
111122223333 |
us-west-2 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Review
Details and remediationDetails
Knowledge base 'promptfoo-rag-workshop-111122223333-kb' (ID: N74ZIKTUFL) uses 'RDS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
1. For OpenSearch Serverless: verify the collection uses a customer-managed KMS key 2. For Amazon RDS/Aurora: verify KMS encryption on the database 3. For third-party stores (Pinecone, Redis, MongoDB): verify the provider's encryption configuration 4. Verify the customer-managed KMS key used for transient data during ingestion |
Informational | N/A |
111122223333 |
us-west-2 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Review
Details and remediationDetails
Knowledge base 'InvestmentResearchKB' (ID: M1GMUG3BP0) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
1. For OpenSearch Serverless: verify the collection uses a customer-managed KMS key 2. For Amazon RDS/Aurora: verify KMS encryption on the database 3. For third-party stores (Pinecone, Redis, MongoDB): verify the provider's encryption configuration 4. Verify the customer-managed KMS key used for transient data during ingestion |
Informational | N/A |
111122223333 |
us-west-2 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Review
Details and remediationDetails
Knowledge base 'knowledge-base-quick-start-xtwwd' (ID: ENFHSBBLMV) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
1. For OpenSearch Serverless: verify the collection uses a customer-managed KMS key 2. For Amazon RDS/Aurora: verify KMS encryption on the database 3. For third-party stores (Pinecone, Redis, MongoDB): verify the provider's encryption configuration 4. Verify the customer-managed KMS key used for transient data during ingestion |
Informational | N/A |
111122223333 |
us-west-2 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Review
Details and remediationDetails
Knowledge base 'kb-s3-vector-store' (ID: 116IXQU5VP) uses 'S3_VECTORS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
1. For OpenSearch Serverless: verify the collection uses a customer-managed KMS key 2. For Amazon RDS/Aurora: verify KMS encryption on the database 3. For third-party stores (Pinecone, Redis, MongoDB): verify the provider's encryption configuration 4. Verify the customer-managed KMS key used for transient data during ingestion |
Informational | N/A |
111122223333 |
us-west-2 |
BR-21 |
Agent Action Group IAM Least Privilege Check
|
High | N/A |
111122223333 |
us-west-2 |
BR-22 |
Model Invocation Throttling Limits Check
|
Low | Passed |
111122223333 |
us-west-2 |
BR-23 |
Guardrail Content Filter Coverage Check
|
High | Failed |
111122223333 |
us-west-2 |
BR-24 |
Automated Reasoning Policy Implementation Check
Details and remediationDetails
Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) does not have an Automated Reasoning policy configured. Automated Reasoning provides formal verification of model responses against defined policies. Resolution
Configure Automated Reasoning policies on guardrails to mathematically verify model responses. Define policies that specify allowed and disallowed behaviors. Use for high-assurance use cases where formal verification is required. |
Medium | Failed |
111122223333 |
us-west-2 |
BR-25 |
RAG Evaluation Jobs Check
Details and remediationDetails
Knowledge base 'knowledge-base-bedrock-agent' (ID: XSPYLN4FQL) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Create RAG evaluation jobs for knowledge bases using Amazon Bedrock Model Evaluation. Configure evaluations to test context relevance, answer correctness, and faithfulness metrics. Run evaluations regularly (monthly or after significant KB updates) to maintain quality. |
Low | Failed |
111122223333 |
us-west-2 |
BR-25 |
RAG Evaluation Jobs Check
Details and remediationDetails
Knowledge base 'IDP-DOCUMENTBEDROCKKB-CY8N0Q7N4YDT' (ID: SUGAG7RGYD) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Create RAG evaluation jobs for knowledge bases using Amazon Bedrock Model Evaluation. Configure evaluations to test context relevance, answer correctness, and faithfulness metrics. Run evaluations regularly (monthly or after significant KB updates) to maintain quality. |
Low | Failed |
111122223333 |
us-west-2 |
BR-25 |
RAG Evaluation Jobs Check
Details and remediationDetails
Knowledge base 'promptfoo-rag-workshop-111122223333-kb' (ID: N74ZIKTUFL) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Create RAG evaluation jobs for knowledge bases using Amazon Bedrock Model Evaluation. Configure evaluations to test context relevance, answer correctness, and faithfulness metrics. Run evaluations regularly (monthly or after significant KB updates) to maintain quality. |
Low | Failed |
111122223333 |
us-west-2 |
BR-25 |
RAG Evaluation Jobs Check
Details and remediationDetails
Knowledge base 'InvestmentResearchKB' (ID: M1GMUG3BP0) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Create RAG evaluation jobs for knowledge bases using Amazon Bedrock Model Evaluation. Configure evaluations to test context relevance, answer correctness, and faithfulness metrics. Run evaluations regularly (monthly or after significant KB updates) to maintain quality. |
Low | Failed |
111122223333 |
us-west-2 |
BR-25 |
RAG Evaluation Jobs Check
Details and remediationDetails
Knowledge base 'knowledge-base-quick-start-xtwwd' (ID: ENFHSBBLMV) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Create RAG evaluation jobs for knowledge bases using Amazon Bedrock Model Evaluation. Configure evaluations to test context relevance, answer correctness, and faithfulness metrics. Run evaluations regularly (monthly or after significant KB updates) to maintain quality. |
Low | Failed |
111122223333 |
us-west-2 |
BR-25 |
RAG Evaluation Jobs Check
Details and remediationDetails
Knowledge base 'kb-s3-vector-store' (ID: 116IXQU5VP) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Create RAG evaluation jobs for knowledge bases using Amazon Bedrock Model Evaluation. Configure evaluations to test context relevance, answer correctness, and faithfulness metrics. Run evaluations regularly (monthly or after significant KB updates) to maintain quality. |
Low | Failed |
111122223333 |
us-west-2 |
BR-26 |
Guardrail Sensitive Information Filter Check
Details and remediationDetails
Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) has no sensitive-information filters configured (no PII entities or regex patterns). Prompts and model responses are not screened for sensitive data such as PII. Resolution
Configure sensitive-information filters on the guardrail: add PII entity types (e.g. NAME, EMAIL, SSN, CREDIT_DEBIT_CARD_NUMBER) and/or custom regex patterns, and set the appropriate BLOCK or ANONYMIZE action for input and output. |
High | Failed |
111122223333 |
us-west-2 |
BR-27 |
Guardrail Contextual Grounding Check
Details and remediationDetails
Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) does not have contextual grounding checks enabled. Without grounding and relevance checks, the guardrail cannot detect hallucinated (ungrounded) or off-topic model responses. Resolution
Enable contextual grounding checks (GROUNDING and RELEVANCE filter types) on the guardrail with appropriate thresholds. This is especially important for RAG applications to ensure responses are grounded in the retrieved source material. |
Medium | Failed |
111122223333 |
us-west-2 |
BR-28 |
Agent Guardrail Association Check
|
High | N/A |
111122223333 |
us-west-2 |
BR-29 |
Agent Idle Session TTL Check
|
Low | N/A |
111122223333 |
us-west-2 |
BR-30 |
Imported Model Customer-Managed KMS Encryption Check
|
High | N/A |
111122223333 |
us-west-2 |
BR-31 |
Batch Inference Output Encryption Check
|
Medium | N/A |
111122223333 |
us-west-2 |
BR-32 |
Bedrock CloudWatch Alarm Check
Details and remediationDetails
No CloudWatch alarms are configured on Amazon Bedrock runtime metrics (AWS/Bedrock namespace). Without alarms, abuse, denial-of-wallet, sustained throttling, and content-filter spikes can go undetected. Resolution
Create CloudWatch alarms on AWS/Bedrock runtime metrics such as Invocations, InvocationThrottles, InputTokenCount, OutputTokenCount, and ContentFilteredCount, and route them to an Amazon SNS topic for notification. |
Medium | Failed |
111122223333 |
us-west-2 |
BR-33 |
Amazon Inspector Lambda Code Scanning Check
Details and remediationDetails
Amazon Inspector Lambda scanning is not fully enabled in us-west-2. Lambda standard scan status: DISABLED. Lambda code scan status: DISABLED. Detected 6 Lambda function(s) with Bedrock indicators: IDP-DOCUMENTBEDROCKKB-CY8-GetAdjustedStackNameFunc-MFYZSG0nWqdj, IDP-DOCUMENTBEDROCKKB-CY8-StartIngestionJobFunctio-QGtm6KrDTRYu, IDP-DOCUMENTBEDROCKKB-CY8N0Q7N-GetSeedUrlsFunction-vCBSeTw4AdDV, IDP-PATTERN1STACK-TNHNKPKJY-ProcessResultsFunction-xLOdarbvGDm7, IDP-QueryKnowledgeBaseResolverFunction-tkmkVZ4lgxf8 (and 1 more). Without both scan types enabled, vulnerable dependencies and hardcoded secrets in these in-scope functions will not be detected. Resolution
Enable both Lambda standard scanning and Lambda code scanning in Amazon Inspector for this account and region. Console: Inspector -> Account management -> Activate for Lambda functions and Lambda code. |
Medium | Failed |
111122223333 |
us-west-2 |
BR-34 |
Guardrail Prompt Attack Filter
|
High | Failed |
111122223333 |
us-west-2 |
BR-35 |
Guardrail Image Content Filter Coverage
Details and remediationDetails
Guardrail 'Sample-Guardrail' has image-modality gaps for: HATE, INSULTS, SEXUAL, VIOLENCE. This is advisory because application modality is not observable from guardrail configuration. Resolution
If the protected workload accepts or returns images, add IMAGE input/output modalities to the listed filters. |
Informational | N/A |
111122223333 |
us-west-2 |
BR-36 |
Application Inference Profile Governance
|
Informational | N/A |
111122223333 |
us-west-2 |
BR-37 |
Bedrock Account Data Retention
|
High | Failed |
111122223333 |
us-west-2 |
BR-38 |
Automated Reasoning Policy CMK Encryption
|
Informational | N/A |
111122223333 |
us-west-2 |
BR-39 |
Marketplace Model Endpoint VPC Configuration
|
Informational | N/A |
111122223333 |
us-west-2 |
BR-40 |
Marketplace Model Endpoint CMK Encryption
|
Informational | N/A |
111122223333 |
us-west-2 |
AG-07 |
Agentic AI Model Invocation Logging
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: Model invocation logging is not enabled. This limits your ability to track and audit model usage. Resolution
Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements. |
Medium | Failed |
111122223333 |
us-west-2 |
AG-08 |
Agentic AI API Audit Trail
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: CloudTrail is properly configured to log Bedrock API activity in trails: GuardTrail-DO-NOT-DELETE Resolution
Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured. |
Medium | Passed |
111122223333 |
us-west-2 |
AG-10 |
Agentic AI Adversarial Evaluation Coverage
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No Bedrock model evaluation jobs found. Model evaluation helps assess toxicity, accuracy, semantic robustness, and other safety metrics before production deployment. Resolution
Configure model or application evaluations that include adversarial, safety, and security-relevant test cases. |
Medium | Failed |
111122223333 |
us-west-2 |
AG-11 |
Agentic AI Prompt Flow Validation
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region Resolution
Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions. |
Informational | N/A |
111122223333 |
us-west-2 |
AG-06 |
Agentic AI Tool Execution Least Privilege
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region Resolution
Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required. |
Informational | N/A |
111122223333 |
us-west-2 |
AG-12 |
Agentic AI Invocation Abuse Controls
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: 8 custom throttling quotas are configured. Regular quota review helps maintain appropriate rate limits. Resolution
Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns. |
Low | Passed |
111122223333 |
us-west-2 |
AG-02 |
Agentic AI Harmful Content Guardrail Coverage
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) is missing content filters: HATE, INSULTS, SEXUAL, VIOLENCE. Resolution
Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads. |
High | Failed |
111122223333 |
us-west-2 |
AG-04 |
Agentic AI Automated Reasoning Guardrails
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) does not have an Automated Reasoning policy configured. Automated Reasoning provides formal verification of model responses against defined policies. Resolution
Configure automated reasoning policies on guardrails where formal response validation is required. |
Medium | Failed |
111122223333 |
us-west-2 |
AG-03 |
Agentic AI Sensitive Information Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) has no sensitive-information filters configured (no PII entities or regex patterns). Prompts and model responses are not screened for sensitive data such as PII. Resolution
Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns. |
High | Failed |
111122223333 |
us-west-2 |
AG-05 |
Agentic AI Grounding Controls
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) does not have contextual grounding checks enabled. Without grounding and relevance checks, the guardrail cannot detect hallucinated (ungrounded) or off-topic model responses. Resolution
Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows. |
Medium | Failed |
111122223333 |
us-west-2 |
AG-01 |
Agentic AI Agent Guardrail Association
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region Resolution
Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating. |
Informational | N/A |
111122223333 |
us-west-2 |
AG-13 |
Agentic AI Session Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region Resolution
Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements. |
Informational | N/A |
111122223333 |
us-west-2 |
AG-14 |
Agentic AI Operational Abuse Alarms
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No CloudWatch alarms are configured on Amazon Bedrock runtime metrics (AWS/Bedrock namespace). Without alarms, abuse, denial-of-wallet, sustained throttling, and content-filter spikes can go undetected. Resolution
Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available. |
Medium | Failed |
111122223333 |
us-west-2 |
AG-30 |
Agentic AI Prompt Attack Protection
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agents should prevent prompt attacks before untrusted input can redirect planning or tool use. Source check BR-34: Guardrail 'Sample-Guardrail' does not have a preventive PROMPT_ATTACK input filter. Resolution
Enable a preventive PROMPT_ATTACK input filter on each guardrail and use Standard tier where prompt-leakage protection is required. |
High | Failed |
111122223333 |
us-east-1 |
OW-01 |
OWASP LLM01: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: Model invocation logging is not enabled. This limits your ability to track and audit model usage. Resolution
Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis. |
Medium | Failed |
111122223333 |
us-east-1 |
OW-07 |
OWASP LLM07: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-04: Model invocation logging is not enabled. This limits your ability to track and audit model usage. Resolution
Enable Bedrock model invocation logging so prompt-extraction attempts against the system prompt are auditable after the fact. |
Medium | Failed |
111122223333 |
us-east-1 |
OW-07 |
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident. |
Informational | N/A |
111122223333 |
us-east-1 |
OW-07 |
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
|
Informational | N/A |
111122223333 |
us-east-1 |
OW-09 |
OWASP LLM09: Model Evaluation Jobs
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check BR-18: No Bedrock model evaluation jobs found. Model evaluation helps assess toxicity, accuracy, semantic robustness, and other safety metrics before production deployment. Resolution
Run Bedrock model evaluation jobs that include correctness and safety datasets. |
Medium | Failed |
111122223333 |
us-east-1 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: Knowledge base 'knowledge-base-semiconductors' (ID: RQYFDSE1LT) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption. |
Informational | N/A |
111122223333 |
us-east-1 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: Knowledge base '111122223333-us-east-1-kb' (ID: PAJOKBSIMQ) uses 'S3_VECTORS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption. |
Informational | N/A |
111122223333 |
us-east-1 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: Knowledge base 'e2e-rag-knowledgebase' (ID: ESIYAYSYTJ) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption. |
Informational | N/A |
111122223333 |
us-east-1 |
OW-06 |
OWASP LLM06: Agent Action-Group Least Privilege
|
Informational | N/A |
111122223333 |
us-east-1 |
OW-10 |
OWASP LLM10: Service Quota Throttling Limits
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-22: 10 custom throttling quotas are configured. Regular quota review helps maintain appropriate rate limits. Resolution
Customise Bedrock TPM / RPM service quotas above the account default to establish an explicit consumption ceiling. |
Low | Passed |
111122223333 |
us-east-1 |
OW-01 |
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier. |
Informational | N/A |
111122223333 |
us-east-1 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: Knowledge base 'knowledge-base-semiconductors' (ID: RQYFDSE1LT) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context. |
Low | Failed |
111122223333 |
us-east-1 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check BR-25: Knowledge base 'knowledge-base-semiconductors' (ID: RQYFDSE1LT) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates. |
Low | Failed |
111122223333 |
us-east-1 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: Knowledge base '111122223333-us-east-1-kb' (ID: PAJOKBSIMQ) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context. |
Low | Failed |
111122223333 |
us-east-1 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check BR-25: Knowledge base '111122223333-us-east-1-kb' (ID: PAJOKBSIMQ) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates. |
Low | Failed |
111122223333 |
us-east-1 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: Knowledge base 'e2e-rag-knowledgebase' (ID: ESIYAYSYTJ) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context. |
Low | Failed |
111122223333 |
us-east-1 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check BR-25: Knowledge base 'e2e-rag-knowledgebase' (ID: ESIYAYSYTJ) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates. |
Low | Failed |
111122223333 |
us-east-1 |
OW-02 |
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation |
Informational | N/A |
111122223333 |
us-east-1 |
OW-01 |
OWASP LLM01: Contextual Grounding Guardrail
|
Informational | N/A |
111122223333 |
us-east-1 |
OW-04 |
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation |
Informational | N/A |
111122223333 |
us-east-1 |
OW-09 |
OWASP LLM09: Contextual Grounding for Faithfulness
|
Informational | N/A |
111122223333 |
us-east-1 |
OW-06 |
OWASP LLM06: Bedrock Agent Guardrail Association
|
Informational | N/A |
111122223333 |
us-east-1 |
OW-06 |
OWASP LLM06: Agent Idle Session TTL
|
Informational | N/A |
111122223333 |
us-east-1 |
OW-03 |
OWASP LLM03: Imported-Model KMS Provenance
|
Informational | N/A |
111122223333 |
us-east-1 |
OW-10 |
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-32: No CloudWatch alarms are configured on Amazon Bedrock runtime metrics (AWS/Bedrock namespace). Without alarms, abuse, denial-of-wallet, sustained throttling, and content-filter spikes can go undetected. Resolution
Create CloudWatch alarms on Bedrock InvocationThrottles, InputTokenCount, OutputTokenCount, and EstimatedTPMQuotaUsage. |
Medium | Failed |
111122223333 |
us-east-1 |
OW-03 |
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check BR-33: Amazon Inspector Lambda scanning is not fully enabled in us-east-1. Lambda standard scan status: ENABLED. Lambda code scan status: DISABLED. Detected 8 Lambda function(s) with Bedrock indicators: ClaudeCoworkEnvironment-BedrockApiKeyLambda-pPWYTtBWqHtH, aiml-security-aiml-security-111122223333-BedrockAssessment, gateway_lambda, myAskMeAnything, resco-aiml-BedrockAssessment (and 3 more). Without both scan types enabled, vulnerable dependencies and hardcoded secrets in these in-scope functions will not be detected. Resolution
Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain. |
Medium | Failed |
111122223333 |
us-east-1 |
OW-01 |
OWASP LLM01: Preventive Prompt Attack Filter
|
Informational | N/A |
111122223333 |
us-east-1 |
OW-02 |
OWASP LLM02: Bedrock Data Retention Boundary
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check BR-37: Bedrock account data retention is inherit; this does not establish an explicit account-level zero-data-retention setting. Resolution
Configure Bedrock account data retention as none and disable provider data sharing when prompts or responses may contain sensitive information. |
High | Failed |
111122223333 |
us-east-1 |
OW-02 |
OWASP LLM02: Automated Reasoning Policy Encryption
Details and remediation |
Informational | N/A |
111122223333 |
us-east-1 |
OW-03 |
OWASP LLM03: Marketplace Endpoint VPC Isolation
Details and remediation |
Informational | N/A |
111122223333 |
us-east-1 |
OW-02 |
OWASP LLM02: Marketplace Endpoint CMK Encryption
|
Informational | N/A |
111122223333 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Internet Exposure
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-01: SageMaker domain 'd-cz8qi7j81si3' (QuickSetupDomain-20250525T153160) is not configured for VPC-only access Resolution
Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths. |
High | Failed |
111122223333 |
us-east-1 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: Domain 'QuickSetupDomain-20250525T153160' - No KMS key configured Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
High | Failed |
111122223333 |
us-east-1 |
OW-01 |
OWASP LLM01: GuardDuty AI Protection
|
High | Failed |
111122223333 |
us-east-1 |
OW-10 |
OWASP LLM10: GuardDuty AI Protection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check SM-26: GuardDuty is enabled, but the AI Protection detector feature is not enabled. Resolution
Enable the GuardDuty AI_PROTECTION detector feature to detect supported anomalous model invocation and cost-harvesting activity. |
High | Failed |
111122223333 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Clarify Evaluation
|
Informational | N/A |
111122223333 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation |
Informational | N/A |
111122223333 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Model Monitor Coverage
|
Informational | N/A |
111122223333 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Notebook VPC Deployment
|
Informational | N/A |
111122223333 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Model Network Isolation
|
Informational | N/A |
111122223333 |
us-east-1 |
OW-10 |
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation |
Informational | N/A |
111122223333 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Container Repository Access
Details and remediation |
Informational | N/A |
111122223333 |
us-east-1 |
OW-02 |
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation |
Informational | N/A |
111122223333 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker AutoML Network Isolation
|
Informational | N/A |
111122223333 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically. |
Informational | N/A |
111122223333 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release. |
Informational | N/A |
111122223333 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
111122223333 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
111122223333 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain. |
Informational | N/A |
111122223333 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated. |
Informational | N/A |
111122223333 |
us-east-1 |
OW-02 |
OWASP LLM02: HyperPod Volume CMK Encryption
Details and remediation |
Informational | N/A |
111122223333 |
us-east-1 |
OW-03 |
OWASP LLM03: HyperPod VPC Boundary
Details and remediation |
Informational | N/A |
111122223333 |
us-east-1 |
OW-03 |
OWASP LLM03: Model Registry Resource Policy Boundary
|
Informational | N/A |
111122223333 |
Global |
OW-06 |
OWASP LLM06: AgentCore IAM Least Privilege
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check AC-02: The following roles have AgentCore full-access policies: AmazonSageMaker-ExecutionRole-20250525T153161, ClaudeCodeWorkshop-CodeEditorInstanceBootstrapRole-GWdiq3M0J6tF Resolution
Remove AmazonBedrockAgentCoreFullAccess (or equivalents) from identities that only need read/execute permissions. |
High | Failed |
111122223333 |
Global |
OW-06 |
OWASP LLM06: AgentCore IAM Least Privilege
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check AC-02: The following roles have wildcard or allow-except AgentCore permissions on all resources: AmazonSageMaker-ExecutionRole-20250525T153161, agentcore-wildrydes_gateway_role_ab3991f6-role Resolution
Remove AmazonBedrockAgentCoreFullAccess (or equivalents) from identities that only need read/execute permissions. |
High | Failed |
111122223333 |
us-east-1 |
OW-06 |
OWASP LLM06: AgentCore Resource-Based Policies
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check AC-10: The following AgentCore resources do not have resource-based policies: Runtime 'origami_expeditions', Runtime 'neoCyan_Agent', Runtime 'customer_support_agent', Runtime 'cdk_agent_core', Runtime 'awsapimcpserver' and 3 more. Without RBPs, access control relies solely on identity-based policies. Resolution
Attach resource-based policies to AgentCore runtimes and gateways so caller identities are constrained. |
High | Failed |
111122223333 |
us-east-1 |
OW-02 |
OWASP LLM02: AgentCore Token Vault CMK Encryption
Details and remediation |
High | Failed |
111122223333 |
us-east-1 |
OW-06 |
OWASP LLM06: Code Interpreter Network Isolation
|
Informational | N/A |
111122223333 |
us-east-1 |
OW-06 |
OWASP LLM06: Browser Tool Network Isolation
|
Informational | N/A |
111122223333 |
Global |
OW-10 |
OWASP LLM10: WAF Rate-Based & Shield Protection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-01: AWS Shield Advanced is not subscribed. GenAI API endpoints are vulnerable to volumetric DDoS attacks that can exhaust token quotas and inflate costs. Resolution
Add a WAF RateBasedStatement plus a SizeConstraintStatement on the GenAI ingress and subscribe to AWS Shield Advanced. |
Low | Failed |
111122223333 |
Global |
OW-10 |
OWASP LLM10: WAF Rate-Based & Shield Protection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-01: No AWS WAF regional Web ACLs found. Without WAF, GenAI endpoints lack rate-based rules to block abusive callers. Resolution
Add a WAF RateBasedStatement plus a SizeConstraintStatement on the GenAI ingress and subscribe to AWS Shield Advanced. |
Medium | Failed |
111122223333 |
Global |
OW-10 |
OWASP LLM10: API Gateway Usage Plans
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-02: Usage plans without throttling: myAskMeAnything-UsagePlan. Unbounded API calls can exhaust Bedrock token quotas and inflate costs. Resolution
Attach API Gateway Usage Plans with non-zero rateLimit / burstLimit to any REST APIs that proxy Bedrock. |
Medium | Failed |
111122223333 |
Global |
OW-10 |
OWASP LLM10: Bedrock TPM/RPM Quotas Customised
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-03: Found 266 Bedrock token-based quota(s); at least one applied value exceeds the AWS default, indicating quotas have been reviewed and raised. Resolution
Customise Bedrock service quotas above the account default so consumption is explicitly bounded. |
Medium | Passed |
111122223333 |
Global |
OW-10 |
OWASP LLM10: Cost Anomaly Detection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-04: No AWS Cost Anomaly Detection monitors found. Unexpected spikes in Bedrock/SageMaker usage (e.g., from prompt injection loops) will go undetected. Resolution
Configure AWS Cost Anomaly Detection monitors that include Bedrock and SageMaker. |
Medium | Failed |
111122223333 |
Global |
OW-10 |
OWASP LLM10: Token / Throttle Alarms
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-05: No CloudWatch alarms found for Bedrock metrics. Token exhaustion and throttling events will not trigger operational alerts. Resolution
Create CloudWatch alarms on the Bedrock namespace for InvocationThrottles and token counters. |
Medium | Failed |
111122223333 |
Global |
OW-10 |
OWASP LLM10: AWS Budgets with Bedrock Filters
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-06: No AWS Budgets found scoped to Bedrock or SageMaker. Unbounded GenAI spend can go undetected until the monthly bill. Resolution
Configure AWS Budgets with FilterExpression / CostFilters targeting Bedrock or SageMaker spend, with an alerting SNS action. |
Medium | Failed |
111122223333 |
Global |
OW-06 |
OWASP LLM06: Agent Execution Role Least Privilege
|
Informational | N/A |
111122223333 |
Global |
OW-06 |
OWASP LLM06: AgentCore Gateway Policy Engine
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check FS-08: Runtimes with no authorizerConfiguration: origami_expeditions, neoCyan_Agent, cdk_agent_core, awsapimcpserver. Requests to these runtime endpoints are not gated by an inbound authorizer. Inbound authorizer presence does not prove tool-level authorization; review authorizer and policy semantics manually. Resolution
Set AgentCore Gateway policyEngineConfiguration.mode to ENFORCE and require identity propagation on Runtimes. |
High | Failed |
111122223333 |
Global |
OW-06 |
OWASP LLM06: AgentCore Gateway Policy Engine
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check FS-08: 1 of 5 runtime(s) have an authorizerConfiguration: customer_support_agent. Inbound authorizer presence does not prove tool-level authorization; review authorizer and policy semantics manually. Resolution
Set AgentCore Gateway policyEngineConfiguration.mode to ENFORCE and require identity propagation on Runtimes. |
High | Passed |
111122223333 |
Global |
OW-06 |
OWASP LLM06: Agent Tool Concurrency Limits
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check FS-09: Agent-related Lambda functions without reserved concurrency: resco-aiml-IAMPermissionCaching, aiml-security-aiml-security-111122223333-OWASPAssessment, aiml-security-aiml-security-111122223333-SagemakerAssessment, resco-aiml-CleanupBucket, aiml-security-aiml-security-111122223333-BedrockAssessment, resco-aiml-BedrockAssessment, ClaudeCoworkEnvironment-BedrockApiKeyLambda-pPWYTtBWqHtH, aiml-security-aiml-security-111122223333-CleanupBucket, aiml-security-aiml-security-111122223333-AgentCoreAssessment, e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk. Unlimited concurrency allows runaway agent loops to exhaust account limits. Resolution
Set reserved concurrency on agent action-group Lambdas so a runaway agent cannot exhaust downstream capacity. |
Medium | Failed |
111122223333 |
Global |
OW-06 |
OWASP LLM06: Human-in-the-Loop Callback States
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check FS-10: No Step Functions state machines with agent/approval naming found. Verify that high-risk agent actions (e.g., fund transfers, account changes) have human approval gates. Resolution
Insert Step Functions .waitForTaskToken callback states before any high-risk agent-triggered action. |
Informational | N/A |
111122223333 |
Global |
OW-03 |
OWASP LLM03: SCP-Enforced Model Allowlist
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check FS-12: No Service Control Policies reference Bedrock. Without SCPs, any account in the organization can access any Bedrock model, including unapproved third-party models. Resolution
Attach an Organizations SCP that denies Bedrock inference outside allowlisted model and inference-profile ARNs using Resource or NotResource scoping. |
High | Failed |
111122223333 |
Global |
OW-03 |
OWASP LLM03: Custom-Model Provenance Tags
|
Medium | Passed |
111122223333 |
Global |
OW-03 |
OWASP LLM03: Config Rules for Model Onboarding
|
Medium | Passed |
111122223333 |
Global |
OW-03 |
OWASP LLM03: Adversarial Evaluation Coverage
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check FS-15: No Bedrock Model Evaluation jobs found. Models have not been evaluated for adversarial robustness. Model-risk management (SR 11-7) expects documented model validation/evaluation. Resolution
Run Bedrock evaluation jobs that include adversarial and safety datasets before promoting a model to production. |
Medium | Failed |
111122223333 |
Global |
OW-03 |
OWASP LLM03: ECR Image Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check FS-16: Amazon Inspector enhanced scanning for ECR is ENABLED account-wide, so all 5 repository(ies) are continuously scanned. 4 repository(ies) do not set scan-on-push (bedrock-agentcore-customer_support_agent, bedrock-agentcore-origami_expeditions, cdk-hnb659fds-container-assets-111122223333-us-east-1, mlexplorationrepo), which is expected when enhanced scanning supersedes basic scanning. Resolution
Enable Amazon Inspector enhanced scanning or scan-on-push on ECR repositories that hold model / agent container images. |
High | Passed |
111122223333 |
Global |
OW-04 |
OWASP LLM04: Feature Store Offline Recovery
Details and remediation |
Informational | N/A |
111122223333 |
Global |
OW-04 |
OWASP LLM04: Training-Data Versioning
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check FS-21: 13 training data bucket(s) without versioning: ancbedrocklogging, bedrock-agentcore-codebuild-sources-111122223333-us-east-1, bedrock-bda-us-east-1-dda43109-6557-48bb-993d-3f97126b64b4, bedrock-bda-us-east-1-logging-00719114-debd-4487-85d1-09cbc3fc8, bedrock-kb-bucket-f736570b, bedrock-video-generation-us-east-1-h5ltpm, fsi-genai-workshop-bedrock-datasources-111122223333-us-west-2, knowledgebase-bedrock-agent-agasthik, llmevaluationpromptfoo-bedrockkb-cozhbzbrcmd2, sagemaker-studio-111122223333-huo1mvme4t. Resolution
Enable S3 versioning on training-data buckets so poisoned data can be reverted. |
High | Failed |
111122223333 |
Global |
OW-08 |
OWASP LLM08: KB IAM Scope
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-22: 876 role(s) with wildcard KB permissions: - Role '111122223333-us-east-1-kb-setup-function-role' allows 'bedrock:CreateKnowledgeBase' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role '111122223333-us-east-1-kb-setup-function-role' allows 'bedrock:CreateDataSource' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'Admin' allows '*' - Role 'agentcore-wildrydes_gateway_role_ab3991f6-role' allows 'bedrock:*' - Role 'AgentCoreEvalsSDK-us-east-1-d04ba7b68b' allows 'bedrock:InvokeModel' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'AgentCoreEvalsSDK-us-east-1-d04ba7b68b' allows 'bedrock:InvokeModelWithResponseStream' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'Agentic-AI-MCP-Strands-SDK-Works-VSCodeInstanceRole-NCTUnlnRBFO6' allows '*' - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:ListGuardrails' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:GetGuardrail' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:ListModelInvocationJobs' on Resource '*' (no ARN scoping to specific Knowledge Bases) Resolution
Scope Knowledge Base IAM roles to specific KB ARNs; remove wildcard bedrock:* on KB actions. |
High | Failed |
111122223333 |
Global |
OW-08 |
OWASP LLM08: KB Metadata Filtering
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-24: Found 3 Knowledge Base(s). Tenant-isolation metadata filtering is a design pattern that cannot be verified via API — manual review required. Verify that metadata attributes (e.g., tenantId, classification) are indexed and that Retrieve calls include RetrievalFilter conditions for tenant isolation. Resolution
Define Knowledge Base metadata fields so tenant / document-level filtering can be applied at retrieval time. |
Informational | N/A |
111122223333 |
Global |
OW-08 |
OWASP LLM08: OpenSearch Serverless Encryption
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-25: 4 of 4 collection(s) are encrypted with an AWS-owned key (kmsKeyArn="auto"): bedrock-knowledge-base-d8pbz4, bedrock-knowledge-base-i3rcye, bedrock-knowledge-base-oca5yg, e2e-rag-collection. Financial-services data-protection controls typically require a customer-managed KMS key for key lifecycle control and auditability. Resolution
Use a customer-managed KMS key on the OpenSearch Serverless encryption policy for the vector collection. |
High | Failed |
111122223333 |
Global |
OW-08 |
OWASP LLM08: OpenSearch Serverless Network Policy
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-26: Found 5 network policy(ies) but none restrict to VPC. Vector stores may be accessible from the public internet. Resolution
Set AllowFromPublic=false on the OpenSearch Serverless network policy and restrict access to bedrock.amazonaws.com or a specific VPC endpoint. |
High | Failed |
111122223333 |
Global |
OW-09 |
OWASP LLM09: Knowledge-Base Ingestion Freshness
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check FS-31: 2 data source(s) not synced in >7 days (a configurable review threshold, NOT an AWS-mandated limit): - KB 'knowledge-base-semiconductors' source 'knowledge-base-quick-start-qpvuv-data-source' last completed ingestion 732 days ago - KB '111122223333-us-east-1-kb' source '111122223333-us-east-1-kb-datasource' last completed ingestion 255 days ago Confirm this age is acceptable for each data source's currency requirement — slow-changing reference data may legitimately sync infrequently. Resolution
Sync Knowledge Base data sources on a schedule (weekly at most); stale KB content increases hallucination risk. |
Medium | Failed |
111122223333 |
Global |
OW-09 |
OWASP LLM09: Source Attribution
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check FS-32: Source attribution in GenAI responses cannot be verified via AWS APIs. Manual review required to confirm responses include citations. Resolution
Return citations in RetrieveAndGenerate responses so end users can verify grounding. |
Informational | N/A |
111122223333 |
Global |
OW-09 |
OWASP LLM09: KB S3 Data-Source Integrity
Details and remediation |
Medium | Failed |
111122223333 |
Global |
OW-04 |
OWASP LLM04: SageMaker Model Card Documentation
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check FS-42: No SageMaker Model Cards found. If GenAI workloads run on Bedrock rather than SageMaker, model documentation may legitimately live elsewhere; Model Cards are a SageMaker-specific artifact. Resolution
Create SageMaker Model Cards for production models that document intended use, training data provenance, and bias/fairness evaluations so poisoned or drifted models are detectable against a documented baseline. |
Informational | N/A |
111122223333 |
Global |
OW-09 |
OWASP LLM09: SageMaker Model Card Documentation
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check FS-42: No SageMaker Model Cards found. If GenAI workloads run on Bedrock rather than SageMaker, model documentation may legitimately live elsewhere; Model Cards are a SageMaker-specific artifact. Resolution
Document each production model's intended use, known limitations, and evaluation results in a SageMaker Model Card so misinformation risks tied to model behaviour are traceable to a reviewed system card. |
Informational | N/A |
111122223333 |
Global |
OW-02 |
OWASP LLM02: CloudWatch Log Data Protection Policies
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-43: Bedrock model invocation logging is not enabled, so no invocation logs are being delivered and there is no log content to mask. Prompt and completion content is therefore also unavailable for audit. Resolution
Apply a CloudWatch Logs data protection policy to log groups that receive Bedrock invocation logs. |
Informational | N/A |
111122223333 |
Global |
OW-02 |
OWASP LLM02: Macie Sensitive-Data Discovery
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-44: Amazon Macie is enabled, but the automated sensitive data discovery status could not be read (AccessDeniedException), so whether anything is actually being scanned is unknown. Resolution
Enable Amazon Macie with automated discovery on S3 buckets that hold training or knowledge-base data. |
Informational | N/A |
111122223333 |
Global |
OW-02 |
OWASP LLM02: Guardrail PII Entities Coverage
|
Informational | N/A |
111122223333 |
Global |
OW-02 |
OWASP LLM02: S3 Data-Classification Tagging
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-46: 18 AI/ML bucket(s) without data-classification tags: 111122223333-us-east-1-kb-data-bucket, ancbedrocklogging, ancknowledgebase, aws-streaming-data-solut-outputaccesslogsbucket8b-1o7m0kb4bafm4, bedrock-agentcore-codebuild-sources-111122223333-us-east-1, bedrock-bda-us-east-1-dda43109-6557-48bb-993d-3f97126b64b4, bedrock-bda-us-east-1-logging-00719114-debd-4487-85d1-09cbc3fc8, bedrock-kb-bucket-f736570b, bedrock-video-generation-us-east-1-h5ltpm, create-customer-resources-kb-bucket-111122223333. Resolution
Tag training and knowledge-base S3 buckets with a data-classification tag so downstream automations enforce controls consistent with the sensitivity level. |
Medium | Failed |
111122223333 |
Global |
OW-09 |
OWASP LLM09: Grounding Filter Threshold
|
Informational | N/A |
111122223333 |
Global |
OW-09 |
OWASP LLM09: Active Knowledge Base Present
|
Medium | Passed |
111122223333 |
Global |
OW-01 |
OWASP LLM01: PROMPT_ATTACK Filter at Standard Tier
|
Informational | N/A |
111122223333 |
Global |
OW-01 |
OWASP LLM01: Bedrock-Calling Lambda Runtimes
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check FS-52: Functions on deprecated runtimes: e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk, e2ebedrockrag-OSSInfraSta-OSSIndexCreationProvider-g56en9UzRjII. Deprecated runtimes may use outdated boto3/SDK versions lacking security patches. Resolution
Ensure Lambda functions that invoke Bedrock use a supported (non-deprecated) runtime to receive security patches. |
Medium | Failed |
111122223333 |
Global |
OW-01 |
OWASP LLM01: WAF SQLi & KnownBadInputs Coverage
|
Informational | N/A |
111122223333 |
Global |
OW-01 |
OWASP LLM01: Adversarial Testing Evidence
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check FS-54: Penetration testing evidence cannot be verified via AWS APIs. Manual review required to confirm GenAI applications have been tested. Resolution
Track adversarial / red-team penetration test evidence for the GenAI application via resource tags or an equivalent audit trail. |
Informational | N/A |
111122223333 |
Global |
OW-05 |
OWASP LLM05: Output-Validation Lambda
Details and remediationDetails
OWASP category: LLM05:2025 Improper Output Handling. Source check FS-55: No Lambda functions with output validation/sanitization naming found. GenAI outputs may be passed directly to downstream systems without validation. Resolution
Deploy an output-validation / sanitisation Lambda between the model response and any downstream consumer to filter injection payloads in generated output. |
Medium | Failed |
111122223333 |
Global |
OW-05 |
OWASP LLM05: WAF XSS Protection
|
Informational | N/A |
111122223333 |
Global |
OW-05 |
OWASP LLM05: Output Encoding Libraries
Details and remediationDetails
OWASP category: LLM05:2025 Improper Output Handling. Source check FS-57: Output encoding practices cannot be verified via AWS APIs. Manual code review required. Resolution
Ensure Lambdas that render model output use a well-known output-encoding library appropriate to the downstream sink (HTML, SQL, shell, etc.). |
Informational | N/A |
111122223333 |
Global |
OW-05 |
OWASP LLM05: Step Functions Output Schema Validation
Details and remediationDetails
OWASP category: LLM05:2025 Improper Output Handling. Source check FS-58: Found 0 Lambda function(s) whose names suggest schema/validation handling. Structured-output / JSON-schema validation of GenAI responses is an application-layer control that cannot be verified automatically — manual review required. Resolution
Add explicit schema-validation states in Step Functions workflows that consume model output. |
Informational | N/A |
111122223333 |
Global |
OW-06 |
OWASP LLM06: Agent Transaction Thresholds
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check FS-67: The following agent action-group Lambda functions have no environment variables whose names suggest transaction-value threshold configuration (this is a best-effort heuristic — a threshold enforced in code or in an AgentCore Policy Engine rule would not be detected here, so treat this as a prompt for manual verification rather than a definitive gap). Without explicit limits, agents could initiate unbounded financial transactions: - resco-aiml-BedrockAssessment - ClaudeCoworkEnvironment-BedrockApiKeyLambda-pPWYTtBWqHtH - e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk - e2ebedrockrag-OSSInfraSta-OSSIndexCreationProvider-g56en9UzRjII - ClaudeCodeWorkshop-BedrockAccessLambda-b9a4xULBNrlV - resco-aiml-AgentCoreAssessment Resolution
Encode agent transaction thresholds in Cedar policies or Lambda configuration so per-action limits are enforced. |
High | Failed |
111122223333 |
Global |
OW-10 |
OWASP LLM10: API Gateway Request Body Size Limits
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-68: Found 3 REST API(s) and 0 regional WAF Web ACL(s), but none enforce a maximum request-body size. Note: an API Gateway request validator does NOT cap body size (it validates the schema and required params; the REST limit is a fixed 10 MB), and a WAF body SizeConstraint only inspects the first ~16 KB of the body by default. Oversized prompts can exhaust Bedrock token quotas and inflate costs. Resolution
Configure API Gateway request validation or an equivalent ingress control so GenAI endpoints reject oversized request bodies before they can drive excessive model consumption. |
Medium | Failed |
111122223333 |
Global |
OW-01 |
OWASP LLM01: Prompt-Input Validation Lambda
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check FS-69: Found 3 Lambda function(s) with input validation/sanitization naming patterns: resco-aiml-CleanupBucket, visa-bulletin-tracker-prod-cleanup, aiml-security-aiml-security-111122223333-CleanupBucket. Resolution
Deploy a prompt-input validation Lambda in front of Bedrock invocations to sanitise untrusted input before it reaches the model. |
Medium | Passed |
111122223333 |
us-east-1 |
OW-11 |
OWASP LLM07: System Prompt Embedded in Lambda Env Var
|
Medium | Passed |
111122223333 |
us-east-1 |
OW-12 |
OWASP LLM07: System-Prompt-Disclosure Denied Topic
|
Informational | N/A |
111122223333 |
us-west-2 |
AR-03 |
AWS Agent Registry Publication Approval Governance
|
Informational | N/A |
111122223333 |
us-west-2 |
AR-04 |
AWS Agent Registry Discovery Authorization
|
Informational | N/A |
111122223333 |
us-west-2 |
AR-05 |
AWS Agent Registry Customer-Managed KMS Encryption
|
Informational | N/A |
111122223333 |
us-west-2 |
AR-06 |
AWS Agent Registry Organization Auto-Detection
|
Informational | N/A |
111122223333 |
us-west-2 |
AR-07 |
AWS Agent Registry Record Lifecycle Governance
|
Informational | N/A |
111122223333 |
us-west-2 |
AR-08 |
AWS Agent Registry Record Provenance
|
Informational | N/A |
111122223333 |
us-west-2 |
AG-33 |
Agentic AI Registry Publication Approval Governance
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry approval workflows control which agents, tools, and skills become discoverable to consumers. Source check AR-03: No AWS Agent Registry registries found. Resolution
Require manual review for registry publication where organizational policy does not permit automatic approval. |
Informational | N/A |
111122223333 |
us-west-2 |
AG-34 |
Agentic AI Registry Discovery Authorization
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry discovery authorization requires review against intended callers and effective access boundaries. Source check AR-04: No AWS Agent Registry registries found. Resolution
Review effective IAM access or compare custom JWT audiences, clients, scopes, and claims with approved registry consumers. |
Informational | N/A |
111122223333 |
us-west-2 |
AG-35 |
Agentic AI Registry Metadata Encryption
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Registry records can contain agent, tool, endpoint, and ownership metadata that benefits from customer-controlled encryption. Source check AR-05: No AWS Agent Registry registries found. Resolution
Create the registry with a customer-managed KMS key when organizational policy requires customer-controlled encryption. |
Informational | N/A |
111122223333 |
us-west-2 |
AG-36 |
Agentic AI Organization Discovery Coverage
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Organization-wide auto-detection provides visibility into unmanaged agent resources. Source check AR-06: No AWS Agent Registry registries found. Resolution
Enable organization-scoped registry auto-detection where centralized discovery is required. |
Informational | N/A |
111122223333 |
us-west-2 |
AG-37 |
Agentic AI Registry Record Lifecycle Governance
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry lifecycle states provide operational visibility but do not independently prove a security control. Source check AR-07: No AWS Agent Registry registries found. Resolution
Review failed or unknown record lifecycle states operationally. |
Informational | N/A |
111122223333 |
us-west-2 |
AG-38 |
Agentic AI Registry Record Provenance
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Consumers need attributable record origin and source lineage to understand which account and resource produced an entry. Source check AR-08: No AWS Agent Registry registries found. Resolution
Ensure records retain creator attribution and auto-detected records retain source provenance. |
Informational | N/A |
111122223333 |
us-west-2 |
AC-01 |
AgentCore VPC Configuration Check
|
Informational | N/A |
111122223333 |
us-west-2 |
AC-04 |
AgentCore Observability Check
|
Informational | N/A |
111122223333 |
us-west-2 |
AC-05 |
AgentCore Encryption Check
|
Informational | N/A |
111122223333 |
us-west-2 |
AC-06 |
AgentCore Browser Session Recording
|
Informational | N/A |
111122223333 |
us-west-2 |
AC-07 |
AgentCore Memory Configuration Check
|
Informational | N/A |
111122223333 |
us-west-2 |
AC-13 |
AgentCore Gateway Configuration Check
|
Medium | Passed |
111122223333 |
us-west-2 |
AC-08 |
AgentCore VPC Endpoints Check
|
Informational | N/A |
111122223333 |
us-west-2 |
AC-10 |
AgentCore Resource-Based Policies Missing
Details and remediationDetails
The following AgentCore resources do not have resource-based policies: Gateway 'aws-news-mcp'. Without RBPs, access control relies solely on identity-based policies. Resolution
Attach resource-based policies to AgentCore resources to: 1. Implement defense-in-depth access control 2. Enable cross-account access control 3. Restrict access based on source VPC or IP 4. Implement hierarchical authorization for Agent Runtimes |
High | Failed |
111122223333 |
us-west-2 |
AC-11 |
AgentCore Policy Engine Encryption Check
|
Informational | N/A |
111122223333 |
us-west-2 |
AC-12 |
AgentCore Gateway Encryption Missing
Details and remediationDetails
The following Gateways do not use customer-managed KMS encryption: 'aws-news-mcp'. Gateway configuration data uses AWS-managed keys. Resolution
1. Create gateways with customer-managed KMS keys for additional control 2. AWS-managed keys are single-tenant and region-specific 3. Consider CMK for enhanced audit capabilities and key rotation control |
Low | Failed |
111122223333 |
us-west-2 |
AC-14 |
AgentCore Identity Token Vault CMK Encryption
|
High | Failed |
111122223333 |
us-west-2 |
AC-15 |
AgentCore Code Interpreter Network Isolation
|
Informational | N/A |
111122223333 |
us-west-2 |
AC-16 |
AgentCore Custom Browser Network Isolation
|
Informational | N/A |
111122223333 |
us-west-2 |
AC-17 |
AgentCore Online Evaluation Coverage
|
Medium | Failed |
111122223333 |
us-west-2 |
AG-24 |
Agentic AI Gateway Inbound Authorization
|
High | Passed |
111122223333 |
us-west-2 |
AG-25 |
Agentic AI Gateway Tool Policy Enforcement Missing
Details and remediation |
High | Failed |
111122223333 |
us-west-2 |
AG-26 |
Agentic AI Gateway Error Detail Exposure
|
Medium | Passed |
111122223333 |
us-west-2 |
AG-27 |
Agentic AI Gateway WAF Protection Missing
|
Low | Failed |
111122223333 |
us-west-2 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
Informational | N/A |
111122223333 |
us-west-2 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Informational | N/A |
111122223333 |
us-west-2 |
AG-19 |
Agentic AI Memory Data Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found Resolution
Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions. |
Informational | N/A |
111122223333 |
us-west-2 |
AG-20 |
Agentic AI Private AgentCore Connectivity
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found Resolution
Create required VPC endpoints for AgentCore services and validate endpoint availability. |
Informational | N/A |
111122223333 |
us-west-2 |
AG-21 |
Agentic AI Resource Policy Boundary
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: The following AgentCore resources do not have resource-based policies: Gateway 'aws-news-mcp'. Without RBPs, access control relies solely on identity-based policies. Resolution
Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources. |
High | Failed |
111122223333 |
us-west-2 |
AG-22 |
Agentic AI Policy Engine Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found Resolution
Configure policy engines with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
111122223333 |
us-west-2 |
AG-23 |
Agentic AI Gateway Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: The following Gateways do not use customer-managed KMS encryption: 'aws-news-mcp'. Gateway configuration data uses AWS-managed keys. Resolution
Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required. |
Low | Failed |
111122223333 |
us-west-2 |
AG-28 |
Agentic AI Identity Token Vault Protection
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Agent credentials stored in the Identity token vault should use customer-controlled encryption where enhanced key control is required. Source check AC-14: AgentCore token vault 'default' uses a service-managed or AWS-owned key. Resolution
Configure the AgentCore Identity token vault with a customer-managed KMS key. |
High | Failed |
111122223333 |
us-west-2 |
AG-29 |
Agentic AI Code Interpreter Isolation
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent-executed code should run inside an explicit VPC boundary with controlled network paths. Source check AC-15: No custom AgentCore Code Interpreters found Resolution
Configure custom AgentCore Code Interpreters in VPC mode with approved subnets and security groups. |
Informational | N/A |
111122223333 |
us-west-2 |
AG-31 |
Agentic AI Browser Tool Isolation
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Browser tools can reach external systems and should use explicit private network boundaries. Source check AC-16: No custom AgentCore browsers found Resolution
Configure custom AgentCore browsers in VPC mode with approved subnets and security groups. |
Informational | N/A |
111122223333 |
us-west-2 |
AG-32 |
Agentic AI Online Evaluation Assurance
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Online evaluation provides continuous evidence about agent behavior, quality, and policy-relevant outcomes. Source check AC-17: No AgentCore online evaluation configurations found. Resolution
Configure an active AgentCore online evaluation with sampling, evaluators, CloudWatch input logs, and an output log group. |
Medium | Failed |
111122223333 |
Global |
FS-01 |
AWS Shield Advanced Not Enabled
Details and remediationDetails
AWS Shield Advanced is not subscribed. GenAI API endpoints are vulnerable to volumetric DDoS attacks that can exhaust token quotas and inflate costs. Resolution
1. Subscribe to AWS Shield Advanced for DDoS protection. 2. After subscribing, explicitly add resource protections in the Shield Advanced console for each Bedrock-facing resource (API Gateway stages, ALBs, CloudFront distributions, Route 53 hosted zones). Shield Advanced subscription alone does NOT automatically protect resources — each resource must be individually added to receive protection. 3. Enable Shield Response Team (SRT) access and configure proactive engagement. 4. Alternatively, use AWS Firewall Manager with a Shield Advanced policy to automate resource protection based on tags or resource types. |
Low | Failed |
111122223333 |
Global |
FS-01 |
No Regional WAF Web ACLs Found
Details and remediationDetails
No AWS WAF regional Web ACLs found. Without WAF, GenAI endpoints lack rate-based rules to block abusive callers. Resolution
1. Create a WAF Web ACL with rate-based rules (e.g., 1000 req/5 min per IP). 2. Associate the ACL with API Gateway stages or ALBs fronting Bedrock. 3. Add AWS Managed Rules for known bad inputs. |
Medium | Failed |
111122223333 |
Global |
FS-02 |
API Gateway Usage Plans Missing Throttle
Details and remediation |
Medium | Failed |
111122223333 |
Global |
FS-03 |
Bedrock Token Quotas Customized
|
Medium | Passed |
111122223333 |
Global |
FS-04 |
No Cost Anomaly Detection Monitors
Details and remediationDetails
No AWS Cost Anomaly Detection monitors found. Unexpected spikes in Bedrock/SageMaker usage (e.g., from prompt injection loops) will go undetected. Resolution
1. Create a Cost Anomaly Detection monitor scoped to AWS/Bedrock and AWS/SageMaker. 2. Configure alert subscriptions (SNS/email) for anomalies above threshold. 3. Set daily spend budgets with AWS Budgets as a secondary control. |
Medium | Failed |
111122223333 |
Global |
FS-05 |
No Bedrock CloudWatch Alarms Found
Details and remediationDetails
No CloudWatch alarms found for Bedrock metrics. Token exhaustion and throttling events will not trigger operational alerts. Resolution
Create CloudWatch alarms for: - AWS/Bedrock InvocationThrottles (threshold > 0) - AWS/Bedrock TokensProcessed (threshold based on quota) - Custom application-level token counters via EMF |
Medium | Failed |
111122223333 |
Global |
FS-06 |
No AI/ML Service Budgets Configured
Details and remediationDetails
No AWS Budgets found scoped to Bedrock or SageMaker. Unbounded GenAI spend can go undetected until the monthly bill. Resolution
1. Create cost budgets for AWS Bedrock and SageMaker with 80%/100% alert thresholds. 2. Add SNS notifications to on-call channels. 3. Consider budget actions to apply IAM deny policies when thresholds are breached. |
Medium | Failed |
111122223333 |
Global |
FS-07 |
Agent Action Boundary Check
|
Informational | N/A |
111122223333 |
Global |
FS-08 |
AgentCore Runtimes Without Inbound Authorizer
Details and remediationDetails
Runtimes with no authorizerConfiguration: origami_expeditions, neoCyan_Agent, cdk_agent_core, awsapimcpserver. Requests to these runtime endpoints are not gated by an inbound authorizer. Inbound authorizer presence does not prove tool-level authorization; review authorizer and policy semantics manually. Resolution
Configure an inbound authorizer (for example a custom JWT authorizer) on each AgentCore runtime, and separately verify tool-level authorization policies. |
High | Failed |
111122223333 |
Global |
FS-08 |
AgentCore Runtimes With Inbound Authorizer Configured
|
High | Passed |
111122223333 |
Global |
FS-09 |
Agent Lambda Functions Without Concurrency Limits
Details and remediationDetails
Agent-related Lambda functions without reserved concurrency: resco-aiml-IAMPermissionCaching, aiml-security-aiml-security-111122223333-OWASPAssessment, aiml-security-aiml-security-111122223333-SagemakerAssessment, resco-aiml-CleanupBucket, aiml-security-aiml-security-111122223333-BedrockAssessment, resco-aiml-BedrockAssessment, ClaudeCoworkEnvironment-BedrockApiKeyLambda-pPWYTtBWqHtH, aiml-security-aiml-security-111122223333-CleanupBucket, aiml-security-aiml-security-111122223333-AgentCoreAssessment, e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk. Unlimited concurrency allows runaway agent loops to exhaust account limits. Resolution
1. Set reserved concurrency on agent Lambda functions. 2. Implement maximum iteration counts in agent orchestration logic. 3. Use Step Functions with MaxConcurrency and timeout states. 4. Add circuit-breaker patterns to agent tool invocations. |
Medium | Failed |
111122223333 |
Global |
FS-10 |
Human-in-the-Loop Check — No Agent Workflows Found
Details and remediationDetails
No Step Functions state machines with agent/approval naming found. Verify that high-risk agent actions (e.g., fund transfers, account changes) have human approval gates. Resolution
Implement Step Functions .waitForTaskToken patterns for high-risk agent actions. Route approval requests to human reviewers via SNS/SES/Slack. |
Informational | N/A |
111122223333 |
Global |
FS-11 |
No Agent Rate Alarms Found
Details and remediationDetails
No CloudWatch alarms found for agent invocation rates. Looping or runaway agents will not trigger operational alerts. Resolution
Create CloudWatch alarms on: - Bedrock agent invocation counts (threshold based on expected max) - Lambda invocation errors for agent functions - Step Functions execution failures and timeouts |
Medium | Failed |
111122223333 |
Global |
FS-12 |
No Bedrock-Scoped SCPs Found
Details and remediationDetails
No Service Control Policies reference Bedrock. Without SCPs, any account in the organization can access any Bedrock model, including unapproved third-party models. Resolution
1. Create an SCP that denies bedrock:InvokeModel, bedrock:InvokeModelWithResponseStream, and bedrock:CreateModelInvocationJob outside approved model access. 2. Use Resource or NotResource with approved foundation-model, custom-model, provisioned-model, and inference-profile ARNs to express the allowlist. 3. Maintain a model inventory and update the SCP when models are approved/retired. |
High | Failed |
111122223333 |
Global |
FS-13 |
Model Provenance Tags Present
|
Medium | Passed |
111122223333 |
Global |
FS-14 |
Model Governance Config Rules Present
|
Medium | Passed |
111122223333 |
Global |
FS-15 |
No Bedrock Evaluation Jobs Found
Details and remediationDetails
No Bedrock Model Evaluation jobs found. Models have not been evaluated for adversarial robustness. Model-risk management (SR 11-7) expects documented model validation/evaluation. Resolution
1. Run Bedrock Model Evaluation with adversarial/red-team datasets. 2. Use FMEval library for automated robustness testing. 3. Schedule periodic re-evaluation after model updates. |
Medium | Failed |
111122223333 |
Global |
FS-16 |
ECR Image Scanning Covered by Inspector Enhanced Scanning
Details and remediationDetails
Amazon Inspector enhanced scanning for ECR is ENABLED account-wide, so all 5 repository(ies) are continuously scanned. 4 repository(ies) do not set scan-on-push (bedrock-agentcore-customer_support_agent, bedrock-agentcore-origami_expeditions, cdk-hnb659fds-container-assets-111122223333-us-east-1, mlexplorationrepo), which is expected when enhanced scanning supersedes basic scanning. Resolution
No action required while Inspector enhanced scanning stays enabled. If it is disabled, enable scan-on-push per repository. |
High | Passed |
111122223333 |
Global |
FS-20 |
No SageMaker Feature Groups Found
|
Informational | N/A |
111122223333 |
Global |
FS-21 |
Training Data Buckets Without Versioning
Details and remediationDetails
13 training data bucket(s) without versioning: ancbedrocklogging, bedrock-agentcore-codebuild-sources-111122223333-us-east-1, bedrock-bda-us-east-1-dda43109-6557-48bb-993d-3f97126b64b4, bedrock-bda-us-east-1-logging-00719114-debd-4487-85d1-09cbc3fc8, bedrock-kb-bucket-f736570b, bedrock-video-generation-us-east-1-h5ltpm, fsi-genai-workshop-bedrock-datasources-111122223333-us-west-2, knowledgebase-bedrock-agent-agasthik, llmevaluationpromptfoo-bedrockkb-cozhbzbrcmd2, sagemaker-studio-111122223333-huo1mvme4t. Resolution
Enable S3 versioning on all training data buckets. Consider enabling MFA Delete for additional protection against poisoning. |
High | Failed |
111122223333 |
Global |
FS-22 |
Overly Permissive Knowledge Base IAM Roles
Details and remediationDetails
876 role(s) with wildcard KB permissions: - Role '111122223333-us-east-1-kb-setup-function-role' allows 'bedrock:CreateKnowledgeBase' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role '111122223333-us-east-1-kb-setup-function-role' allows 'bedrock:CreateDataSource' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'Admin' allows '*' - Role 'agentcore-wildrydes_gateway_role_ab3991f6-role' allows 'bedrock:*' - Role 'AgentCoreEvalsSDK-us-east-1-d04ba7b68b' allows 'bedrock:InvokeModel' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'AgentCoreEvalsSDK-us-east-1-d04ba7b68b' allows 'bedrock:InvokeModelWithResponseStream' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'Agentic-AI-MCP-Strands-SDK-Works-VSCodeInstanceRole-NCTUnlnRBFO6' allows '*' - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:ListGuardrails' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:GetGuardrail' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:ListModelInvocationJobs' on Resource '*' (no ARN scoping to specific Knowledge Bases) Resolution
Replace wildcard bedrock:* with specific actions such as bedrock:Retrieve, bedrock:RetrieveAndGenerate. Scope resources to specific Knowledge Base ARNs. |
High | Failed |
111122223333 |
Global |
FS-24 |
ADVISORY: Knowledge Base Metadata Filtering — Manual Review Required
Details and remediationDetails
Found 3 Knowledge Base(s). Tenant-isolation metadata filtering is a design pattern that cannot be verified via API — manual review required. Verify that metadata attributes (e.g., tenantId, classification) are indexed and that Retrieve calls include RetrievalFilter conditions for tenant isolation. Resolution
1. Add metadata fields (tenantId, dataClassification) to KB data sources. 2. Pass RetrievalFilter in all Retrieve/RetrieveAndGenerate calls. 3. Validate filters in integration tests to prevent cross-tenant data leakage. |
Informational | N/A |
111122223333 |
Global |
FS-25 |
OpenSearch Serverless Collections Using AWS-Owned Encryption Keys
Details and remediationDetails
4 of 4 collection(s) are encrypted with an AWS-owned key (kmsKeyArn="auto"): bedrock-knowledge-base-d8pbz4, bedrock-knowledge-base-i3rcye, bedrock-knowledge-base-oca5yg, e2e-rag-collection. Financial-services data-protection controls typically require a customer-managed KMS key for key lifecycle control and auditability. Resolution
1. Create a customer-managed KMS key and grant aoss.amazonaws.com the required key permissions. 2. Create an encryption policy for the collection with AWSOwnedKey=false and KmsARN set to that key. 3. The encryption key is fixed at collection creation, so the collection must be recreated and re-indexed to change it. |
High | Failed |
111122223333 |
Global |
FS-26 |
OpenSearch Serverless Collections Not VPC-Restricted
|
High | Failed |
111122223333 |
Global |
FS-27 |
No Guardrails — Contextual Grounding Not Applicable
|
Informational | N/A |
111122223333 |
Global |
FS-27 |
No Automated Reasoning Policies Found
Details and remediationDetails
No Bedrock Automated Reasoning policies have been created. ARC (GA August 2025) uses formal verification to guarantee that GenAI outputs comply with authored business rules — e.g., loan criteria, regulatory thresholds, policy constraints. Without ARC policies, factual accuracy of outputs is not formally verified, only heuristically filtered by contextual grounding thresholds. Resolution
1. In the Amazon Bedrock console → Guardrails → Automated Reasoning, create a policy document encoding your business rules (e.g., eligibility criteria, rate limits, regulatory thresholds). 2. Associate the ARC policy with your guardrail (automatedReasoningPolicy.policies field in CreateGuardrail/UpdateGuardrail). 3. Set confidenceThreshold on the policy to control strictness. 4. ARC requires cross-Region inference — ensure your guardrail has a guardrailProfileArn configured (crossRegionDetails in GetGuardrail response). 5. Reference: AWS Announcement — Automated Reasoning checks GA (August 2025). |
Medium | Failed |
111122223333 |
Global |
FS-28 |
No Guardrails — Topic Policy Not Applicable
|
Informational | N/A |
111122223333 |
Global |
FS-29 |
ADVISORY: Compliance Disclaimer — Manual Review Required
Details and remediationDetails
Application-level compliance disclaimers cannot be verified via AWS APIs. Manual review required to confirm GenAI outputs include required regulatory disclosures. Resolution
1. Implement post-processing to append required disclaimers to GenAI outputs. 2. Use Bedrock Guardrails word filters to block outputs that omit required disclosures. 3. Document disclaimer requirements in the AI use case register. 4. Test disclaimer presence in QA/UAT before production deployment. |
Informational | N/A |
111122223333 |
Global |
FS-30 |
ADVISORY: Compliance Dataset Coverage — Manual Review Required
Details and remediationDetails
Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation jobs include compliance-specific datasets (fair lending/ECOA, Fair Housing Act, UDAP/UDAAP, AML/KYC edge cases). Whether any evaluation jobs exist at all is assessed by FS-15. Resolution
Run Bedrock Model Evaluation with compliance-specific datasets: - Fair lending test cases (ECOA, Fair Housing Act) - UDAP/UDAAP unfair/deceptive practice scenarios - AML/KYC edge cases |
Informational | N/A |
111122223333 |
Global |
FS-31 |
Knowledge Base Data Sources Past Review Threshold
Details and remediationDetails
2 data source(s) not synced in >7 days (a configurable review threshold, NOT an AWS-mandated limit): - KB 'knowledge-base-semiconductors' source 'knowledge-base-quick-start-qpvuv-data-source' last completed ingestion 732 days ago - KB '111122223333-us-east-1-kb' source '111122223333-us-east-1-kb-datasource' last completed ingestion 255 days ago Confirm this age is acceptable for each data source's currency requirement — slow-changing reference data may legitimately sync infrequently. Resolution
1. Define the maximum acceptable data age per use case (e.g., intraday for market data, daily for product terms, weekly/monthly for regulatory guidance) and adjust the review threshold to match. 2. Configure automated sync (EventBridge Scheduler → StartIngestionJob) at that cadence — see FS-61. 3. Set CloudWatch alarms on sync job failures. |
Medium | Failed |
111122223333 |
Global |
FS-32 |
ADVISORY: Source Attribution — Manual Review Required
Details and remediationDetails
Source attribution in GenAI responses cannot be verified via AWS APIs. Manual review required to confirm responses include citations. Resolution
1. Use Bedrock RetrieveAndGenerate with citations enabled. 2. Include source document references in response post-processing. 3. Test citation accuracy in QA before production deployment. 4. Consider Bedrock Guardrails grounding checks to validate response accuracy. |
Informational | N/A |
111122223333 |
Global |
FS-33 |
KB Data Source Buckets Without Versioning
|
Medium | Failed |
111122223333 |
Global |
FS-34 |
Legacy Foundation Models Available in Region
Details and remediationDetails
Legacy/deprecated foundation models are available in this account/region: anthropic.claude-sonnet-4-20250514-v1:0, twelvelabs.marengo-embed-2-7-v1:0, anthropic.claude-opus-4-1-20250805-v1:0, amazon.nova-premier-v1:0:8k, amazon.nova-premier-v1:0:20k, amazon.nova-premier-v1:0:1000k, amazon.nova-premier-v1:0:mm, amazon.nova-premier-v1:0, amazon.nova-canvas-v1:0, amazon.nova-reel-v1:0. This API reports model *availability*, not actual usage — it cannot determine which models your applications invoke. Legacy models have older training-data cutoffs and may produce outdated information if used. Review whether any are in active use. Resolution
1. Identify which (if any) of these legacy models your applications invoke (e.g., via CloudTrail InvokeModel events or application config). 2. Migrate active usage to current model versions. 3. Document training-data cutoff dates for all models in use. 4. Add data-currency disclaimers to outputs from models with old cutoffs. |
Informational | N/A |
111122223333 |
Global |
FS-35 |
ADVISORY: Harmful-Content Test Coverage — Manual Review Required
Details and remediationDetails
Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation/FMEval jobs include harmful-content datasets (toxicity, hate speech, violence/self-harm). Whether any evaluation jobs exist at all is assessed by FS-15. Resolution
Run Bedrock Model Evaluation or FMEval with harmful content datasets: - Toxicity detection - Hate speech classification - Violence/self-harm content |
Informational | N/A |
111122223333 |
Global |
FS-36 |
No Guardrails — Content Filters Not Applicable
|
Informational | N/A |
111122223333 |
Global |
FS-37 |
ADVISORY: User Feedback Mechanism — Manual Review Required
Details and remediationDetails
User feedback mechanisms for harmful outputs cannot be verified via AWS APIs. Manual review required. Resolution
1. Implement thumbs-up/down or flag-for-review UI in GenAI applications. 2. Route flagged outputs to human reviewers via SQS/SNS. 3. Log feedback to DynamoDB/S3 for model improvement. 4. Define SLAs for reviewing flagged content. |
Informational | N/A |
111122223333 |
Global |
FS-38 |
No Guardrails — Word Filters Not Applicable
|
Informational | N/A |
111122223333 |
Global |
FS-39 |
No SageMaker Clarify Bias Monitoring
Details and remediationDetails
No SageMaker Clarify model bias monitoring schedules found. Models making financial decisions (credit, insurance) may exhibit discriminatory bias without detection. Resolution
1. Configure SageMaker Clarify bias detection for all models making credit, insurance, or employment decisions. 2. Define protected attributes (age, gender, race proxies). 3. Set bias metric thresholds and alert on violations. 4. Document bias testing results for regulatory examination. |
High | Failed |
111122223333 |
Global |
FS-40 |
ADVISORY: Bias Dataset Coverage — Manual Review Required
Details and remediationDetails
Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation jobs include bias/fairness datasets (demographic parity, equal-opportunity, counterfactual fairness) for any GenAI models used in financial decisions (ECOA/Fair Housing). Whether any evaluation jobs exist at all is assessed by FS-15. Resolution
Run Bedrock Model Evaluation with bias test datasets: - Demographic parity test cases - Equal opportunity scenarios - Counterfactual fairness tests |
Informational | N/A |
111122223333 |
Global |
FS-41 |
No SageMaker Clarify Explainability Monitoring
Details and remediationDetails
No SageMaker Clarify explainability monitoring found. Models making adverse financial decisions may not provide required explanations (ECOA adverse action notices). Resolution
1. Configure SageMaker Clarify explainability for credit/lending models. 2. Generate SHAP values for feature importance. 3. Map top features to human-readable adverse action reason codes. 4. Store explanations for regulatory examination. |
High | Failed |
111122223333 |
Global |
FS-42 |
No SageMaker Model Cards Found
Details and remediationDetails
No SageMaker Model Cards found. If GenAI workloads run on Bedrock rather than SageMaker, model documentation may legitimately live elsewhere; Model Cards are a SageMaker-specific artifact. Resolution
1. For SageMaker models, create a Model Card documenting intended use, out-of-scope uses, training data and bias evaluations. 2. For Bedrock-only estates, record the equivalent documentation in your model-governance system and reference the AWS AI Service Cards. |
Informational | N/A |
111122223333 |
Global |
FS-43 |
Bedrock Invocation Logging Not Enabled
Details and remediationDetails
Bedrock model invocation logging is not enabled, so no invocation logs are being delivered and there is no log content to mask. Prompt and completion content is therefore also unavailable for audit. Resolution
1. Enable Bedrock model invocation logging. 2. If delivering to CloudWatch Logs, attach a data protection policy masking PII to the destination log group. |
Informational | N/A |
111122223333 |
Global |
FS-44 |
COULD NOT ASSESS: Macie Automated Discovery Status
Details and remediation |
Low | N/A |
111122223333 |
Global |
FS-45 |
No Guardrails — PII Filters Not Applicable
|
Informational | N/A |
111122223333 |
Global |
FS-46 |
AI/ML Buckets Without Data Classification Tags
Details and remediationDetails
18 AI/ML bucket(s) without data-classification tags: 111122223333-us-east-1-kb-data-bucket, ancbedrocklogging, ancknowledgebase, aws-streaming-data-solut-outputaccesslogsbucket8b-1o7m0kb4bafm4, bedrock-agentcore-codebuild-sources-111122223333-us-east-1, bedrock-bda-us-east-1-dda43109-6557-48bb-993d-3f97126b64b4, bedrock-bda-us-east-1-logging-00719114-debd-4487-85d1-09cbc3fc8, bedrock-kb-bucket-f736570b, bedrock-video-generation-us-east-1-h5ltpm, create-customer-resources-kb-bucket-111122223333. Resolution
Tag all AI/ML data buckets with 'data-classification' key. Values: Public, Internal, Confidential, Restricted. Enforce via SCP or AWS Config rule. |
Medium | Failed |
111122223333 |
Global |
FS-47 |
No Guardrails — Grounding Threshold Not Applicable
|
Informational | N/A |
111122223333 |
Global |
FS-48 |
Active Knowledge Bases for RAG Present
|
Medium | Passed |
111122223333 |
Global |
FS-49 |
ADVISORY: Hallucination Disclaimer — Manual Review Required
Details and remediationDetails
Application-level hallucination disclaimers cannot be verified via AWS APIs. Manual review required. Resolution
1. Add disclaimers to GenAI outputs: 'AI-generated content may contain errors. Verify with authoritative sources before acting.' 2. Implement post-processing to append disclaimers. 3. Test disclaimer presence in QA before production. |
Informational | N/A |
111122223333 |
Global |
FS-50 |
No Guardrails With Relevance Grounding Filters
Details and remediationDetails
No guardrails have RELEVANCE contextual grounding filters. Without relevance filters, responses that are off-topic or unrelated to the user query will not be blocked, increasing hallucination risk in RAG-based applications. Resolution
Enable the RELEVANCE contextual grounding filter in Bedrock Guardrails with a threshold of ≥0.7 to block responses that are not relevant to the user query. Also enable the GROUNDING filter (≥0.7) to block responses not supported by the retrieved source context. |
Medium | Failed |
111122223333 |
Global |
FS-51 |
No Guardrails — Prompt Attack Filters Not Applicable
|
Informational | N/A |
111122223333 |
Global |
FS-52 |
Bedrock Lambda Functions on Deprecated Runtimes
Details and remediationDetails
Functions on deprecated runtimes: e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk, e2ebedrockrag-OSSInfraSta-OSSIndexCreationProvider-g56en9UzRjII. Deprecated runtimes may use outdated boto3/SDK versions lacking security patches. Resolution
1. Upgrade Lambda functions to a supported runtime — Python 3.12+, Node.js 22.x or 24.x, Java 21+, or .NET 8+. 2. Update boto3 to the latest version in Lambda layers (pin the version in requirements.txt and redeploy). 3. Enable Lambda runtime management controls for automatic minor-version updates (runtimeManagementConfig.updateRuntimeOn = 'Auto'). 4. Refer to https://docs.aws.amazon.com/lambda/latest/dg/lambda-runtimes.html for the authoritative list of supported and deprecated runtimes. |
Medium | Failed |
111122223333 |
Global |
FS-53 |
No WAF Web ACLs — Injection Rules Not Applicable
|
Informational | N/A |
111122223333 |
Global |
FS-54 |
ADVISORY: Penetration Testing — Manual Review Required
Details and remediationDetails
Penetration testing evidence cannot be verified via AWS APIs. Manual review required to confirm GenAI applications have been tested. Resolution
1. Conduct penetration testing of GenAI applications at least annually and before major releases. 2. Include AI-specific test cases: prompt injection, jailbreak, indirect (cross-domain) injection, system-prompt leakage, and data-extraction attempts. 3. Consider AWS Security Agent for on-demand, AI-driven penetration testing (GA March 2026; available in US East N. Virginia, US West Oregon, Europe Ireland, Europe Frankfurt, Asia Pacific Sydney, Asia Pacific Tokyo, with cross-account shared-VPC testing via AWS RAM). Open-source tools such as Garak or PyRIT and manual red-teaming are complementary options. Verify current regional availability on the AWS Security Agent page before relying on it. 4. Document findings and remediation for regulatory examination, and tag tested resources with a last-pentest-date for audit trail. 5. For DORA compliance, include GenAI in TLPT (Threat-Led Penetration Testing) scope. |
Informational | N/A |
111122223333 |
Global |
FS-55 |
No Output Validation Functions Found
Details and remediationDetails
No Lambda functions with output validation/sanitization naming found. GenAI outputs may be passed directly to downstream systems without validation. Resolution
1. Implement output validation Lambda functions in GenAI pipelines. 2. Validate output schema, length, and content before downstream use. 3. Sanitize outputs before rendering in web UIs (XSS prevention). 4. Encode outputs appropriately for the target context (HTML, SQL, JSON). |
Medium | Failed |
111122223333 |
Global |
FS-56 |
No WAF ACLs — XSS Prevention Not Applicable
|
Informational | N/A |
111122223333 |
Global |
FS-57 |
ADVISORY: Output Encoding — Manual Review Required
Details and remediationDetails
Output encoding practices cannot be verified via AWS APIs. Manual code review required. Resolution
1. HTML-encode GenAI outputs before rendering in web UIs. 2. Use parameterized queries when GenAI output is used in database operations. 3. JSON-encode outputs before embedding in JavaScript contexts. 4. Validate output length and format before passing to downstream APIs. |
Informational | N/A |
111122223333 |
Global |
FS-58 |
ADVISORY: Output Schema Validation — Manual Review Required
Details and remediationDetails
Found 0 Lambda function(s) whose names suggest schema/validation handling. Structured-output / JSON-schema validation of GenAI responses is an application-layer control that cannot be verified automatically — manual review required. Resolution
1. Use Bedrock structured output (response schemas) where supported. 2. Implement JSON schema validation on Lambda output processors. 3. Reject malformed outputs and return safe error responses. 4. Log schema validation failures to CloudWatch for monitoring. |
Informational | N/A |
111122223333 |
Global |
FS-59 |
No Guardrails — Topic Allowlist Not Applicable
|
Informational | N/A |
111122223333 |
Global |
FS-60 |
ADVISORY: Contextual Grounding for Off-Topic Prevention
Details and remediationDetails
Contextual grounding for off-topic prevention is covered by guardrail grounding checks (FS-47) and RAG configuration (FS-48). Additionally verify system prompts explicitly scope the assistant's role. Resolution
1. Include explicit scope instructions in system prompts. 2. Use Bedrock Guardrails relevance grounding filter. 3. Test with off-topic prompts in QA to verify rejection behavior. |
Informational | N/A |
111122223333 |
Global |
FS-61 |
No Automated KB Sync Schedules Detected
Details and remediationDetails
Found 3 Knowledge Base(s) but no EventBridge Scheduler schedules or EventBridge rules with 'bedrock'/'knowledge' naming were found. Note: this check uses a name/target heuristic — sync automation with other naming conventions, AWS Step Functions-based orchestration, or native Bedrock API-triggered syncs (StartIngestionJob called directly) will not be detected. Verify sync automation manually if applicable. Resolution
1. Use EventBridge Scheduler (the AWS-recommended approach) to create a recurring schedule (e.g., rate(1 day) or a cron expression) that triggers a Lambda function calling the Bedrock StartIngestionJob API for each data source. Classic EventBridge scheduled rules also work but are a legacy feature. 2. As of December 2024, Bedrock Knowledge Bases supports custom connectors and streaming data ingestion — use direct document ingestion (KnowledgeBaseDocuments API) for real-time updates without a full S3 sync. 3. Set sync frequency based on data currency requirements (e.g., hourly for market data, daily for regulatory guidance). 4. Configure CloudWatch alarms or SNS notifications on IngestionJob FAILED status for sync failure alerting. |
Medium | Failed |
111122223333 |
Global |
FS-62 |
ADVISORY: Data Currency Disclaimer — Manual Review Required
Details and remediationDetails
Data currency disclaimers cannot be verified via AWS APIs. Manual review required. Resolution
1. Add data currency disclaimers to GenAI outputs: 'Information based on data current as of [KB last sync date].' 2. Expose KB last sync timestamp in application responses. 3. Alert users when KB data is older than defined threshold. |
Informational | N/A |
111122223333 |
Global |
FS-63 |
Foundation Model Lifecycle Governance Detected
Details and remediationDetails
10 AWS Config rule(s) with lifecycle- or model-related names were found, indicating some account-side model lifecycle governance: securityhub-ecr-private-lifecycle-policy-configured-c35f8211, securityhub-s3-lifecycle-policy-check-e7c34dbb, securityhub-s3express-dir-bucket-lifecycle-rules-check-5a9780d7, securityhub-sagemaker-model-bias-job-encrypt-in-transit-10be60eb, securityhub-sagemaker-model-bias-job-isolation-497b8bd2. Rule names are a heuristic; whether these rules enforce model currency is not assessed. For context, 17 of 122 model(s) offered in this region are marked LEGACY (for example ai21.jamba-1-5-large-v1:0, ai21.jamba-1-5-mini-v1:0, amazon.nova-canvas-v1:0, amazon.nova-premier-v1:0, amazon.nova-premier-v1:0:1000k); this reflects the regional catalogue, not this account's usage. Resolution
Confirm the matched rules genuinely track model currency, and that deprecation notifications are monitored. |
Medium | Passed |
111122223333 |
Global |
FS-65 |
KB Data Source Buckets Missing S3 Event Notifications
Details and remediationDetails
The following KB data-source S3 buckets have no event notifications configured. Unauthorized document modifications will not be detected in real time: - semiconductor-demo-9999 - 111122223333-us-east-1-kb-data-bucket Resolution
1. Enable Amazon EventBridge notifications on each KB data-source S3 bucket. 2. Create an EventBridge rule to route s3:ObjectCreated, s3:ObjectRemoved, and s3:ObjectModified events to an SNS topic or Lambda for alerting. 3. Integrate alerts into your security incident response workflow. |
Medium | Failed |
111122223333 |
Global |
FS-66 |
AgentCore Runtimes Without JWT Authorizer
Details and remediationDetails
The following runtimes have no customJWTAuthorizer, so no end-user identity can reach the runtime and tool calls are authorized only by the agent execution role: - origami_expeditions - neoCyan_Agent - cdk_agent_core - awsapimcpserver A JWT authorizer is a prerequisite, not proof of propagation; verify downstream token forwarding and validation manually. Resolution
1. Configure a custom JWT authorizer on each AgentCore runtime. 2. Propagate the end-user's identity token to downstream tool services. 3. Ensure tool services validate the propagated identity before executing actions. 4. Do not expose propagated identity tokens to unauthorized third parties. |
High | Failed |
111122223333 |
Global |
FS-66 |
AgentCore Runtimes With JWT Authorizer Configured
|
High | Passed |
111122223333 |
Global |
FS-67 |
Agent Action-Group Lambdas May Lack Transaction Thresholds
Details and remediationDetails
The following agent action-group Lambda functions have no environment variables whose names suggest transaction-value threshold configuration (this is a best-effort heuristic — a threshold enforced in code or in an AgentCore Policy Engine rule would not be detected here, so treat this as a prompt for manual verification rather than a definitive gap). Without explicit limits, agents could initiate unbounded financial transactions: - resco-aiml-BedrockAssessment - ClaudeCoworkEnvironment-BedrockApiKeyLambda-pPWYTtBWqHtH - e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk - e2ebedrockrag-OSSInfraSta-OSSIndexCreationProvider-g56en9UzRjII - ClaudeCodeWorkshop-BedrockAccessLambda-b9a4xULBNrlV - resco-aiml-AgentCoreAssessment Resolution
1. Add transaction-value threshold environment variables (e.g., MAX_TRANSACTION_AMOUNT) to each agent action-group Lambda. 2. Implement threshold enforcement logic in the Lambda handler. 3. Configure AgentCore Policy Engine rules to cap financial transaction amounts. 4. Route transactions exceeding thresholds to a human-in-the-loop approval step. |
High | Failed |
111122223333 |
Global |
FS-68 |
API Gateway Request Body Size Limits Not Enforced
Details and remediationDetails
Found 3 REST API(s) and 0 regional WAF Web ACL(s), but none enforce a maximum request-body size. Note: an API Gateway request validator does NOT cap body size (it validates the schema and required params; the REST limit is a fixed 10 MB), and a WAF body SizeConstraint only inspects the first ~16 KB of the body by default. Oversized prompts can exhaust Bedrock token quotas and inflate costs. Resolution
1. Add a maxLength (or maxItems/maxProperties) bound to the request-body JSON-Schema model used by your request validator, so oversized prompts are rejected with a 400. 2. Add a WAF SizeConstraintStatement on the request Body sized within WAF's body-inspection window (default 16 KB; raise via the web ACL AssociationConfig, or set OversizeHandling=MATCH to block bodies beyond the window), and associate the ACL with the API stage. 3. Set the max_tokens parameter in Bedrock API calls to cap output length. 4. Implement client-side token counting before submitting requests. |
Medium | Failed |
111122223333 |
Global |
FS-69 |
Prompt Input Validation Functions Present
Details and remediationDetails
Found 3 Lambda function(s) with input validation/sanitization naming patterns: resco-aiml-CleanupBucket, visa-bulletin-tracker-prod-cleanup, aiml-security-aiml-security-111122223333-CleanupBucket. Resolution
Review these functions to confirm they cover: special-character stripping, format validation, size limits, and injection-sequence detection. |
Medium | Passed |
111122223333 |
us-west-2 |
SM-01 |
Non-VPC Only Network Access
|
High | Failed |
111122223333 |
us-west-2 |
SM-02 |
SSO Not Properly Configured
|
Medium | Failed |
111122223333 |
us-west-2 |
SM-03 |
Missing Encryption Configuration
|
High | Failed |
111122223333 |
us-west-2 |
SM-04 |
GuardDuty Enabled
|
Medium | Passed |
111122223333 |
us-west-2 |
SM-26 |
GuardDuty AI Protection
|
High | Failed |
111122223333 |
us-west-2 |
SM-05 |
SageMaker Model Registry Issue
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-05 |
SageMaker Feature Store Issue
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-05 |
SageMaker Pipelines Issue
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-06 |
SageMaker Clarify No Clarify Usage
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-07 |
SageMaker Model Monitor No Model Monitoring
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-08 |
Model Registry Registry Not Used
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-09 |
SageMaker Notebook Root Access Check
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-10 |
SageMaker Notebook VPC Deployment Check
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-11 |
SageMaker Model Network Isolation Check
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-12 |
SageMaker Endpoint Instance Count Check
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-13 |
SageMaker Monitoring Network Isolation Check
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-14 |
SageMaker Model Repository Access Check
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-15 |
SageMaker Feature Store Encryption Check
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-16 |
SageMaker Data Quality Job Encryption Check
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-17 |
SageMaker Processing Job Encryption Check
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-18 |
SageMaker Transform Job Encryption Check
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-19 |
SageMaker Hyperparameter Tuning Job Encryption Check
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-20 |
SageMaker Compilation Job Encryption Check
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-21 |
SageMaker AutoML Job Network Isolation Check
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-22 |
Model Approval Workflow Check
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-23 |
Model Drift Detection Check
|
Medium | Passed |
111122223333 |
us-west-2 |
SM-24 |
A/B Testing and Shadow Deployment Check
|
Low | Passed |
111122223333 |
us-west-2 |
SM-25 |
ML Lineage Tracking - Experiments Not Used
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-27 |
HyperPod EBS CMK Encryption
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-28 |
HyperPod VPC Configuration
|
Informational | N/A |
111122223333 |
us-west-2 |
SM-30 |
Model Package Group Resource Policy Exposure
|
Informational | N/A |
111122223333 |
Global |
SM-02 |
SageMaker Full Access Policy Used
|
High | Failed |
111122223333 |
Global |
SM-02 |
SageMaker Full Access Policy Used
|
High | Failed |
111122223333 |
Global |
SM-02 |
SageMaker Full Access Policy Used
|
High | Failed |
111122223333 |
Global |
SM-02 |
SageMaker Full Access Policy Used
|
High | Failed |
111122223333 |
Global |
SM-02 |
SageMaker Full Access Policy Used
|
High | Failed |
111122223333 |
Global |
SM-02 |
SageMaker Full Access Policy Used
|
High | Failed |
111122223333 |
Global |
SM-02 |
SageMaker Full Access Policy Used
|
High | Failed |
111122223333 |
us-east-1 |
SM-01 |
Non-VPC Only Network Access
|
High | Failed |
111122223333 |
us-east-1 |
SM-02 |
SSO Not Properly Configured
Details and remediation |
Medium | Failed |
111122223333 |
us-east-1 |
SM-03 |
Missing Encryption Configuration
|
High | Failed |
111122223333 |
us-east-1 |
SM-04 |
GuardDuty Enabled
|
Medium | Passed |
111122223333 |
us-east-1 |
SM-26 |
GuardDuty AI Protection
|
High | Failed |
111122223333 |
us-east-1 |
SM-05 |
SageMaker Model Registry Issue
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-05 |
SageMaker Feature Store Issue
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-05 |
SageMaker Pipelines Issue
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-06 |
SageMaker Clarify No Clarify Usage
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-07 |
SageMaker Model Monitor No Model Monitoring
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-08 |
Model Registry Registry Not Used
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-09 |
SageMaker Notebook Root Access Check
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-10 |
SageMaker Notebook VPC Deployment Check
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-11 |
SageMaker Model Network Isolation Check
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-12 |
SageMaker Endpoint Instance Count Check
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-13 |
SageMaker Monitoring Network Isolation Check
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-14 |
SageMaker Model Repository Access Check
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-15 |
SageMaker Feature Store Encryption Check
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-16 |
SageMaker Data Quality Job Encryption Check
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-17 |
SageMaker Processing Job Encryption Check
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-18 |
SageMaker Transform Job Encryption Check
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-19 |
SageMaker Hyperparameter Tuning Job Encryption Check
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-20 |
SageMaker Compilation Job Encryption Check
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-21 |
SageMaker AutoML Job Network Isolation Check
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-22 |
Model Approval Workflow Check
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-23 |
Model Drift Detection Check
|
Medium | Passed |
111122223333 |
us-east-1 |
SM-24 |
A/B Testing and Shadow Deployment Check
|
Low | Passed |
111122223333 |
us-east-1 |
SM-25 |
ML Lineage Tracking - Experiments Not Used
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-27 |
HyperPod EBS CMK Encryption
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-28 |
HyperPod VPC Configuration
|
Informational | N/A |
111122223333 |
us-east-1 |
SM-30 |
Model Package Group Resource Policy Exposure
|
Informational | N/A |
111122223333 |
Global |
AC-02 |
AgentCore IAM Full Access Policy
Details and remediation |
High | Failed |
111122223333 |
Global |
AC-02 |
AgentCore IAM Wildcard Permissions
Details and remediationDetails
The following roles have wildcard or allow-except AgentCore permissions on all resources: AmazonSageMaker-ExecutionRole-20250525T153161, agentcore-wildrydes_gateway_role_ab3991f6-role Resolution
Replace wildcard or allow-except permissions with required AgentCore actions and scope resources using ARNs |
High | Failed |
111122223333 |
Global |
AC-03 |
AgentCore Stale Access
Details and remediationDetails
The following principals have not accessed AgentCore in 60+ days: role 'AmazonSageMaker-ExecutionRole-20250525T153161' (255 days), role 'AWSServiceRoleForBedrockAgentCoreRuntimeIdentity' (255 days), role 'CustomerSupportAssistantBedrockAgentCoreRole-us-east-1' (255 days), role 'resco-aiml-security-19304-AgentCoreSecurityAssessme-w773pPsFWNsn' (138 days) Resolution
Review and remove unused AgentCore permissions following least privilege principle |
Medium | Failed |
111122223333 |
Global |
AC-03 |
AgentCore Unused Permissions
Details and remediationDetails
The following principals have AgentCore permissions but have never accessed the service: role 'agentcore-wildrydes_gateway_role_ab3991f6-role', role 'AIMLSecurityMemberRole', role 'AmazonBedrockAgentCoreSDKRuntime-us-east-1-a6ddf3fc76', role 'AmazonBedrockAgentCoreSDKRuntime-us-east-1-ed660add8b', role 'AwsSecurityAudit', role 'AWSServiceRoleForSupport', role 'cdk-hnb659fds-lookup-role-111122223333-us-east-1', role 'cdk-hnb659fds-lookup-role-111122223333-us-west-2', role 'CloudSecAuditRole', role 'CloudSeerTrustedServiceRole', role 'CustomerSupportStackInfra-RuntimeAgentCoreRole-N188nLB5RtLO', role 'EpoxyAccessRole', role 'IDP-AnalyticsProcessorFunctionRole-H3gwkJtNqrqW', role 'IibsAdminAccess-DO-NOT-DELETE', role 'InternalAuditInternal', role 'ManagedInstance-CrossAccountExecutionRole', role 'ProwlerMemberRole' Resolution
Review and remove unused AgentCore permissions following least privilege principle |
Informational | N/A |
111122223333 |
Global |
AC-09 |
AgentCore Service-Linked Role Missing
Details and remediationDetails
Service-linked role 'AWSServiceRoleForBedrockAgentCoreNetwork' does not exist. VPC configuration for AgentCore Runtimes will fail without this role. Resolution
Allow iam:CreateServiceLinkedRole for arn:PARTITION:iam::*:role/aws-service-role/network.bedrock-agentcore.amazonaws.com/AWSServiceRoleForBedrockAgentCoreNetwork, replacing PARTITION with the deployment partition, and add StringEquals for iam:AWSServiceName = network.bedrock-agentcore.amazonaws.com. Then configure VPC networking on an AgentCore Runtime so AWS creates the service-linked role. |
Medium | Failed |
111122223333 |
us-east-1 |
AC-01 |
AgentCore Runtime VPC Configuration
|
High | Failed |
111122223333 |
us-east-1 |
AC-01 |
AgentCore Runtime VPC Configuration
|
High | Failed |
111122223333 |
us-east-1 |
AC-01 |
AgentCore Runtime VPC Configuration
|
High | Failed |
111122223333 |
us-east-1 |
AC-01 |
AgentCore Runtime VPC Configuration
|
High | Failed |
111122223333 |
us-east-1 |
AC-01 |
AgentCore Runtime VPC Configuration
|
High | Failed |
111122223333 |
us-east-1 |
AC-04 |
AgentCore Runtime CloudWatch Logs
|
Medium | Failed |
111122223333 |
us-east-1 |
AC-04 |
AgentCore Runtime X-Ray Tracing
|
Medium | Failed |
111122223333 |
us-east-1 |
AC-04 |
AgentCore Runtime CloudWatch Logs
|
Medium | Failed |
111122223333 |
us-east-1 |
AC-04 |
AgentCore Runtime X-Ray Tracing
|
Medium | Failed |
111122223333 |
us-east-1 |
AC-04 |
AgentCore Runtime CloudWatch Logs
|
Medium | Failed |
111122223333 |
us-east-1 |
AC-04 |
AgentCore Runtime X-Ray Tracing
|
Medium | Failed |
111122223333 |
us-east-1 |
AC-04 |
AgentCore Runtime CloudWatch Logs
|
Medium | Failed |
111122223333 |
us-east-1 |
AC-04 |
AgentCore Runtime X-Ray Tracing
|
Medium | Failed |
111122223333 |
us-east-1 |
AC-04 |
AgentCore Runtime CloudWatch Logs
|
Medium | Failed |
111122223333 |
us-east-1 |
AC-04 |
AgentCore Runtime X-Ray Tracing
|
Medium | Failed |
111122223333 |
us-east-1 |
AC-05 |
AgentCore ECR Repository AWS-Managed Keys
|
Low | Failed |
111122223333 |
us-east-1 |
AC-05 |
AgentCore ECR Repository AWS-Managed Keys
|
Low | Failed |
111122223333 |
us-east-1 |
AC-06 |
AgentCore Browser Session Recording
|
Informational | N/A |
111122223333 |
us-east-1 |
AC-07 |
AgentCore Memory Encryption
|
Medium | Failed |
111122223333 |
us-east-1 |
AC-07 |
AgentCore Memory Encryption
|
Medium | Failed |
111122223333 |
us-east-1 |
AC-07 |
AgentCore Memory Encryption
|
Medium | Failed |
111122223333 |
us-east-1 |
AC-13 |
AgentCore Gateway Configuration Check
|
Medium | Passed |
111122223333 |
us-east-1 |
AC-08 |
AgentCore VPC Endpoints Missing
Details and remediationDetails
No AgentCore VPC endpoints found in 4 VPCs. AgentCore API traffic traverses public internet, exposing it to interception. Resolution
Create VPC interface endpoints for AgentCore services: 1. com.amazonaws.region.bedrock-agentcore 2. com.amazonaws.region.bedrock-agentcore-control 3. com.amazonaws.region.bedrock-agentcore-runtime This enables private connectivity via AWS PrivateLink |
High | Failed |
111122223333 |
us-east-1 |
AC-10 |
AgentCore Resource-Based Policies Missing
Details and remediationDetails
The following AgentCore resources do not have resource-based policies: Runtime 'origami_expeditions', Runtime 'neoCyan_Agent', Runtime 'customer_support_agent', Runtime 'cdk_agent_core', Runtime 'awsapimcpserver' and 3 more. Without RBPs, access control relies solely on identity-based policies. Resolution
Attach resource-based policies to AgentCore resources to: 1. Implement defense-in-depth access control 2. Enable cross-account access control 3. Restrict access based on source VPC or IP 4. Implement hierarchical authorization for Agent Runtimes |
High | Failed |
111122223333 |
us-east-1 |
AC-11 |
AgentCore Policy Engine Encryption Check
|
Informational | N/A |
111122223333 |
us-east-1 |
AC-12 |
AgentCore Gateway Encryption Missing
Details and remediationDetails
The following Gateways do not use customer-managed KMS encryption: 'customersupport-gw', 'WebSearchGateway', 'wildrydes-gateway-ab3991f6'. Gateway configuration data uses AWS-managed keys. Resolution
1. Create gateways with customer-managed KMS keys for additional control 2. AWS-managed keys are single-tenant and region-specific 3. Consider CMK for enhanced audit capabilities and key rotation control |
Low | Failed |
111122223333 |
us-east-1 |
AC-14 |
AgentCore Identity Token Vault CMK Encryption
|
High | Failed |
111122223333 |
us-east-1 |
AC-15 |
AgentCore Code Interpreter Network Isolation
|
Informational | N/A |
111122223333 |
us-east-1 |
AC-16 |
AgentCore Custom Browser Network Isolation
|
Informational | N/A |
111122223333 |
us-east-1 |
AC-17 |
AgentCore Online Evaluation Coverage
|
Medium | Passed |
111122223333 |
us-east-1 |
AG-24 |
Agentic AI Gateway Inbound Authorization
|
High | Passed |
111122223333 |
us-east-1 |
AG-25 |
Agentic AI Gateway Tool Policy Enforcement Missing
Details and remediation |
High | Failed |
111122223333 |
us-east-1 |
AG-26 |
Agentic AI Gateway Error Detail Exposure
|
Medium | Passed |
111122223333 |
us-east-1 |
AG-27 |
Agentic AI Gateway WAF Protection Missing
|
Low | Failed |
111122223333 |
us-east-1 |
AG-24 |
Agentic AI Gateway Inbound Authorization
|
High | Passed |
111122223333 |
us-east-1 |
AG-25 |
Agentic AI Gateway Tool Policy Enforcement Missing
Details and remediation |
High | Failed |
111122223333 |
us-east-1 |
AG-26 |
Agentic AI Gateway Error Detail Exposure
|
Medium | Passed |
111122223333 |
us-east-1 |
AG-27 |
Agentic AI Gateway WAF Protection Missing
|
Low | Failed |
111122223333 |
us-east-1 |
AG-24 |
Agentic AI Gateway Inbound Authorization
|
High | Passed |
111122223333 |
us-east-1 |
AG-25 |
Agentic AI Gateway Tool Policy Enforcement Missing
Details and remediationDetails
Gateway 'wildrydes-gateway-ab3991f6' (wildrydes-gateway-ab3991f6-jrlh9ok6ya) does not have a policy engine configuration. Tool calls are not evaluated by AgentCore policy enforcement. Resolution
Attach an AgentCore policy engine to the gateway and use ENFORCE mode for production tool authorization. |
High | Failed |
111122223333 |
us-east-1 |
AG-26 |
Agentic AI Gateway Error Detail Exposure
|
Medium | Passed |
111122223333 |
us-east-1 |
AG-27 |
Agentic AI Gateway WAF Protection Missing
|
Low | Failed |
111122223333 |
Global |
AG-16 |
Agentic AI AgentCore Least Privilege
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Over-permissive AgentCore principals can let agents or operators bypass intended autonomy and tool boundaries. Source check AC-02: The following roles have AgentCore full-access policies: AmazonSageMaker-ExecutionRole-20250525T153161, ClaudeCodeWorkshop-CodeEditorInstanceBootstrapRole-GWdiq3M0J6tF Resolution
Replace full-access AgentCore permissions with least-privilege IAM policies scoped to required resources and actions. |
High | Failed |
111122223333 |
Global |
AG-16 |
Agentic AI AgentCore Least Privilege
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Over-permissive AgentCore principals can let agents or operators bypass intended autonomy and tool boundaries. Source check AC-02: The following roles have wildcard or allow-except AgentCore permissions on all resources: AmazonSageMaker-ExecutionRole-20250525T153161, agentcore-wildrydes_gateway_role_ab3991f6-role Resolution
Replace full-access AgentCore permissions with least-privilege IAM policies scoped to required resources and actions. |
High | Failed |
111122223333 |
Global |
AG-17 |
Agentic AI Stale AgentCore Access
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Unused AgentCore permissions increase the blast radius of compromised principals. Source check AC-03: The following principals have not accessed AgentCore in 60+ days: role 'AmazonSageMaker-ExecutionRole-20250525T153161' (255 days), role 'AWSServiceRoleForBedrockAgentCoreRuntimeIdentity' (255 days), role 'CustomerSupportAssistantBedrockAgentCoreRole-us-east-1' (255 days), role 'resco-aiml-security-19304-AgentCoreSecurityAssessme-w773pPsFWNsn' (138 days) Resolution
Remove or restrict stale AgentCore permissions for principals that no longer need access. |
Medium | Failed |
111122223333 |
Global |
AG-17 |
Agentic AI Stale AgentCore Access
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Unused AgentCore permissions increase the blast radius of compromised principals. Source check AC-03: The following principals have AgentCore permissions but have never accessed the service: role 'agentcore-wildrydes_gateway_role_ab3991f6-role', role 'AIMLSecurityMemberRole', role 'AmazonBedrockAgentCoreSDKRuntime-us-east-1-a6ddf3fc76', role 'AmazonBedrockAgentCoreSDKRuntime-us-east-1-ed660add8b', role 'AwsSecurityAudit', role 'AWSServiceRoleForSupport', role 'cdk-hnb659fds-lookup-role-111122223333-us-east-1', role 'cdk-hnb659fds-lookup-role-111122223333-us-west-2', role 'CloudSecAuditRole', role 'CloudSeerTrustedServiceRole', role 'CustomerSupportStackInfra-RuntimeAgentCoreRole-N188nLB5RtLO', role 'EpoxyAccessRole', role 'IDP-AnalyticsProcessorFunctionRole-H3gwkJtNqrqW', role 'IibsAdminAccess-DO-NOT-DELETE', role 'InternalAuditInternal', role 'ManagedInstance-CrossAccountExecutionRole', role 'ProwlerMemberRole' Resolution
Remove or restrict stale AgentCore permissions for principals that no longer need access. |
Informational | N/A |
111122223333 |
us-east-1 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: Runtime 'origami_expeditions' (origami_expeditions-TR4jDoHXe8) is not configured with VPC. This exposes the runtime to public internet. Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
High | Failed |
111122223333 |
us-east-1 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: Runtime 'neoCyan_Agent' (neoCyan_Agent-yAFXSWFaA3) is not configured with VPC. This exposes the runtime to public internet. Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
High | Failed |
111122223333 |
us-east-1 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: Runtime 'customer_support_agent' (customer_support_agent-ZP4e8z55dP) is not configured with VPC. This exposes the runtime to public internet. Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
High | Failed |
111122223333 |
us-east-1 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: Runtime 'cdk_agent_core' (cdk_agent_core-7FqFlD86LW) is not configured with VPC. This exposes the runtime to public internet. Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
High | Failed |
111122223333 |
us-east-1 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: Runtime 'awsapimcpserver' (awsapimcpserver-mJrqgt37GO) is not configured with VPC. This exposes the runtime to public internet. Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
High | Failed |
111122223333 |
us-east-1 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: Runtime 'origami_expeditions' (origami_expeditions-TR4jDoHXe8) does not have CloudWatch Logs configured Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Medium | Failed |
111122223333 |
us-east-1 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: Runtime 'origami_expeditions' (origami_expeditions-TR4jDoHXe8) does not have X-Ray tracing enabled Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Medium | Failed |
111122223333 |
us-east-1 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: Runtime 'neoCyan_Agent' (neoCyan_Agent-yAFXSWFaA3) does not have CloudWatch Logs configured Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Medium | Failed |
111122223333 |
us-east-1 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: Runtime 'neoCyan_Agent' (neoCyan_Agent-yAFXSWFaA3) does not have X-Ray tracing enabled Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Medium | Failed |
111122223333 |
us-east-1 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: Runtime 'customer_support_agent' (customer_support_agent-ZP4e8z55dP) does not have CloudWatch Logs configured Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Medium | Failed |
111122223333 |
us-east-1 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: Runtime 'customer_support_agent' (customer_support_agent-ZP4e8z55dP) does not have X-Ray tracing enabled Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Medium | Failed |
111122223333 |
us-east-1 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: Runtime 'cdk_agent_core' (cdk_agent_core-7FqFlD86LW) does not have CloudWatch Logs configured Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Medium | Failed |
111122223333 |
us-east-1 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: Runtime 'cdk_agent_core' (cdk_agent_core-7FqFlD86LW) does not have X-Ray tracing enabled Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Medium | Failed |
111122223333 |
us-east-1 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: Runtime 'awsapimcpserver' (awsapimcpserver-mJrqgt37GO) does not have CloudWatch Logs configured Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Medium | Failed |
111122223333 |
us-east-1 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: Runtime 'awsapimcpserver' (awsapimcpserver-mJrqgt37GO) does not have X-Ray tracing enabled Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Medium | Failed |
111122223333 |
us-east-1 |
AG-19 |
Agentic AI Memory Data Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: Memory 'CustomerSupportMemory-x69jBq5GLp' (CustomerSupportMemory-x69jBq5GLp) does not have customer-managed encryption configured Resolution
Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions. |
Medium | Failed |
111122223333 |
us-east-1 |
AG-19 |
Agentic AI Memory Data Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: Memory 'cdk_agent_core_mem-uxfIagADuF' (cdk_agent_core_mem-uxfIagADuF) does not have customer-managed encryption configured Resolution
Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions. |
Medium | Failed |
111122223333 |
us-east-1 |
AG-19 |
Agentic AI Memory Data Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: Memory 'wildrydes_memory_ab3991f6-9FjiHOHjT2' (wildrydes_memory_ab3991f6-9FjiHOHjT2) does not have customer-managed encryption configured Resolution
Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions. |
Medium | Failed |
111122223333 |
us-east-1 |
AG-20 |
Agentic AI Private AgentCore Connectivity
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore VPC endpoints found in 4 VPCs. AgentCore API traffic traverses public internet, exposing it to interception. Resolution
Create required VPC endpoints for AgentCore services and validate endpoint availability. |
High | Failed |
111122223333 |
us-east-1 |
AG-21 |
Agentic AI Resource Policy Boundary
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: The following AgentCore resources do not have resource-based policies: Runtime 'origami_expeditions', Runtime 'neoCyan_Agent', Runtime 'customer_support_agent', Runtime 'cdk_agent_core', Runtime 'awsapimcpserver' and 3 more. Without RBPs, access control relies solely on identity-based policies. Resolution
Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources. |
High | Failed |
111122223333 |
us-east-1 |
AG-22 |
Agentic AI Policy Engine Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found Resolution
Configure policy engines with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
111122223333 |
us-east-1 |
AG-23 |
Agentic AI Gateway Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: The following Gateways do not use customer-managed KMS encryption: 'customersupport-gw', 'WebSearchGateway', 'wildrydes-gateway-ab3991f6'. Gateway configuration data uses AWS-managed keys. Resolution
Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required. |
Low | Failed |
111122223333 |
us-east-1 |
AG-28 |
Agentic AI Identity Token Vault Protection
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Agent credentials stored in the Identity token vault should use customer-controlled encryption where enhanced key control is required. Source check AC-14: AgentCore token vault 'default' uses a service-managed or AWS-owned key. Resolution
Configure the AgentCore Identity token vault with a customer-managed KMS key. |
High | Failed |
111122223333 |
us-east-1 |
AG-29 |
Agentic AI Code Interpreter Isolation
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent-executed code should run inside an explicit VPC boundary with controlled network paths. Source check AC-15: No custom AgentCore Code Interpreters found Resolution
Configure custom AgentCore Code Interpreters in VPC mode with approved subnets and security groups. |
Informational | N/A |
111122223333 |
us-east-1 |
AG-31 |
Agentic AI Browser Tool Isolation
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Browser tools can reach external systems and should use explicit private network boundaries. Source check AC-16: No custom AgentCore browsers found Resolution
Configure custom AgentCore browsers in VPC mode with approved subnets and security groups. |
Informational | N/A |
111122223333 |
us-east-1 |
AG-32 |
Agentic AI Online Evaluation Assurance
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Online evaluation provides continuous evidence about agent behavior, quality, and policy-relevant outcomes. Source check AC-17: Online evaluation 'customer_support_agent_eval' (customer_support_agent_eval-lFMtoeBXUD) is active with sampling, evaluators, input logs, and output logging. Resolution
Configure an active AgentCore online evaluation with sampling, evaluators, CloudWatch input logs, and an output log group. |
Medium | Passed |
111122223333 |
us-east-2 |
AC-01 |
AgentCore VPC Configuration Check
|
Informational | N/A |
111122223333 |
us-east-2 |
AC-04 |
AgentCore Observability Check
|
Informational | N/A |
111122223333 |
us-east-2 |
AC-05 |
AgentCore Encryption Check
|
Informational | N/A |
111122223333 |
us-east-2 |
AC-06 |
AgentCore Browser Session Recording
|
Informational | N/A |
111122223333 |
us-east-2 |
AC-07 |
AgentCore Memory Configuration Check
|
Informational | N/A |
111122223333 |
us-east-2 |
AC-13 |
AgentCore Gateway Configuration Check
|
Informational | N/A |
111122223333 |
us-east-2 |
AC-08 |
AgentCore VPC Endpoints Check
|
Informational | N/A |
111122223333 |
us-east-2 |
AC-10 |
AgentCore Resource-Based Policies Check
|
Informational | N/A |
111122223333 |
us-east-2 |
AC-11 |
AgentCore Policy Engine Encryption Check
|
Informational | N/A |
111122223333 |
us-east-2 |
AC-12 |
AgentCore Gateway Encryption Check
|
Informational | N/A |
111122223333 |
us-east-2 |
AC-14 |
AgentCore Identity Token Vault CMK Encryption
|
Informational | N/A |
111122223333 |
us-east-2 |
AC-15 |
AgentCore Code Interpreter Network Isolation
|
Informational | N/A |
111122223333 |
us-east-2 |
AC-16 |
AgentCore Custom Browser Network Isolation
|
Informational | N/A |
111122223333 |
us-east-2 |
AC-17 |
AgentCore Online Evaluation Coverage
|
Medium | Failed |
111122223333 |
us-east-2 |
AG-24 |
Agentic AI Gateway Inbound Authorization
|
Informational | N/A |
111122223333 |
us-east-2 |
AG-25 |
Agentic AI Gateway Tool Policy Enforcement
|
Informational | N/A |
111122223333 |
us-east-2 |
AG-26 |
Agentic AI Gateway Error Detail Exposure
|
Informational | N/A |
111122223333 |
us-east-2 |
AG-27 |
Agentic AI Gateway WAF Protection
|
Informational | N/A |
111122223333 |
us-east-2 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-19 |
Agentic AI Memory Data Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found Resolution
Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-20 |
Agentic AI Private AgentCore Connectivity
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found Resolution
Create required VPC endpoints for AgentCore services and validate endpoint availability. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-21 |
Agentic AI Resource Policy Boundary
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies Resolution
Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-22 |
Agentic AI Policy Engine Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found Resolution
Configure policy engines with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-23 |
Agentic AI Gateway Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found Resolution
Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-28 |
Agentic AI Identity Token Vault Protection
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Agent credentials stored in the Identity token vault should use customer-controlled encryption where enhanced key control is required. Source check AC-14: No assessable AgentCore Identity token vault was found. Resolution
Configure the AgentCore Identity token vault with a customer-managed KMS key. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-29 |
Agentic AI Code Interpreter Isolation
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent-executed code should run inside an explicit VPC boundary with controlled network paths. Source check AC-15: No custom AgentCore Code Interpreters found Resolution
Configure custom AgentCore Code Interpreters in VPC mode with approved subnets and security groups. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-31 |
Agentic AI Browser Tool Isolation
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Browser tools can reach external systems and should use explicit private network boundaries. Source check AC-16: No custom AgentCore browsers found Resolution
Configure custom AgentCore browsers in VPC mode with approved subnets and security groups. |
Informational | N/A |
111122223333 |
us-east-2 |
AG-32 |
Agentic AI Online Evaluation Assurance
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Online evaluation provides continuous evidence about agent behavior, quality, and policy-relevant outcomes. Source check AC-17: No AgentCore online evaluation configurations found. Resolution
Configure an active AgentCore online evaluation with sampling, evaluators, CloudWatch input logs, and an output log group. |
Medium | Failed |
111122223333 |
us-east-2 |
SM-01 |
SageMaker Internet Access Check
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-02 |
SageMaker SSO Configuration Check
|
Medium | Passed |
111122223333 |
us-east-2 |
SM-03 |
Missing Encryption Configuration
|
High | Failed |
111122223333 |
us-east-2 |
SM-03 |
Missing VPC Encryption
|
Medium | Failed |
111122223333 |
us-east-2 |
SM-04 |
GuardDuty Enabled
|
Medium | Passed |
111122223333 |
us-east-2 |
SM-26 |
GuardDuty AI Protection
|
High | Failed |
111122223333 |
us-east-2 |
SM-05 |
SageMaker Model Registry Issue
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-05 |
SageMaker Feature Store Issue
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-05 |
SageMaker Pipelines Issue
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-06 |
SageMaker Clarify No Clarify Usage
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-07 |
SageMaker Model Monitor No Model Monitoring
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-08 |
Model Registry Registry Not Used
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-09 |
SageMaker Notebook Root Access Check
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-10 |
SageMaker Notebook VPC Deployment Check
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-11 |
SageMaker Model Network Isolation Disabled
Details and remediationDetails
Model 'xgboost-2021-12-19-01-25-44-527' does not have network isolation enabled. Model containers can make outbound network calls, potentially exfiltrating data. Resolution
Enable network isolation by setting EnableNetworkIsolation=True when creating models. This prevents containers from making outbound network calls. |
High | Failed |
111122223333 |
us-east-2 |
SM-12 |
SageMaker Endpoint Instance Count Check
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-13 |
SageMaker Monitoring Network Isolation Check
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-14 |
SageMaker Model Platform Repository Access
Details and remediationDetails
Model 'xgboost-2021-12-19-01-25-44-527' uses Platform repository access mode. Container images are pulled from public/external registries, exposing supply chain risks. Resolution
Configure RepositoryAccessMode=Vpc in ImageConfig to pull images from private ECR repositories through VPC. This provides supply chain security. |
Medium | Failed |
111122223333 |
us-east-2 |
SM-15 |
SageMaker Feature Store Encryption Check
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-16 |
SageMaker Data Quality Job Encryption Check
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-17 |
SageMaker Processing Job Encryption Check
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-18 |
SageMaker Transform Job Volume Encryption Missing
Details and remediationDetails
Transform job 'xgboost-2021-12-19-01-25-49-740' does not have volume encryption configured. Data at rest on transform instances is not encrypted with customer-managed keys. Resolution
Configure VolumeKmsKeyId in TransformResources when creating transform jobs to encrypt attached EBS volumes. |
Medium | Failed |
111122223333 |
us-east-2 |
SM-19 |
SageMaker Hyperparameter Tuning Job Encryption Check
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-20 |
SageMaker Compilation Job Encryption Check
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-21 |
SageMaker AutoML Job Network Isolation Check
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-22 |
Model Approval Workflow Check
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-23 |
Model Drift Detection Check
|
Medium | Passed |
111122223333 |
us-east-2 |
SM-24 |
A/B Testing and Shadow Deployment Check
|
Low | Passed |
111122223333 |
us-east-2 |
SM-25 |
ML Lineage Tracking - Experiments Not Used
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-27 |
HyperPod EBS CMK Encryption
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-28 |
HyperPod VPC Configuration
|
Informational | N/A |
111122223333 |
us-east-2 |
SM-30 |
Model Package Group Resource Policy Exposure
|
Informational | N/A |
444455556666 |
us-east-2 |
AR-03 |
AWS Agent Registry Publication Approval Governance Incomplete
|
Informational | N/A |
444455556666 |
us-east-2 |
AR-04 |
AWS Agent Registry Discovery Authorization Incomplete
|
Informational | N/A |
444455556666 |
us-east-2 |
AR-05 |
AWS Agent Registry Customer-Managed KMS Encryption Incomplete
|
Informational | N/A |
444455556666 |
us-east-2 |
AR-06 |
AWS Agent Registry Organization Auto-Detection Incomplete
|
Informational | N/A |
444455556666 |
us-east-2 |
AR-07 |
AWS Agent Registry Record Lifecycle Governance Incomplete
|
Informational | N/A |
444455556666 |
us-east-2 |
AR-08 |
AWS Agent Registry Record Provenance Incomplete
|
Informational | N/A |
444455556666 |
us-east-2 |
AG-33 |
Agentic AI Registry Publication Approval Governance
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry approval workflows control which agents, tools, and skills become discoverable to consumers. Source check AR-03: Assessment could not enumerate AWS Agent Registry registries: AccessDeniedException (Unauthorized access). Resolution
Require manual review for registry publication where organizational policy does not permit automatic approval. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-34 |
Agentic AI Registry Discovery Authorization
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry discovery authorization requires review against intended callers and effective access boundaries. Source check AR-04: Assessment could not enumerate AWS Agent Registry registries: AccessDeniedException (Unauthorized access). Resolution
Review effective IAM access or compare custom JWT audiences, clients, scopes, and claims with approved registry consumers. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-35 |
Agentic AI Registry Metadata Encryption
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Registry records can contain agent, tool, endpoint, and ownership metadata that benefits from customer-controlled encryption. Source check AR-05: Assessment could not enumerate AWS Agent Registry registries: AccessDeniedException (Unauthorized access). Resolution
Create the registry with a customer-managed KMS key when organizational policy requires customer-controlled encryption. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-36 |
Agentic AI Organization Discovery Coverage
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Organization-wide auto-detection provides visibility into unmanaged agent resources. Source check AR-06: Assessment could not enumerate AWS Agent Registry registries: AccessDeniedException (Unauthorized access). Resolution
Enable organization-scoped registry auto-detection where centralized discovery is required. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-37 |
Agentic AI Registry Record Lifecycle Governance
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry lifecycle states provide operational visibility but do not independently prove a security control. Source check AR-07: Assessment could not enumerate AWS Agent Registry registries: AccessDeniedException (Unauthorized access). Resolution
Review failed or unknown record lifecycle states operationally. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-38 |
Agentic AI Registry Record Provenance
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Consumers need attributable record origin and source lineage to understand which account and resource produced an entry. Source check AR-08: Assessment could not enumerate AWS Agent Registry registries: AccessDeniedException (Unauthorized access). Resolution
Ensure records retain creator attribution and auto-detected records retain source provenance. |
Informational | N/A |
444455556666 |
Global |
AR-01 |
AWS Agent Registry IAM Full Access Check
|
High | Passed |
444455556666 |
Global |
AR-02 |
AWS Agent Registry Unused Permissions
|
Informational | N/A |
444455556666 |
us-east-1 |
AR-03 |
AWS Agent Registry Publication Approval Governance
|
Informational | N/A |
444455556666 |
us-east-1 |
AR-04 |
AWS Agent Registry Discovery Authorization
|
Informational | N/A |
444455556666 |
us-east-1 |
AR-05 |
AWS Agent Registry Customer-Managed KMS Encryption
|
Informational | N/A |
444455556666 |
us-east-1 |
AR-06 |
AWS Agent Registry Organization Auto-Detection
|
Informational | N/A |
444455556666 |
us-east-1 |
AR-07 |
AWS Agent Registry Record Lifecycle Governance
|
Informational | N/A |
444455556666 |
us-east-1 |
AR-08 |
AWS Agent Registry Record Provenance
|
Informational | N/A |
444455556666 |
us-east-1 |
AG-33 |
Agentic AI Registry Publication Approval Governance
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry approval workflows control which agents, tools, and skills become discoverable to consumers. Source check AR-03: No AWS Agent Registry registries found. Resolution
Require manual review for registry publication where organizational policy does not permit automatic approval. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-34 |
Agentic AI Registry Discovery Authorization
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry discovery authorization requires review against intended callers and effective access boundaries. Source check AR-04: No AWS Agent Registry registries found. Resolution
Review effective IAM access or compare custom JWT audiences, clients, scopes, and claims with approved registry consumers. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-35 |
Agentic AI Registry Metadata Encryption
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Registry records can contain agent, tool, endpoint, and ownership metadata that benefits from customer-controlled encryption. Source check AR-05: No AWS Agent Registry registries found. Resolution
Create the registry with a customer-managed KMS key when organizational policy requires customer-controlled encryption. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-36 |
Agentic AI Organization Discovery Coverage
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Organization-wide auto-detection provides visibility into unmanaged agent resources. Source check AR-06: No AWS Agent Registry registries found. Resolution
Enable organization-scoped registry auto-detection where centralized discovery is required. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-37 |
Agentic AI Registry Record Lifecycle Governance
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry lifecycle states provide operational visibility but do not independently prove a security control. Source check AR-07: No AWS Agent Registry registries found. Resolution
Review failed or unknown record lifecycle states operationally. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-38 |
Agentic AI Registry Record Provenance
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Consumers need attributable record origin and source lineage to understand which account and resource produced an entry. Source check AR-08: No AWS Agent Registry registries found. Resolution
Ensure records retain creator attribution and auto-detected records retain source provenance. |
Informational | N/A |
444455556666 |
us-west-2 |
AR-03 |
AWS Agent Registry Publication Approval Governance
|
Informational | N/A |
444455556666 |
us-west-2 |
AR-04 |
AWS Agent Registry Discovery Authorization
|
Informational | N/A |
444455556666 |
us-west-2 |
AR-05 |
AWS Agent Registry Customer-Managed KMS Encryption
|
Informational | N/A |
444455556666 |
us-west-2 |
AR-06 |
AWS Agent Registry Organization Auto-Detection
|
Informational | N/A |
444455556666 |
us-west-2 |
AR-07 |
AWS Agent Registry Record Lifecycle Governance
|
Informational | N/A |
444455556666 |
us-west-2 |
AR-08 |
AWS Agent Registry Record Provenance
|
Informational | N/A |
444455556666 |
us-west-2 |
AG-33 |
Agentic AI Registry Publication Approval Governance
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry approval workflows control which agents, tools, and skills become discoverable to consumers. Source check AR-03: No AWS Agent Registry registries found. Resolution
Require manual review for registry publication where organizational policy does not permit automatic approval. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-34 |
Agentic AI Registry Discovery Authorization
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry discovery authorization requires review against intended callers and effective access boundaries. Source check AR-04: No AWS Agent Registry registries found. Resolution
Review effective IAM access or compare custom JWT audiences, clients, scopes, and claims with approved registry consumers. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-35 |
Agentic AI Registry Metadata Encryption
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Registry records can contain agent, tool, endpoint, and ownership metadata that benefits from customer-controlled encryption. Source check AR-05: No AWS Agent Registry registries found. Resolution
Create the registry with a customer-managed KMS key when organizational policy requires customer-controlled encryption. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-36 |
Agentic AI Organization Discovery Coverage
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Organization-wide auto-detection provides visibility into unmanaged agent resources. Source check AR-06: No AWS Agent Registry registries found. Resolution
Enable organization-scoped registry auto-detection where centralized discovery is required. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-37 |
Agentic AI Registry Record Lifecycle Governance
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry lifecycle states provide operational visibility but do not independently prove a security control. Source check AR-07: No AWS Agent Registry registries found. Resolution
Review failed or unknown record lifecycle states operationally. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-38 |
Agentic AI Registry Record Provenance
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Consumers need attributable record origin and source lineage to understand which account and resource produced an entry. Source check AR-08: No AWS Agent Registry registries found. Resolution
Ensure records retain creator attribution and auto-detected records retain source provenance. |
Informational | N/A |
444455556666 |
Global |
AC-02 |
AgentCore IAM Full Access Check
|
High | Passed |
444455556666 |
Global |
AC-03 |
AgentCore Stale Access
|
Medium | Failed |
444455556666 |
Global |
AC-03 |
AgentCore Unused Permissions
Details and remediationDetails
The following principals have AgentCore permissions but have never accessed the service: role 'AIMLSecurityMemberRole', role 'AwsSecurityAudit', role 'AWSServiceRoleForSupport', role 'CloudSecAuditRole', role 'CloudSeerTrustedServiceRole', role 'EpoxyAccessRole', role 'IibsAdminAccess-DO-NOT-DELETE', role 'InternalAuditInternal', role 'ManagedInstance-CrossAccountExecutionRole', role 'ProwlerMemberRole' Resolution
Review and remove unused AgentCore permissions following least privilege principle |
Informational | N/A |
444455556666 |
Global |
AC-09 |
AgentCore Service-Linked Role Missing
Details and remediationDetails
Service-linked role 'AWSServiceRoleForBedrockAgentCoreNetwork' does not exist. VPC configuration for AgentCore Runtimes will fail without this role. Resolution
Allow iam:CreateServiceLinkedRole for arn:PARTITION:iam::*:role/aws-service-role/network.bedrock-agentcore.amazonaws.com/AWSServiceRoleForBedrockAgentCoreNetwork, replacing PARTITION with the deployment partition, and add StringEquals for iam:AWSServiceName = network.bedrock-agentcore.amazonaws.com. Then configure VPC networking on an AgentCore Runtime so AWS creates the service-linked role. |
Medium | Failed |
444455556666 |
us-east-1 |
AC-01 |
AgentCore VPC Configuration Check
|
Informational | N/A |
444455556666 |
us-east-1 |
AC-04 |
AgentCore Observability Check
|
Informational | N/A |
444455556666 |
us-east-1 |
AC-05 |
AgentCore Encryption Check
|
Informational | N/A |
444455556666 |
us-east-1 |
AC-06 |
AgentCore Browser Session Recording
|
Informational | N/A |
444455556666 |
us-east-1 |
AC-07 |
AgentCore Memory Configuration Check
|
Informational | N/A |
444455556666 |
us-east-1 |
AC-13 |
AgentCore Gateway Configuration Check
|
Informational | N/A |
444455556666 |
us-east-1 |
AC-08 |
AgentCore VPC Endpoints Check
|
Informational | N/A |
444455556666 |
us-east-1 |
AC-10 |
AgentCore Resource-Based Policies Check
|
Informational | N/A |
444455556666 |
us-east-1 |
AC-11 |
AgentCore Policy Engine Encryption Check
|
Informational | N/A |
444455556666 |
us-east-1 |
AC-12 |
AgentCore Gateway Encryption Check
|
Informational | N/A |
444455556666 |
us-east-1 |
AC-14 |
AgentCore Identity Token Vault CMK Encryption
|
High | Failed |
444455556666 |
us-east-1 |
AC-15 |
AgentCore Code Interpreter Network Isolation
|
Informational | N/A |
444455556666 |
us-east-1 |
AC-16 |
AgentCore Custom Browser Network Isolation
|
Informational | N/A |
444455556666 |
us-east-1 |
AC-17 |
AgentCore Online Evaluation Coverage
|
Medium | Failed |
444455556666 |
us-east-1 |
AG-24 |
Agentic AI Gateway Inbound Authorization
|
Informational | N/A |
444455556666 |
us-east-1 |
AG-25 |
Agentic AI Gateway Tool Policy Enforcement
|
Informational | N/A |
444455556666 |
us-east-1 |
AG-26 |
Agentic AI Gateway Error Detail Exposure
|
Informational | N/A |
444455556666 |
us-east-1 |
AG-27 |
Agentic AI Gateway WAF Protection
|
Informational | N/A |
444455556666 |
Global |
AG-16 |
Agentic AI AgentCore Least Privilege
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Over-permissive AgentCore principals can let agents or operators bypass intended autonomy and tool boundaries. Source check AC-02: No roles with overly permissive AgentCore access found Resolution
Replace full-access AgentCore permissions with least-privilege IAM policies scoped to required resources and actions. |
High | Passed |
444455556666 |
Global |
AG-17 |
Agentic AI Stale AgentCore Access
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Unused AgentCore permissions increase the blast radius of compromised principals. Source check AC-03: The following principals have not accessed AgentCore in 60+ days: role 'resco-aiml-security-23026-AgentCoreSecurityAssessme-2AEt2MTxg4AU' (138 days) Resolution
Remove or restrict stale AgentCore permissions for principals that no longer need access. |
Medium | Failed |
444455556666 |
Global |
AG-17 |
Agentic AI Stale AgentCore Access
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Unused AgentCore permissions increase the blast radius of compromised principals. Source check AC-03: The following principals have AgentCore permissions but have never accessed the service: role 'AIMLSecurityMemberRole', role 'AwsSecurityAudit', role 'AWSServiceRoleForSupport', role 'CloudSecAuditRole', role 'CloudSeerTrustedServiceRole', role 'EpoxyAccessRole', role 'IibsAdminAccess-DO-NOT-DELETE', role 'InternalAuditInternal', role 'ManagedInstance-CrossAccountExecutionRole', role 'ProwlerMemberRole' Resolution
Remove or restrict stale AgentCore permissions for principals that no longer need access. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-19 |
Agentic AI Memory Data Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found Resolution
Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-20 |
Agentic AI Private AgentCore Connectivity
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found Resolution
Create required VPC endpoints for AgentCore services and validate endpoint availability. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-21 |
Agentic AI Resource Policy Boundary
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies Resolution
Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-22 |
Agentic AI Policy Engine Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found Resolution
Configure policy engines with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-23 |
Agentic AI Gateway Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found Resolution
Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-28 |
Agentic AI Identity Token Vault Protection
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Agent credentials stored in the Identity token vault should use customer-controlled encryption where enhanced key control is required. Source check AC-14: AgentCore token vault 'default' uses a service-managed or AWS-owned key. Resolution
Configure the AgentCore Identity token vault with a customer-managed KMS key. |
High | Failed |
444455556666 |
us-east-1 |
AG-29 |
Agentic AI Code Interpreter Isolation
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent-executed code should run inside an explicit VPC boundary with controlled network paths. Source check AC-15: No custom AgentCore Code Interpreters found Resolution
Configure custom AgentCore Code Interpreters in VPC mode with approved subnets and security groups. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-31 |
Agentic AI Browser Tool Isolation
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Browser tools can reach external systems and should use explicit private network boundaries. Source check AC-16: No custom AgentCore browsers found Resolution
Configure custom AgentCore browsers in VPC mode with approved subnets and security groups. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-32 |
Agentic AI Online Evaluation Assurance
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Online evaluation provides continuous evidence about agent behavior, quality, and policy-relevant outcomes. Source check AC-17: No AgentCore online evaluation configurations found. Resolution
Configure an active AgentCore online evaluation with sampling, evaluators, CloudWatch input logs, and an output log group. |
Medium | Failed |
444455556666 |
us-west-2 |
AC-01 |
AgentCore VPC Configuration Check
|
Informational | N/A |
444455556666 |
us-west-2 |
AC-04 |
AgentCore Observability Check
|
Informational | N/A |
444455556666 |
us-west-2 |
AC-05 |
AgentCore Encryption Check
|
Informational | N/A |
444455556666 |
us-west-2 |
AC-06 |
AgentCore Browser Session Recording
|
Informational | N/A |
444455556666 |
us-west-2 |
AC-07 |
AgentCore Memory Configuration Check
|
Informational | N/A |
444455556666 |
us-west-2 |
AC-13 |
AgentCore Gateway Configuration Check
|
Informational | N/A |
444455556666 |
us-west-2 |
AC-08 |
AgentCore VPC Endpoints Check
|
Informational | N/A |
444455556666 |
us-west-2 |
AC-10 |
AgentCore Resource-Based Policies Check
|
Informational | N/A |
444455556666 |
us-west-2 |
AC-11 |
AgentCore Policy Engine Encryption Check
|
Informational | N/A |
444455556666 |
us-west-2 |
AC-12 |
AgentCore Gateway Encryption Check
|
Informational | N/A |
444455556666 |
us-west-2 |
AC-14 |
AgentCore Identity Token Vault CMK Encryption
|
Informational | N/A |
444455556666 |
us-west-2 |
AC-15 |
AgentCore Code Interpreter Network Isolation
|
Informational | N/A |
444455556666 |
us-west-2 |
AC-16 |
AgentCore Custom Browser Network Isolation
|
Informational | N/A |
444455556666 |
us-west-2 |
AC-17 |
AgentCore Online Evaluation Coverage
|
Medium | Failed |
444455556666 |
us-west-2 |
AG-24 |
Agentic AI Gateway Inbound Authorization
|
Informational | N/A |
444455556666 |
us-west-2 |
AG-25 |
Agentic AI Gateway Tool Policy Enforcement
|
Informational | N/A |
444455556666 |
us-west-2 |
AG-26 |
Agentic AI Gateway Error Detail Exposure
|
Informational | N/A |
444455556666 |
us-west-2 |
AG-27 |
Agentic AI Gateway WAF Protection
|
Informational | N/A |
444455556666 |
us-west-2 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-19 |
Agentic AI Memory Data Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found Resolution
Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-20 |
Agentic AI Private AgentCore Connectivity
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found Resolution
Create required VPC endpoints for AgentCore services and validate endpoint availability. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-21 |
Agentic AI Resource Policy Boundary
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies Resolution
Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-22 |
Agentic AI Policy Engine Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found Resolution
Configure policy engines with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-23 |
Agentic AI Gateway Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found Resolution
Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-28 |
Agentic AI Identity Token Vault Protection
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Agent credentials stored in the Identity token vault should use customer-controlled encryption where enhanced key control is required. Source check AC-14: No assessable AgentCore Identity token vault was found. Resolution
Configure the AgentCore Identity token vault with a customer-managed KMS key. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-29 |
Agentic AI Code Interpreter Isolation
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent-executed code should run inside an explicit VPC boundary with controlled network paths. Source check AC-15: No custom AgentCore Code Interpreters found Resolution
Configure custom AgentCore Code Interpreters in VPC mode with approved subnets and security groups. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-31 |
Agentic AI Browser Tool Isolation
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Browser tools can reach external systems and should use explicit private network boundaries. Source check AC-16: No custom AgentCore browsers found Resolution
Configure custom AgentCore browsers in VPC mode with approved subnets and security groups. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-32 |
Agentic AI Online Evaluation Assurance
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Online evaluation provides continuous evidence about agent behavior, quality, and policy-relevant outcomes. Source check AC-17: No AgentCore online evaluation configurations found. Resolution
Configure an active AgentCore online evaluation with sampling, evaluators, CloudWatch input logs, and an output log group. |
Medium | Failed |
444455556666 |
us-east-2 |
AC-01 |
AgentCore VPC Configuration Check
|
Informational | N/A |
444455556666 |
us-east-2 |
AC-04 |
AgentCore Observability Check
|
Informational | N/A |
444455556666 |
us-east-2 |
AC-05 |
AgentCore Encryption Check
|
Informational | N/A |
444455556666 |
us-east-2 |
AC-06 |
AgentCore Browser Session Recording
|
Informational | N/A |
444455556666 |
us-east-2 |
AC-07 |
AgentCore Memory Configuration Check
|
Informational | N/A |
444455556666 |
us-east-2 |
AC-13 |
AgentCore Gateway Configuration Check
|
Informational | N/A |
444455556666 |
us-east-2 |
AC-08 |
AgentCore VPC Endpoints Check
|
Informational | N/A |
444455556666 |
us-east-2 |
AC-10 |
AgentCore Resource-Based Policies Check
|
Informational | N/A |
444455556666 |
us-east-2 |
AC-11 |
AgentCore Policy Engine Encryption Check
|
Informational | N/A |
444455556666 |
us-east-2 |
AC-12 |
AgentCore Gateway Encryption Check
|
Informational | N/A |
444455556666 |
us-east-2 |
AC-14 |
AgentCore Identity Token Vault CMK Encryption
|
Informational | N/A |
444455556666 |
us-east-2 |
AC-15 |
AgentCore Code Interpreter Network Isolation
|
Informational | N/A |
444455556666 |
us-east-2 |
AC-16 |
AgentCore Custom Browser Network Isolation
|
Informational | N/A |
444455556666 |
us-east-2 |
AC-17 |
AgentCore Online Evaluation Coverage
|
Medium | Failed |
444455556666 |
us-east-2 |
AG-24 |
Agentic AI Gateway Inbound Authorization
|
Informational | N/A |
444455556666 |
us-east-2 |
AG-25 |
Agentic AI Gateway Tool Policy Enforcement
|
Informational | N/A |
444455556666 |
us-east-2 |
AG-26 |
Agentic AI Gateway Error Detail Exposure
|
Informational | N/A |
444455556666 |
us-east-2 |
AG-27 |
Agentic AI Gateway WAF Protection
|
Informational | N/A |
444455556666 |
us-east-2 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-19 |
Agentic AI Memory Data Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found Resolution
Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-20 |
Agentic AI Private AgentCore Connectivity
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found Resolution
Create required VPC endpoints for AgentCore services and validate endpoint availability. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-21 |
Agentic AI Resource Policy Boundary
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies Resolution
Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-22 |
Agentic AI Policy Engine Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found Resolution
Configure policy engines with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-23 |
Agentic AI Gateway Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found Resolution
Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-28 |
Agentic AI Identity Token Vault Protection
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Agent credentials stored in the Identity token vault should use customer-controlled encryption where enhanced key control is required. Source check AC-14: No assessable AgentCore Identity token vault was found. Resolution
Configure the AgentCore Identity token vault with a customer-managed KMS key. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-29 |
Agentic AI Code Interpreter Isolation
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent-executed code should run inside an explicit VPC boundary with controlled network paths. Source check AC-15: No custom AgentCore Code Interpreters found Resolution
Configure custom AgentCore Code Interpreters in VPC mode with approved subnets and security groups. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-31 |
Agentic AI Browser Tool Isolation
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Browser tools can reach external systems and should use explicit private network boundaries. Source check AC-16: No custom AgentCore browsers found Resolution
Configure custom AgentCore browsers in VPC mode with approved subnets and security groups. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-32 |
Agentic AI Online Evaluation Assurance
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Online evaluation provides continuous evidence about agent behavior, quality, and policy-relevant outcomes. Source check AC-17: No AgentCore online evaluation configurations found. Resolution
Configure an active AgentCore online evaluation with sampling, evaluators, CloudWatch input logs, and an output log group. |
Medium | Failed |
444455556666 |
us-west-2 |
OW-01 |
OWASP LLM01: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis. |
Informational | N/A |
444455556666 |
us-west-2 |
OW-07 |
OWASP LLM07: Model Invocation Logging
Details and remediation |
Informational | N/A |
444455556666 |
us-west-2 |
OW-07 |
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident. |
Informational | N/A |
444455556666 |
us-west-2 |
OW-07 |
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-09 |
OWASP LLM09: Model Evaluation Jobs
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-06 |
OWASP LLM06: Agent Action-Group Least Privilege
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-10 |
OWASP LLM10: Service Quota Throttling Limits
Details and remediation |
Informational | N/A |
444455556666 |
us-west-2 |
OW-01 |
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier. |
Informational | N/A |
444455556666 |
us-west-2 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-02 |
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation |
Informational | N/A |
444455556666 |
us-west-2 |
OW-01 |
OWASP LLM01: Contextual Grounding Guardrail
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-04 |
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation |
Informational | N/A |
444455556666 |
us-west-2 |
OW-09 |
OWASP LLM09: Contextual Grounding for Faithfulness
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-06 |
OWASP LLM06: Bedrock Agent Guardrail Association
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-06 |
OWASP LLM06: Agent Idle Session TTL
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-03 |
OWASP LLM03: Imported-Model KMS Provenance
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-10 |
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation |
Informational | N/A |
444455556666 |
us-west-2 |
OW-03 |
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check BR-33: No Lambda functions with Bedrock indicators were found in us-west-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain. |
Informational | N/A |
444455556666 |
us-west-2 |
OW-01 |
OWASP LLM01: Preventive Prompt Attack Filter
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-02 |
OWASP LLM02: Bedrock Data Retention Boundary
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check BR-37: Bedrock account data retention is inherit; this does not establish an explicit account-level zero-data-retention setting. Resolution
Configure Bedrock account data retention as none and disable provider data sharing when prompts or responses may contain sensitive information. |
High | Failed |
444455556666 |
us-west-2 |
OW-02 |
OWASP LLM02: Automated Reasoning Policy Encryption
Details and remediation |
Informational | N/A |
444455556666 |
us-west-2 |
OW-03 |
OWASP LLM03: Marketplace Endpoint VPC Isolation
Details and remediation |
Informational | N/A |
444455556666 |
us-west-2 |
OW-02 |
OWASP LLM02: Marketplace Endpoint CMK Encryption
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker Internet Exposure
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-01: No SageMaker notebook instances or domains found to check Resolution
Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths. |
Informational | N/A |
444455556666 |
us-west-2 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: No SageMaker resources found to check for data protection Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
Informational | N/A |
444455556666 |
us-west-2 |
OW-01 |
OWASP LLM01: GuardDuty AI Protection
|
High | Failed |
444455556666 |
us-west-2 |
OW-10 |
OWASP LLM10: GuardDuty AI Protection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check SM-26: GuardDuty is enabled, but the AI Protection detector feature is not enabled. Resolution
Enable the GuardDuty AI_PROTECTION detector feature to detect supported anomalous model invocation and cost-harvesting activity. |
High | Failed |
444455556666 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Clarify Evaluation
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation |
Informational | N/A |
444455556666 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Model Monitor Coverage
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker Notebook VPC Deployment
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker Model Network Isolation
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-10 |
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation |
Informational | N/A |
444455556666 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker Container Repository Access
Details and remediation |
Informational | N/A |
444455556666 |
us-west-2 |
OW-02 |
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation |
Informational | N/A |
444455556666 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker AutoML Network Isolation
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically. |
Informational | N/A |
444455556666 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release. |
Informational | N/A |
444455556666 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
444455556666 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
444455556666 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain. |
Informational | N/A |
444455556666 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated. |
Informational | N/A |
444455556666 |
us-west-2 |
OW-02 |
OWASP LLM02: HyperPod Volume CMK Encryption
Details and remediation |
Informational | N/A |
444455556666 |
us-west-2 |
OW-03 |
OWASP LLM03: HyperPod VPC Boundary
Details and remediation |
Informational | N/A |
444455556666 |
us-west-2 |
OW-03 |
OWASP LLM03: Model Registry Resource Policy Boundary
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-06 |
OWASP LLM06: AgentCore Resource-Based Policies
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-02 |
OWASP LLM02: AgentCore Token Vault CMK Encryption
Details and remediation |
Informational | N/A |
444455556666 |
us-west-2 |
OW-06 |
OWASP LLM06: Code Interpreter Network Isolation
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-06 |
OWASP LLM06: Browser Tool Network Isolation
|
Informational | N/A |
444455556666 |
us-west-2 |
OW-11 |
OWASP LLM07: System Prompt Embedded in Lambda Env Var
|
Medium | Passed |
444455556666 |
us-west-2 |
OW-12 |
OWASP LLM07: System-Prompt-Disclosure Denied Topic
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-02 |
Amazon Bedrock private connectivity check
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-04 |
Bedrock Model Invocation Logging Check
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-05 |
Bedrock Guardrails Check
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-06 |
Bedrock CloudTrail Logging Check
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-07 |
Bedrock Prompt Management Check
Details and remediationDetails
Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates |
Informational | N/A |
444455556666 |
us-east-2 |
BR-08 |
Bedrock Agent IAM Roles Check
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-09 |
Bedrock Knowledge Base Encryption Check
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-10 |
Bedrock Guardrail IAM Enforcement Check
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-11 |
Bedrock Custom Model Encryption Check
|
Low | N/A |
444455556666 |
us-east-2 |
BR-12 |
Bedrock Invocation Log Encryption Check
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-13 |
Bedrock Flows Guardrails Check
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-16 |
Guardrail Tier Validation Check
|
Medium | N/A |
444455556666 |
us-east-2 |
BR-17 |
Custom Model Customer-Managed KMS Encryption Check
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-18 |
Model Evaluation Implementation Check
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-19 |
Prompt Flow Validation Check
|
Medium | N/A |
444455556666 |
us-east-2 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Check
|
High | N/A |
444455556666 |
us-east-2 |
BR-21 |
Agent Action Group IAM Least Privilege Check
|
High | N/A |
444455556666 |
us-east-2 |
BR-22 |
Model Invocation Throttling Limits Check
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-23 |
Guardrail Content Filter Coverage Check
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-24 |
Automated Reasoning Policy Implementation Check
|
Medium | N/A |
444455556666 |
us-east-2 |
BR-25 |
RAG Evaluation Jobs Check
|
Low | N/A |
444455556666 |
us-east-2 |
BR-26 |
Guardrail Sensitive Information Filter Check
|
High | N/A |
444455556666 |
us-east-2 |
BR-27 |
Guardrail Contextual Grounding Check
|
Medium | N/A |
444455556666 |
us-east-2 |
BR-28 |
Agent Guardrail Association Check
|
High | N/A |
444455556666 |
us-east-2 |
BR-29 |
Agent Idle Session TTL Check
|
Low | N/A |
444455556666 |
us-east-2 |
BR-30 |
Imported Model Customer-Managed KMS Encryption Check
|
High | N/A |
444455556666 |
us-east-2 |
BR-31 |
Batch Inference Output Encryption Check
|
Medium | N/A |
444455556666 |
us-east-2 |
BR-32 |
Bedrock CloudWatch Alarm Check
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-33 |
Amazon Inspector Lambda Code Scanning Check
Details and remediationDetails
No Lambda functions with Bedrock indicators were found in us-east-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
No action required. If Bedrock-calling Lambda functions exist, ensure their function name, ARN, description, handler, role, or environment variables contain a Bedrock identifier that the assessment can detect, or evaluate Inspector coverage manually. |
Informational | N/A |
444455556666 |
us-east-2 |
BR-34 |
Guardrail Prompt Attack Filter
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-35 |
Guardrail Image Content Filter Coverage
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-36 |
Application Inference Profile Governance
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-37 |
Bedrock Account Data Retention
|
High | Failed |
444455556666 |
us-east-2 |
BR-38 |
Automated Reasoning Policy CMK Encryption
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-39 |
Marketplace Model Endpoint VPC Configuration
|
Informational | N/A |
444455556666 |
us-east-2 |
BR-40 |
Marketplace Model Endpoint CMK Encryption
|
Informational | N/A |
444455556666 |
us-east-2 |
AG-07 |
Agentic AI Model Invocation Logging
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-08 |
Agentic AI API Audit Trail
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage Resolution
Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-10 |
Agentic AI Adversarial Evaluation Coverage
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs Resolution
Configure model or application evaluations that include adversarial, safety, and security-relevant test cases. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-11 |
Agentic AI Prompt Flow Validation
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region Resolution
Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-06 |
Agentic AI Tool Execution Least Privilege
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region Resolution
Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-12 |
Agentic AI Invocation Abuse Controls
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas Resolution
Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-02 |
Agentic AI Harmful Content Guardrail Coverage
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-04 |
Agentic AI Automated Reasoning Guardrails
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: No Bedrock guardrails configured in this region Resolution
Configure automated reasoning policies on guardrails where formal response validation is required. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-03 |
Agentic AI Sensitive Information Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: No Bedrock guardrails configured in this region Resolution
Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-05 |
Agentic AI Grounding Controls
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: No Bedrock guardrails configured in this region Resolution
Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-01 |
Agentic AI Agent Guardrail Association
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region Resolution
Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-13 |
Agentic AI Session Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region Resolution
Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-14 |
Agentic AI Operational Abuse Alarms
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms Resolution
Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available. |
Informational | N/A |
444455556666 |
us-east-2 |
AG-30 |
Agentic AI Prompt Attack Protection
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agents should prevent prompt attacks before untrusted input can redirect planning or tool use. Source check BR-34: No Bedrock guardrails configured in this region Resolution
Enable a preventive PROMPT_ATTACK input filter on each guardrail and use Standard tier where prompt-leakage protection is required. |
Informational | N/A |
444455556666 |
us-east-1 |
OW-01 |
OWASP LLM01: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis. |
Informational | N/A |
444455556666 |
us-east-1 |
OW-07 |
OWASP LLM07: Model Invocation Logging
Details and remediation |
Informational | N/A |
444455556666 |
us-east-1 |
OW-07 |
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident. |
Informational | N/A |
444455556666 |
us-east-1 |
OW-07 |
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-09 |
OWASP LLM09: Model Evaluation Jobs
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-06 |
OWASP LLM06: Agent Action-Group Least Privilege
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-10 |
OWASP LLM10: Service Quota Throttling Limits
Details and remediation |
Informational | N/A |
444455556666 |
us-east-1 |
OW-01 |
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier. |
Informational | N/A |
444455556666 |
us-east-1 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-02 |
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation |
Informational | N/A |
444455556666 |
us-east-1 |
OW-01 |
OWASP LLM01: Contextual Grounding Guardrail
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-04 |
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation |
Informational | N/A |
444455556666 |
us-east-1 |
OW-09 |
OWASP LLM09: Contextual Grounding for Faithfulness
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-06 |
OWASP LLM06: Bedrock Agent Guardrail Association
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-06 |
OWASP LLM06: Agent Idle Session TTL
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-03 |
OWASP LLM03: Imported-Model KMS Provenance
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-10 |
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation |
Informational | N/A |
444455556666 |
us-east-1 |
OW-03 |
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check BR-33: Amazon Inspector Lambda standard scanning and Lambda code scanning are both ENABLED in us-east-1. Detected 2 Lambda function(s) with Bedrock indicators: aiml-security-aiml-security-444455556666-BedrockAssessment, resco-aiml-BedrockAssessment. Resolution
Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain. |
Medium | Passed |
444455556666 |
us-east-1 |
OW-01 |
OWASP LLM01: Preventive Prompt Attack Filter
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-02 |
OWASP LLM02: Bedrock Data Retention Boundary
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check BR-37: Bedrock account data retention is inherit; this does not establish an explicit account-level zero-data-retention setting. Resolution
Configure Bedrock account data retention as none and disable provider data sharing when prompts or responses may contain sensitive information. |
High | Failed |
444455556666 |
us-east-1 |
OW-02 |
OWASP LLM02: Automated Reasoning Policy Encryption
Details and remediation |
Informational | N/A |
444455556666 |
us-east-1 |
OW-03 |
OWASP LLM03: Marketplace Endpoint VPC Isolation
Details and remediation |
Informational | N/A |
444455556666 |
us-east-1 |
OW-02 |
OWASP LLM02: Marketplace Endpoint CMK Encryption
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Internet Exposure
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-01: No SageMaker notebook instances or domains found to check Resolution
Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths. |
Informational | N/A |
444455556666 |
us-east-1 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: No SageMaker resources found to check for data protection Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
Informational | N/A |
444455556666 |
us-east-1 |
OW-01 |
OWASP LLM01: GuardDuty AI Protection
|
High | Failed |
444455556666 |
us-east-1 |
OW-10 |
OWASP LLM10: GuardDuty AI Protection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check SM-26: GuardDuty is enabled, but the AI Protection detector feature is not enabled. Resolution
Enable the GuardDuty AI_PROTECTION detector feature to detect supported anomalous model invocation and cost-harvesting activity. |
High | Failed |
444455556666 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Clarify Evaluation
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation |
Informational | N/A |
444455556666 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Model Monitor Coverage
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Notebook VPC Deployment
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Model Network Isolation
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-10 |
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation |
Informational | N/A |
444455556666 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Container Repository Access
Details and remediation |
Informational | N/A |
444455556666 |
us-east-1 |
OW-02 |
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation |
Informational | N/A |
444455556666 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker AutoML Network Isolation
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically. |
Informational | N/A |
444455556666 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release. |
Informational | N/A |
444455556666 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
444455556666 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
444455556666 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain. |
Informational | N/A |
444455556666 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated. |
Informational | N/A |
444455556666 |
us-east-1 |
OW-02 |
OWASP LLM02: HyperPod Volume CMK Encryption
Details and remediation |
Informational | N/A |
444455556666 |
us-east-1 |
OW-03 |
OWASP LLM03: HyperPod VPC Boundary
Details and remediation |
Informational | N/A |
444455556666 |
us-east-1 |
OW-03 |
OWASP LLM03: Model Registry Resource Policy Boundary
|
Informational | N/A |
444455556666 |
Global |
OW-06 |
OWASP LLM06: AgentCore IAM Least Privilege
|
High | Passed |
444455556666 |
us-east-1 |
OW-06 |
OWASP LLM06: AgentCore Resource-Based Policies
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-02 |
OWASP LLM02: AgentCore Token Vault CMK Encryption
Details and remediation |
High | Failed |
444455556666 |
us-east-1 |
OW-06 |
OWASP LLM06: Code Interpreter Network Isolation
|
Informational | N/A |
444455556666 |
us-east-1 |
OW-06 |
OWASP LLM06: Browser Tool Network Isolation
|
Informational | N/A |
444455556666 |
Global |
OW-10 |
OWASP LLM10: WAF Rate-Based & Shield Protection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-01: AWS Shield Advanced is not subscribed. GenAI API endpoints are vulnerable to volumetric DDoS attacks that can exhaust token quotas and inflate costs. Resolution
Add a WAF RateBasedStatement plus a SizeConstraintStatement on the GenAI ingress and subscribe to AWS Shield Advanced. |
Low | Failed |
444455556666 |
Global |
OW-10 |
OWASP LLM10: WAF Rate-Based & Shield Protection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-01: No AWS WAF regional Web ACLs found. Without WAF, GenAI endpoints lack rate-based rules to block abusive callers. Resolution
Add a WAF RateBasedStatement plus a SizeConstraintStatement on the GenAI ingress and subscribe to AWS Shield Advanced. |
Medium | Failed |
444455556666 |
Global |
OW-10 |
OWASP LLM10: API Gateway Usage Plans
|
Informational | N/A |
444455556666 |
Global |
OW-10 |
OWASP LLM10: Bedrock TPM/RPM Quotas Customised
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-03: Found 266 Bedrock token-based quota(s); at least one applied value exceeds the AWS default, indicating quotas have been reviewed and raised. Resolution
Customise Bedrock service quotas above the account default so consumption is explicitly bounded. |
Medium | Passed |
444455556666 |
Global |
OW-10 |
OWASP LLM10: Cost Anomaly Detection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-04: No AWS Cost Anomaly Detection monitors found. Unexpected spikes in Bedrock/SageMaker usage (e.g., from prompt injection loops) will go undetected. Resolution
Configure AWS Cost Anomaly Detection monitors that include Bedrock and SageMaker. |
Medium | Failed |
444455556666 |
Global |
OW-10 |
OWASP LLM10: Token / Throttle Alarms
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-05: No CloudWatch alarms found for Bedrock metrics. Token exhaustion and throttling events will not trigger operational alerts. Resolution
Create CloudWatch alarms on the Bedrock namespace for InvocationThrottles and token counters. |
Medium | Failed |
444455556666 |
Global |
OW-10 |
OWASP LLM10: AWS Budgets with Bedrock Filters
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-06: No AWS Budgets found scoped to Bedrock or SageMaker. Unbounded GenAI spend can go undetected until the monthly bill. Resolution
Configure AWS Budgets with FilterExpression / CostFilters targeting Bedrock or SageMaker spend, with an alerting SNS action. |
Medium | Failed |
444455556666 |
Global |
OW-06 |
OWASP LLM06: Agent Execution Role Least Privilege
|
Informational | N/A |
444455556666 |
Global |
OW-06 |
OWASP LLM06: AgentCore Gateway Policy Engine
|
Informational | N/A |
444455556666 |
Global |
OW-06 |
OWASP LLM06: Agent Tool Concurrency Limits
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check FS-09: Agent-related Lambda functions without reserved concurrency: aiml-security-aiml-security-444455556666-AgentCoreAssessment, aiml-security-aiml-security-444455556666-RAIGRCAssessment, aiml-security-aiml-security-444455556666-AgentRegistryAssessment, aiml-security-aiml-security-444455556666-SagemakerAssessment, resco-aiml-BedrockAssessment, aiml-security-aiml-security-444455556666-BedrockAssessment, aiml-security-aiml-security-444455556666-GenerateReport, resco-aiml-GenerateReport, resco-aiml-IAMPermissionCaching, resco-aiml-CleanupBucket. Unlimited concurrency allows runaway agent loops to exhaust account limits. Resolution
Set reserved concurrency on agent action-group Lambdas so a runaway agent cannot exhaust downstream capacity. |
Medium | Failed |
444455556666 |
Global |
OW-06 |
OWASP LLM06: Human-in-the-Loop Callback States
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check FS-10: No Step Functions state machines with agent/approval naming found. Verify that high-risk agent actions (e.g., fund transfers, account changes) have human approval gates. Resolution
Insert Step Functions .waitForTaskToken callback states before any high-risk agent-triggered action. |
Informational | N/A |
444455556666 |
Global |
OW-03 |
OWASP LLM03: SCP-Enforced Model Allowlist
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check FS-12: Account is not part of an AWS Organization or lacks SCP read access. Resolution
Attach an Organizations SCP that denies Bedrock inference outside allowlisted model and inference-profile ARNs using Resource or NotResource scoping. |
Informational | N/A |
444455556666 |
Global |
OW-03 |
OWASP LLM03: Custom-Model Provenance Tags
|
Medium | Passed |
444455556666 |
Global |
OW-03 |
OWASP LLM03: Config Rules for Model Onboarding
|
Medium | Passed |
444455556666 |
Global |
OW-03 |
OWASP LLM03: Adversarial Evaluation Coverage
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check FS-15: No Bedrock Model Evaluation jobs found. Models have not been evaluated for adversarial robustness. Model-risk management (SR 11-7) expects documented model validation/evaluation. Resolution
Run Bedrock evaluation jobs that include adversarial and safety datasets before promoting a model to production. |
Medium | Failed |
444455556666 |
Global |
OW-03 |
OWASP LLM03: ECR Image Scanning
|
Informational | N/A |
444455556666 |
Global |
OW-04 |
OWASP LLM04: Feature Store Offline Recovery
Details and remediation |
Informational | N/A |
444455556666 |
Global |
OW-04 |
OWASP LLM04: Training-Data Versioning
|
Informational | N/A |
444455556666 |
Global |
OW-08 |
OWASP LLM08: KB IAM Scope
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-22: 637 role(s) with wildcard KB permissions: - Role 'Admin' allows '*' - Role 'aiml-security-23026652352-BedrockSecurityAssessment-UZzmVN1xrMwf' allows 'bedrock:ListGuardrails' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-23026652352-BedrockSecurityAssessment-UZzmVN1xrMwf' allows 'bedrock:GetGuardrail' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-23026652352-BedrockSecurityAssessment-UZzmVN1xrMwf' allows 'bedrock:ListModelInvocationJobs' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-23026652352-BedrockSecurityAssessment-UZzmVN1xrMwf' allows 'bedrock:GetModelInvocationLoggingConfiguration' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-23026652352-BedrockSecurityAssessment-UZzmVN1xrMwf' allows 'bedrock:ListPrompts' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-23026652352-BedrockSecurityAssessment-UZzmVN1xrMwf' allows 'bedrock:GetPrompt' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-23026652352-BedrockSecurityAssessment-UZzmVN1xrMwf' allows 'bedrock:ListAgents' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-23026652352-BedrockSecurityAssessment-UZzmVN1xrMwf' allows 'bedrock:GetAgent' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-23026652352-BedrockSecurityAssessment-UZzmVN1xrMwf' allows 'bedrock:ListCustomModels' on Resource '*' (no ARN scoping to specific Knowledge Bases) Resolution
Scope Knowledge Base IAM roles to specific KB ARNs; remove wildcard bedrock:* on KB actions. |
High | Failed |
444455556666 |
Global |
OW-08 |
OWASP LLM08: KB Metadata Filtering
|
Informational | N/A |
444455556666 |
Global |
OW-08 |
OWASP LLM08: OpenSearch Serverless Encryption
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-25: No OpenSearch Serverless collections exist in this region, so there is no OpenSearch vector-store data at rest to encrypt. If Bedrock Knowledge Bases use a different vector store (S3 Vectors, Aurora, Pinecone), verify its encryption separately. Resolution
Use a customer-managed KMS key on the OpenSearch Serverless encryption policy for the vector collection. |
Informational | N/A |
444455556666 |
Global |
OW-08 |
OWASP LLM08: OpenSearch Serverless Network Policy
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-26: No OpenSearch Serverless network policies found. Vector store collections may be publicly accessible. Resolution
Set AllowFromPublic=false on the OpenSearch Serverless network policy and restrict access to bedrock.amazonaws.com or a specific VPC endpoint. |
High | Failed |
444455556666 |
Global |
OW-09 |
OWASP LLM09: Knowledge-Base Ingestion Freshness
|
Informational | N/A |
444455556666 |
Global |
OW-09 |
OWASP LLM09: Source Attribution
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check FS-32: Source attribution in GenAI responses cannot be verified via AWS APIs. Manual review required to confirm responses include citations. Resolution
Return citations in RetrieveAndGenerate responses so end users can verify grounding. |
Informational | N/A |
444455556666 |
Global |
OW-09 |
OWASP LLM09: KB S3 Data-Source Integrity
|
Informational | N/A |
444455556666 |
Global |
OW-04 |
OWASP LLM04: SageMaker Model Card Documentation
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check FS-42: No SageMaker Model Cards found. If GenAI workloads run on Bedrock rather than SageMaker, model documentation may legitimately live elsewhere; Model Cards are a SageMaker-specific artifact. Resolution
Create SageMaker Model Cards for production models that document intended use, training data provenance, and bias/fairness evaluations so poisoned or drifted models are detectable against a documented baseline. |
Informational | N/A |
444455556666 |
Global |
OW-09 |
OWASP LLM09: SageMaker Model Card Documentation
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check FS-42: No SageMaker Model Cards found. If GenAI workloads run on Bedrock rather than SageMaker, model documentation may legitimately live elsewhere; Model Cards are a SageMaker-specific artifact. Resolution
Document each production model's intended use, known limitations, and evaluation results in a SageMaker Model Card so misinformation risks tied to model behaviour are traceable to a reviewed system card. |
Informational | N/A |
444455556666 |
Global |
OW-02 |
OWASP LLM02: CloudWatch Log Data Protection Policies
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-43: Bedrock model invocation logging is not enabled, so no invocation logs are being delivered and there is no log content to mask. Prompt and completion content is therefore also unavailable for audit. Resolution
Apply a CloudWatch Logs data protection policy to log groups that receive Bedrock invocation logs. |
Informational | N/A |
444455556666 |
Global |
OW-02 |
OWASP LLM02: Macie Sensitive-Data Discovery
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-44: Amazon Macie is enabled, but the automated sensitive data discovery status could not be read (AccessDeniedException), so whether anything is actually being scanned is unknown. Resolution
Enable Amazon Macie with automated discovery on S3 buckets that hold training or knowledge-base data. |
Informational | N/A |
444455556666 |
Global |
OW-02 |
OWASP LLM02: Guardrail PII Entities Coverage
|
Informational | N/A |
444455556666 |
Global |
OW-02 |
OWASP LLM02: S3 Data-Classification Tagging
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-46: No S3 buckets with AI/ML naming found. Resolution
Tag training and knowledge-base S3 buckets with a data-classification tag so downstream automations enforce controls consistent with the sensitivity level. |
Informational | N/A |
444455556666 |
Global |
OW-09 |
OWASP LLM09: Grounding Filter Threshold
|
Informational | N/A |
444455556666 |
Global |
OW-09 |
OWASP LLM09: Active Knowledge Base Present
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check FS-48: No active Bedrock Knowledge Bases found. GenAI responses are not grounded in authoritative data sources, increasing hallucination risk. Resolution
Deploy at least one ACTIVE Knowledge Base when Bedrock models are used, so grounded retrieval is available. |
Medium | Failed |
444455556666 |
Global |
OW-01 |
OWASP LLM01: PROMPT_ATTACK Filter at Standard Tier
|
Informational | N/A |
444455556666 |
Global |
OW-01 |
OWASP LLM01: Bedrock-Calling Lambda Runtimes
|
Medium | Passed |
444455556666 |
Global |
OW-01 |
OWASP LLM01: WAF SQLi & KnownBadInputs Coverage
|
Informational | N/A |
444455556666 |
Global |
OW-01 |
OWASP LLM01: Adversarial Testing Evidence
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check FS-54: Penetration testing evidence cannot be verified via AWS APIs. Manual review required to confirm GenAI applications have been tested. Resolution
Track adversarial / red-team penetration test evidence for the GenAI application via resource tags or an equivalent audit trail. |
Informational | N/A |
444455556666 |
Global |
OW-05 |
OWASP LLM05: Output-Validation Lambda
Details and remediationDetails
OWASP category: LLM05:2025 Improper Output Handling. Source check FS-55: No Lambda functions with output validation/sanitization naming found. GenAI outputs may be passed directly to downstream systems without validation. Resolution
Deploy an output-validation / sanitisation Lambda between the model response and any downstream consumer to filter injection payloads in generated output. |
Medium | Failed |
444455556666 |
Global |
OW-05 |
OWASP LLM05: WAF XSS Protection
|
Informational | N/A |
444455556666 |
Global |
OW-05 |
OWASP LLM05: Output Encoding Libraries
Details and remediationDetails
OWASP category: LLM05:2025 Improper Output Handling. Source check FS-57: Output encoding practices cannot be verified via AWS APIs. Manual code review required. Resolution
Ensure Lambdas that render model output use a well-known output-encoding library appropriate to the downstream sink (HTML, SQL, shell, etc.). |
Informational | N/A |
444455556666 |
Global |
OW-05 |
OWASP LLM05: Step Functions Output Schema Validation
Details and remediationDetails
OWASP category: LLM05:2025 Improper Output Handling. Source check FS-58: Found 0 Lambda function(s) whose names suggest schema/validation handling. Structured-output / JSON-schema validation of GenAI responses is an application-layer control that cannot be verified automatically — manual review required. Resolution
Add explicit schema-validation states in Step Functions workflows that consume model output. |
Informational | N/A |
444455556666 |
Global |
OW-06 |
OWASP LLM06: Agent Transaction Thresholds
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check FS-67: The following agent action-group Lambda functions have no environment variables whose names suggest transaction-value threshold configuration (this is a best-effort heuristic — a threshold enforced in code or in an AgentCore Policy Engine rule would not be detected here, so treat this as a prompt for manual verification rather than a definitive gap). Without explicit limits, agents could initiate unbounded financial transactions: - resco-aiml-BedrockAssessment - resco-aiml-AgentCoreAssessment Resolution
Encode agent transaction thresholds in Cedar policies or Lambda configuration so per-action limits are enforced. |
High | Failed |
444455556666 |
Global |
OW-10 |
OWASP LLM10: API Gateway Request Body Size Limits
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-68: Found 5 REST API(s) and 0 regional WAF Web ACL(s), but none enforce a maximum request-body size. Note: an API Gateway request validator does NOT cap body size (it validates the schema and required params; the REST limit is a fixed 10 MB), and a WAF body SizeConstraint only inspects the first ~16 KB of the body by default. Oversized prompts can exhaust Bedrock token quotas and inflate costs. Resolution
Configure API Gateway request validation or an equivalent ingress control so GenAI endpoints reject oversized request bodies before they can drive excessive model consumption. |
Medium | Failed |
444455556666 |
Global |
OW-01 |
OWASP LLM01: Prompt-Input Validation Lambda
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check FS-69: Found 2 Lambda function(s) with input validation/sanitization naming patterns: resco-aiml-CleanupBucket, aiml-security-aiml-security-444455556666-CleanupBucket. Resolution
Deploy a prompt-input validation Lambda in front of Bedrock invocations to sanitise untrusted input before it reaches the model. |
Medium | Passed |
444455556666 |
us-east-1 |
OW-11 |
OWASP LLM07: System Prompt Embedded in Lambda Env Var
|
Medium | Passed |
444455556666 |
us-east-1 |
OW-12 |
OWASP LLM07: System-Prompt-Disclosure Denied Topic
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-02 |
Amazon Bedrock private connectivity check
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-04 |
Bedrock Model Invocation Logging Check
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-05 |
Bedrock Guardrails Check
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-06 |
Bedrock CloudTrail Logging Check
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-07 |
Bedrock Prompt Management Check
Details and remediationDetails
Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates |
Informational | N/A |
444455556666 |
us-west-2 |
BR-08 |
Bedrock Agent IAM Roles Check
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-09 |
Bedrock Knowledge Base Encryption Check
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-10 |
Bedrock Guardrail IAM Enforcement Check
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-11 |
Bedrock Custom Model Encryption Check
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-12 |
Bedrock Invocation Log Encryption Check
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-13 |
Bedrock Flows Guardrails Check
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-16 |
Guardrail Tier Validation Check
|
Medium | N/A |
444455556666 |
us-west-2 |
BR-17 |
Custom Model Customer-Managed KMS Encryption Check
|
High | N/A |
444455556666 |
us-west-2 |
BR-18 |
Model Evaluation Implementation Check
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-19 |
Prompt Flow Validation Check
|
Medium | N/A |
444455556666 |
us-west-2 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Check
|
High | N/A |
444455556666 |
us-west-2 |
BR-21 |
Agent Action Group IAM Least Privilege Check
|
High | N/A |
444455556666 |
us-west-2 |
BR-22 |
Model Invocation Throttling Limits Check
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-23 |
Guardrail Content Filter Coverage Check
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-24 |
Automated Reasoning Policy Implementation Check
|
Medium | N/A |
444455556666 |
us-west-2 |
BR-25 |
RAG Evaluation Jobs Check
|
Low | N/A |
444455556666 |
us-west-2 |
BR-26 |
Guardrail Sensitive Information Filter Check
|
High | N/A |
444455556666 |
us-west-2 |
BR-27 |
Guardrail Contextual Grounding Check
|
Medium | N/A |
444455556666 |
us-west-2 |
BR-28 |
Agent Guardrail Association Check
|
High | N/A |
444455556666 |
us-west-2 |
BR-29 |
Agent Idle Session TTL Check
|
Low | N/A |
444455556666 |
us-west-2 |
BR-30 |
Imported Model Customer-Managed KMS Encryption Check
|
High | N/A |
444455556666 |
us-west-2 |
BR-31 |
Batch Inference Output Encryption Check
|
Medium | N/A |
444455556666 |
us-west-2 |
BR-32 |
Bedrock CloudWatch Alarm Check
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-33 |
Amazon Inspector Lambda Code Scanning Check
Details and remediationDetails
No Lambda functions with Bedrock indicators were found in us-west-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
No action required. If Bedrock-calling Lambda functions exist, ensure their function name, ARN, description, handler, role, or environment variables contain a Bedrock identifier that the assessment can detect, or evaluate Inspector coverage manually. |
Informational | N/A |
444455556666 |
us-west-2 |
BR-34 |
Guardrail Prompt Attack Filter
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-35 |
Guardrail Image Content Filter Coverage
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-36 |
Application Inference Profile Governance
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-37 |
Bedrock Account Data Retention
|
High | Failed |
444455556666 |
us-west-2 |
BR-38 |
Automated Reasoning Policy CMK Encryption
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-39 |
Marketplace Model Endpoint VPC Configuration
|
Informational | N/A |
444455556666 |
us-west-2 |
BR-40 |
Marketplace Model Endpoint CMK Encryption
|
Informational | N/A |
444455556666 |
us-west-2 |
AG-07 |
Agentic AI Model Invocation Logging
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-08 |
Agentic AI API Audit Trail
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage Resolution
Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-10 |
Agentic AI Adversarial Evaluation Coverage
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs Resolution
Configure model or application evaluations that include adversarial, safety, and security-relevant test cases. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-11 |
Agentic AI Prompt Flow Validation
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region Resolution
Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-06 |
Agentic AI Tool Execution Least Privilege
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region Resolution
Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-12 |
Agentic AI Invocation Abuse Controls
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas Resolution
Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-02 |
Agentic AI Harmful Content Guardrail Coverage
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-04 |
Agentic AI Automated Reasoning Guardrails
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: No Bedrock guardrails configured in this region Resolution
Configure automated reasoning policies on guardrails where formal response validation is required. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-03 |
Agentic AI Sensitive Information Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: No Bedrock guardrails configured in this region Resolution
Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-05 |
Agentic AI Grounding Controls
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: No Bedrock guardrails configured in this region Resolution
Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-01 |
Agentic AI Agent Guardrail Association
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region Resolution
Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-13 |
Agentic AI Session Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region Resolution
Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-14 |
Agentic AI Operational Abuse Alarms
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms Resolution
Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available. |
Informational | N/A |
444455556666 |
us-west-2 |
AG-30 |
Agentic AI Prompt Attack Protection
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agents should prevent prompt attacks before untrusted input can redirect planning or tool use. Source check BR-34: No Bedrock guardrails configured in this region Resolution
Enable a preventive PROMPT_ATTACK input filter on each guardrail and use Standard tier where prompt-leakage protection is required. |
Informational | N/A |
444455556666 |
us-east-2 |
SM-01 |
Direct Internet Access Enabled
|
High | Failed |
444455556666 |
us-east-2 |
SM-02 |
SageMaker SSO Configuration Check
|
Medium | Passed |
444455556666 |
us-east-2 |
SM-03 |
Missing Encryption Configuration
|
High | Failed |
444455556666 |
us-east-2 |
SM-04 |
GuardDuty Enabled
|
Medium | Passed |
444455556666 |
us-east-2 |
SM-26 |
GuardDuty AI Protection
|
High | Failed |
444455556666 |
us-east-2 |
SM-05 |
SageMaker Model Registry Issue
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-05 |
SageMaker Feature Store Issue
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-05 |
SageMaker Pipelines Issue
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-06 |
SageMaker Clarify No Clarify Usage
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-07 |
SageMaker Model Monitor No Model Monitoring
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-08 |
Model Registry Registry Not Used
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-09 |
SageMaker Notebook Root Access Enabled
Details and remediationDetails
Notebook instance 'aws-neptune-Mybookstore-Bookstore-WS-Notebook' has root access enabled. Root access allows users to install arbitrary software, modify system configurations, and potentially escalate privileges. Resolution
Disable root access by updating the notebook instance with RootAccess=Disabled. Note: Lifecycle configurations will still run with root access. |
High | Failed |
444455556666 |
us-east-2 |
SM-10 |
SageMaker Notebook VPC Deployment Check
|
High | Passed |
444455556666 |
us-east-2 |
SM-11 |
SageMaker Model Network Isolation Check
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-12 |
SageMaker Endpoint Instance Count Check
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-13 |
SageMaker Monitoring Network Isolation Check
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-14 |
SageMaker Model Repository Access Check
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-15 |
SageMaker Feature Store Encryption Check
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-16 |
SageMaker Data Quality Job Encryption Check
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-17 |
SageMaker Processing Job Encryption Check
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-18 |
SageMaker Transform Job Encryption Check
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-19 |
SageMaker Hyperparameter Tuning Job Encryption Check
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-20 |
SageMaker Compilation Job Encryption Check
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-21 |
SageMaker AutoML Job Network Isolation Check
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-22 |
Model Approval Workflow Check
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-23 |
Model Drift Detection Check
|
Medium | Passed |
444455556666 |
us-east-2 |
SM-24 |
A/B Testing and Shadow Deployment Check
|
Low | Passed |
444455556666 |
us-east-2 |
SM-25 |
ML Lineage Tracking - Experiments Not Used
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-27 |
HyperPod EBS CMK Encryption
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-28 |
HyperPod VPC Configuration
|
Informational | N/A |
444455556666 |
us-east-2 |
SM-30 |
Model Package Group Resource Policy Exposure
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-01 |
SageMaker Internet Access Check
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-02 |
SageMaker SSO Configuration Check
|
Medium | Passed |
444455556666 |
us-west-2 |
SM-03 |
Data Protection Check
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-04 |
GuardDuty Enabled
|
Medium | Passed |
444455556666 |
us-west-2 |
SM-26 |
GuardDuty AI Protection
|
High | Failed |
444455556666 |
us-west-2 |
SM-05 |
SageMaker Model Registry Issue
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-05 |
SageMaker Feature Store Issue
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-05 |
SageMaker Pipelines Issue
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-06 |
SageMaker Clarify No Clarify Usage
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-07 |
SageMaker Model Monitor No Model Monitoring
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-08 |
Model Registry Registry Not Used
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-09 |
SageMaker Notebook Root Access Check
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-10 |
SageMaker Notebook VPC Deployment Check
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-11 |
SageMaker Model Network Isolation Check
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-12 |
SageMaker Endpoint Instance Count Check
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-13 |
SageMaker Monitoring Network Isolation Check
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-14 |
SageMaker Model Repository Access Check
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-15 |
SageMaker Feature Store Encryption Check
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-16 |
SageMaker Data Quality Job Encryption Check
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-17 |
SageMaker Processing Job Encryption Check
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-18 |
SageMaker Transform Job Encryption Check
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-19 |
SageMaker Hyperparameter Tuning Job Encryption Check
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-20 |
SageMaker Compilation Job Encryption Check
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-21 |
SageMaker AutoML Job Network Isolation Check
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-22 |
Model Approval Workflow Check
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-23 |
Model Drift Detection Check
|
Medium | Passed |
444455556666 |
us-west-2 |
SM-24 |
A/B Testing and Shadow Deployment Check
|
Low | Passed |
444455556666 |
us-west-2 |
SM-25 |
ML Lineage Tracking - Experiments Not Used
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-27 |
HyperPod EBS CMK Encryption
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-28 |
HyperPod VPC Configuration
|
Informational | N/A |
444455556666 |
us-west-2 |
SM-30 |
Model Package Group Resource Policy Exposure
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-01 |
OWASP LLM01: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis. |
Informational | N/A |
444455556666 |
us-east-2 |
OW-07 |
OWASP LLM07: Model Invocation Logging
Details and remediation |
Informational | N/A |
444455556666 |
us-east-2 |
OW-07 |
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident. |
Informational | N/A |
444455556666 |
us-east-2 |
OW-07 |
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-09 |
OWASP LLM09: Model Evaluation Jobs
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-06 |
OWASP LLM06: Agent Action-Group Least Privilege
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-10 |
OWASP LLM10: Service Quota Throttling Limits
Details and remediation |
Informational | N/A |
444455556666 |
us-east-2 |
OW-01 |
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier. |
Informational | N/A |
444455556666 |
us-east-2 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-02 |
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation |
Informational | N/A |
444455556666 |
us-east-2 |
OW-01 |
OWASP LLM01: Contextual Grounding Guardrail
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-04 |
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation |
Informational | N/A |
444455556666 |
us-east-2 |
OW-09 |
OWASP LLM09: Contextual Grounding for Faithfulness
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-06 |
OWASP LLM06: Bedrock Agent Guardrail Association
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-06 |
OWASP LLM06: Agent Idle Session TTL
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-03 |
OWASP LLM03: Imported-Model KMS Provenance
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-10 |
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation |
Informational | N/A |
444455556666 |
us-east-2 |
OW-03 |
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check BR-33: No Lambda functions with Bedrock indicators were found in us-east-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain. |
Informational | N/A |
444455556666 |
us-east-2 |
OW-01 |
OWASP LLM01: Preventive Prompt Attack Filter
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-02 |
OWASP LLM02: Bedrock Data Retention Boundary
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check BR-37: Bedrock account data retention is inherit; this does not establish an explicit account-level zero-data-retention setting. Resolution
Configure Bedrock account data retention as none and disable provider data sharing when prompts or responses may contain sensitive information. |
High | Failed |
444455556666 |
us-east-2 |
OW-02 |
OWASP LLM02: Automated Reasoning Policy Encryption
Details and remediation |
Informational | N/A |
444455556666 |
us-east-2 |
OW-03 |
OWASP LLM03: Marketplace Endpoint VPC Isolation
Details and remediation |
Informational | N/A |
444455556666 |
us-east-2 |
OW-02 |
OWASP LLM02: Marketplace Endpoint CMK Encryption
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker Internet Exposure
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-01: SageMaker notebook instance 'aws-neptune-Mybookstore-Bookstore-WS-Notebook' has direct internet access enabled Resolution
Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths. |
High | Failed |
444455556666 |
us-east-2 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: Notebook Instance 'aws-neptune-Mybookstore-Bookstore-WS-Notebook' - No KMS key configured Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
High | Failed |
444455556666 |
us-east-2 |
OW-01 |
OWASP LLM01: GuardDuty AI Protection
|
High | Failed |
444455556666 |
us-east-2 |
OW-10 |
OWASP LLM10: GuardDuty AI Protection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check SM-26: GuardDuty is enabled, but the AI Protection detector feature is not enabled. Resolution
Enable the GuardDuty AI_PROTECTION detector feature to detect supported anomalous model invocation and cost-harvesting activity. |
High | Failed |
444455556666 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Clarify Evaluation
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation |
Informational | N/A |
444455556666 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Model Monitor Coverage
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker Notebook VPC Deployment
Details and remediation |
High | Passed |
444455556666 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker Model Network Isolation
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-10 |
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation |
Informational | N/A |
444455556666 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker Container Repository Access
Details and remediation |
Informational | N/A |
444455556666 |
us-east-2 |
OW-02 |
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation |
Informational | N/A |
444455556666 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker AutoML Network Isolation
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically. |
Informational | N/A |
444455556666 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release. |
Informational | N/A |
444455556666 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
444455556666 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
444455556666 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain. |
Informational | N/A |
444455556666 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated. |
Informational | N/A |
444455556666 |
us-east-2 |
OW-02 |
OWASP LLM02: HyperPod Volume CMK Encryption
Details and remediation |
Informational | N/A |
444455556666 |
us-east-2 |
OW-03 |
OWASP LLM03: HyperPod VPC Boundary
Details and remediation |
Informational | N/A |
444455556666 |
us-east-2 |
OW-03 |
OWASP LLM03: Model Registry Resource Policy Boundary
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-06 |
OWASP LLM06: AgentCore Resource-Based Policies
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-02 |
OWASP LLM02: AgentCore Token Vault CMK Encryption
Details and remediation |
Informational | N/A |
444455556666 |
us-east-2 |
OW-06 |
OWASP LLM06: Code Interpreter Network Isolation
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-06 |
OWASP LLM06: Browser Tool Network Isolation
|
Informational | N/A |
444455556666 |
us-east-2 |
OW-11 |
OWASP LLM07: System Prompt Embedded in Lambda Env Var
|
Medium | Passed |
444455556666 |
us-east-2 |
OW-12 |
OWASP LLM07: System-Prompt-Disclosure Denied Topic
|
Informational | N/A |
444455556666 |
Global |
SM-02 |
SageMaker IAM Permissions Check
|
High | Passed |
444455556666 |
us-east-1 |
SM-01 |
SageMaker Internet Access Check
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-02 |
SageMaker SSO Configuration Check
|
Medium | Passed |
444455556666 |
us-east-1 |
SM-03 |
Data Protection Check
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-04 |
GuardDuty Enabled
|
Medium | Passed |
444455556666 |
us-east-1 |
SM-26 |
GuardDuty AI Protection
|
High | Failed |
444455556666 |
us-east-1 |
SM-05 |
SageMaker Model Registry Issue
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-05 |
SageMaker Feature Store Issue
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-05 |
SageMaker Pipelines Issue
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-06 |
SageMaker Clarify No Clarify Usage
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-07 |
SageMaker Model Monitor No Model Monitoring
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-08 |
Model Registry Registry Not Used
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-09 |
SageMaker Notebook Root Access Check
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-10 |
SageMaker Notebook VPC Deployment Check
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-11 |
SageMaker Model Network Isolation Check
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-12 |
SageMaker Endpoint Instance Count Check
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-13 |
SageMaker Monitoring Network Isolation Check
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-14 |
SageMaker Model Repository Access Check
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-15 |
SageMaker Feature Store Encryption Check
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-16 |
SageMaker Data Quality Job Encryption Check
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-17 |
SageMaker Processing Job Encryption Check
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-18 |
SageMaker Transform Job Encryption Check
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-19 |
SageMaker Hyperparameter Tuning Job Encryption Check
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-20 |
SageMaker Compilation Job Encryption Check
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-21 |
SageMaker AutoML Job Network Isolation Check
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-22 |
Model Approval Workflow Check
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-23 |
Model Drift Detection Check
|
Medium | Passed |
444455556666 |
us-east-1 |
SM-24 |
A/B Testing and Shadow Deployment Check
|
Low | Passed |
444455556666 |
us-east-1 |
SM-25 |
ML Lineage Tracking - Experiments Not Used
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-27 |
HyperPod EBS CMK Encryption
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-28 |
HyperPod VPC Configuration
|
Informational | N/A |
444455556666 |
us-east-1 |
SM-30 |
Model Package Group Resource Policy Exposure
|
Informational | N/A |
444455556666 |
Global |
FS-01 |
AWS Shield Advanced Not Enabled
Details and remediationDetails
AWS Shield Advanced is not subscribed. GenAI API endpoints are vulnerable to volumetric DDoS attacks that can exhaust token quotas and inflate costs. Resolution
1. Subscribe to AWS Shield Advanced for DDoS protection. 2. After subscribing, explicitly add resource protections in the Shield Advanced console for each Bedrock-facing resource (API Gateway stages, ALBs, CloudFront distributions, Route 53 hosted zones). Shield Advanced subscription alone does NOT automatically protect resources — each resource must be individually added to receive protection. 3. Enable Shield Response Team (SRT) access and configure proactive engagement. 4. Alternatively, use AWS Firewall Manager with a Shield Advanced policy to automate resource protection based on tags or resource types. |
Low | Failed |
444455556666 |
Global |
FS-01 |
No Regional WAF Web ACLs Found
Details and remediationDetails
No AWS WAF regional Web ACLs found. Without WAF, GenAI endpoints lack rate-based rules to block abusive callers. Resolution
1. Create a WAF Web ACL with rate-based rules (e.g., 1000 req/5 min per IP). 2. Associate the ACL with API Gateway stages or ALBs fronting Bedrock. 3. Add AWS Managed Rules for known bad inputs. |
Medium | Failed |
444455556666 |
Global |
FS-02 |
No API Gateway Usage Plans Found
|
Informational | N/A |
444455556666 |
Global |
FS-03 |
Bedrock Token Quotas Customized
|
Medium | Passed |
444455556666 |
Global |
FS-04 |
No Cost Anomaly Detection Monitors
Details and remediationDetails
No AWS Cost Anomaly Detection monitors found. Unexpected spikes in Bedrock/SageMaker usage (e.g., from prompt injection loops) will go undetected. Resolution
1. Create a Cost Anomaly Detection monitor scoped to AWS/Bedrock and AWS/SageMaker. 2. Configure alert subscriptions (SNS/email) for anomalies above threshold. 3. Set daily spend budgets with AWS Budgets as a secondary control. |
Medium | Failed |
444455556666 |
Global |
FS-05 |
No Bedrock CloudWatch Alarms Found
Details and remediationDetails
No CloudWatch alarms found for Bedrock metrics. Token exhaustion and throttling events will not trigger operational alerts. Resolution
Create CloudWatch alarms for: - AWS/Bedrock InvocationThrottles (threshold > 0) - AWS/Bedrock TokensProcessed (threshold based on quota) - Custom application-level token counters via EMF |
Medium | Failed |
444455556666 |
Global |
FS-06 |
No AI/ML Service Budgets Configured
Details and remediationDetails
No AWS Budgets found scoped to Bedrock or SageMaker. Unbounded GenAI spend can go undetected until the monthly bill. Resolution
1. Create cost budgets for AWS Bedrock and SageMaker with 80%/100% alert thresholds. 2. Add SNS notifications to on-call channels. 3. Consider budget actions to apply IAM deny policies when thresholds are breached. |
Medium | Failed |
444455556666 |
Global |
FS-07 |
Agent Action Boundary Check
|
Informational | N/A |
444455556666 |
Global |
FS-08 |
No AgentCore Runtimes Found
|
Informational | N/A |
444455556666 |
Global |
FS-09 |
Agent Lambda Functions Without Concurrency Limits
Details and remediationDetails
Agent-related Lambda functions without reserved concurrency: aiml-security-aiml-security-444455556666-AgentCoreAssessment, aiml-security-aiml-security-444455556666-RAIGRCAssessment, aiml-security-aiml-security-444455556666-AgentRegistryAssessment, aiml-security-aiml-security-444455556666-SagemakerAssessment, resco-aiml-BedrockAssessment, aiml-security-aiml-security-444455556666-BedrockAssessment, aiml-security-aiml-security-444455556666-GenerateReport, resco-aiml-GenerateReport, resco-aiml-IAMPermissionCaching, resco-aiml-CleanupBucket. Unlimited concurrency allows runaway agent loops to exhaust account limits. Resolution
1. Set reserved concurrency on agent Lambda functions. 2. Implement maximum iteration counts in agent orchestration logic. 3. Use Step Functions with MaxConcurrency and timeout states. 4. Add circuit-breaker patterns to agent tool invocations. |
Medium | Failed |
444455556666 |
Global |
FS-10 |
Human-in-the-Loop Check — No Agent Workflows Found
Details and remediationDetails
No Step Functions state machines with agent/approval naming found. Verify that high-risk agent actions (e.g., fund transfers, account changes) have human approval gates. Resolution
Implement Step Functions .waitForTaskToken patterns for high-risk agent actions. Route approval requests to human reviewers via SNS/SES/Slack. |
Informational | N/A |
444455556666 |
Global |
FS-11 |
No Agent Rate Alarms Found
Details and remediationDetails
No CloudWatch alarms found for agent invocation rates. Looping or runaway agents will not trigger operational alerts. Resolution
Create CloudWatch alarms on: - Bedrock agent invocation counts (threshold based on expected max) - Lambda invocation errors for agent functions - Step Functions execution failures and timeouts |
Medium | Failed |
444455556666 |
Global |
FS-12 |
SCP Model Access Check — Not in Organization
|
Informational | N/A |
444455556666 |
Global |
FS-13 |
Model Provenance Tags Present
|
Medium | Passed |
444455556666 |
Global |
FS-14 |
Model Governance Config Rules Present
|
Medium | Passed |
444455556666 |
Global |
FS-15 |
No Bedrock Evaluation Jobs Found
Details and remediationDetails
No Bedrock Model Evaluation jobs found. Models have not been evaluated for adversarial robustness. Model-risk management (SR 11-7) expects documented model validation/evaluation. Resolution
1. Run Bedrock Model Evaluation with adversarial/red-team datasets. 2. Use FMEval library for automated robustness testing. 3. Schedule periodic re-evaluation after model updates. |
Medium | Failed |
444455556666 |
Global |
FS-16 |
No ECR Repositories Found
|
Informational | N/A |
444455556666 |
Global |
FS-20 |
No SageMaker Feature Groups Found
|
Informational | N/A |
444455556666 |
Global |
FS-21 |
No Training Data Buckets Identified
|
Informational | N/A |
444455556666 |
Global |
FS-22 |
Overly Permissive Knowledge Base IAM Roles
Details and remediationDetails
637 role(s) with wildcard KB permissions: - Role 'Admin' allows '*' - Role 'aiml-security-23026652352-BedrockSecurityAssessment-UZzmVN1xrMwf' allows 'bedrock:ListGuardrails' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-23026652352-BedrockSecurityAssessment-UZzmVN1xrMwf' allows 'bedrock:GetGuardrail' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-23026652352-BedrockSecurityAssessment-UZzmVN1xrMwf' allows 'bedrock:ListModelInvocationJobs' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-23026652352-BedrockSecurityAssessment-UZzmVN1xrMwf' allows 'bedrock:GetModelInvocationLoggingConfiguration' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-23026652352-BedrockSecurityAssessment-UZzmVN1xrMwf' allows 'bedrock:ListPrompts' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-23026652352-BedrockSecurityAssessment-UZzmVN1xrMwf' allows 'bedrock:GetPrompt' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-23026652352-BedrockSecurityAssessment-UZzmVN1xrMwf' allows 'bedrock:ListAgents' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-23026652352-BedrockSecurityAssessment-UZzmVN1xrMwf' allows 'bedrock:GetAgent' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-23026652352-BedrockSecurityAssessment-UZzmVN1xrMwf' allows 'bedrock:ListCustomModels' on Resource '*' (no ARN scoping to specific Knowledge Bases) Resolution
Replace wildcard bedrock:* with specific actions such as bedrock:Retrieve, bedrock:RetrieveAndGenerate. Scope resources to specific Knowledge Base ARNs. |
High | Failed |
444455556666 |
Global |
FS-24 |
No Knowledge Bases Found
|
Informational | N/A |
444455556666 |
Global |
FS-25 |
No OpenSearch Serverless Collections Found
Details and remediationDetails
No OpenSearch Serverless collections exist in this region, so there is no OpenSearch vector-store data at rest to encrypt. If Bedrock Knowledge Bases use a different vector store (S3 Vectors, Aurora, Pinecone), verify its encryption separately. Resolution
If you adopt OpenSearch Serverless as a Bedrock KB vector store, create an encryption policy specifying a customer-managed KMS key before creating the collection. |
Informational | N/A |
444455556666 |
Global |
FS-26 |
No OpenSearch Serverless Network Policies
|
High | Failed |
444455556666 |
Global |
FS-27 |
No Guardrails — Contextual Grounding Not Applicable
|
Informational | N/A |
444455556666 |
Global |
FS-27 |
No Automated Reasoning Policies Found
Details and remediationDetails
No Bedrock Automated Reasoning policies have been created. ARC (GA August 2025) uses formal verification to guarantee that GenAI outputs comply with authored business rules — e.g., loan criteria, regulatory thresholds, policy constraints. Without ARC policies, factual accuracy of outputs is not formally verified, only heuristically filtered by contextual grounding thresholds. Resolution
1. In the Amazon Bedrock console → Guardrails → Automated Reasoning, create a policy document encoding your business rules (e.g., eligibility criteria, rate limits, regulatory thresholds). 2. Associate the ARC policy with your guardrail (automatedReasoningPolicy.policies field in CreateGuardrail/UpdateGuardrail). 3. Set confidenceThreshold on the policy to control strictness. 4. ARC requires cross-Region inference — ensure your guardrail has a guardrailProfileArn configured (crossRegionDetails in GetGuardrail response). 5. Reference: AWS Announcement — Automated Reasoning checks GA (August 2025). |
Medium | Failed |
444455556666 |
Global |
FS-28 |
No Guardrails — Topic Policy Not Applicable
|
Informational | N/A |
444455556666 |
Global |
FS-29 |
ADVISORY: Compliance Disclaimer — Manual Review Required
Details and remediationDetails
Application-level compliance disclaimers cannot be verified via AWS APIs. Manual review required to confirm GenAI outputs include required regulatory disclosures. Resolution
1. Implement post-processing to append required disclaimers to GenAI outputs. 2. Use Bedrock Guardrails word filters to block outputs that omit required disclosures. 3. Document disclaimer requirements in the AI use case register. 4. Test disclaimer presence in QA/UAT before production deployment. |
Informational | N/A |
444455556666 |
Global |
FS-30 |
ADVISORY: Compliance Dataset Coverage — Manual Review Required
Details and remediationDetails
Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation jobs include compliance-specific datasets (fair lending/ECOA, Fair Housing Act, UDAP/UDAAP, AML/KYC edge cases). Whether any evaluation jobs exist at all is assessed by FS-15. Resolution
Run Bedrock Model Evaluation with compliance-specific datasets: - Fair lending test cases (ECOA, Fair Housing Act) - UDAP/UDAAP unfair/deceptive practice scenarios - AML/KYC edge cases |
Informational | N/A |
444455556666 |
Global |
FS-31 |
No Knowledge Bases Found
|
Informational | N/A |
444455556666 |
Global |
FS-32 |
ADVISORY: Source Attribution — Manual Review Required
Details and remediationDetails
Source attribution in GenAI responses cannot be verified via AWS APIs. Manual review required to confirm responses include citations. Resolution
1. Use Bedrock RetrieveAndGenerate with citations enabled. 2. Include source document references in response post-processing. 3. Test citation accuracy in QA before production deployment. 4. Consider Bedrock Guardrails grounding checks to validate response accuracy. |
Informational | N/A |
444455556666 |
Global |
FS-33 |
No Knowledge Bases Found
|
Informational | N/A |
444455556666 |
Global |
FS-34 |
Legacy Foundation Models Available in Region
Details and remediationDetails
Legacy/deprecated foundation models are available in this account/region: anthropic.claude-sonnet-4-20250514-v1:0, twelvelabs.marengo-embed-2-7-v1:0, anthropic.claude-opus-4-1-20250805-v1:0, amazon.nova-premier-v1:0:8k, amazon.nova-premier-v1:0:20k, amazon.nova-premier-v1:0:1000k, amazon.nova-premier-v1:0:mm, amazon.nova-premier-v1:0, amazon.nova-canvas-v1:0, amazon.nova-reel-v1:0. This API reports model *availability*, not actual usage — it cannot determine which models your applications invoke. Legacy models have older training-data cutoffs and may produce outdated information if used. Review whether any are in active use. Resolution
1. Identify which (if any) of these legacy models your applications invoke (e.g., via CloudTrail InvokeModel events or application config). 2. Migrate active usage to current model versions. 3. Document training-data cutoff dates for all models in use. 4. Add data-currency disclaimers to outputs from models with old cutoffs. |
Informational | N/A |
444455556666 |
Global |
FS-35 |
ADVISORY: Harmful-Content Test Coverage — Manual Review Required
Details and remediationDetails
Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation/FMEval jobs include harmful-content datasets (toxicity, hate speech, violence/self-harm). Whether any evaluation jobs exist at all is assessed by FS-15. Resolution
Run Bedrock Model Evaluation or FMEval with harmful content datasets: - Toxicity detection - Hate speech classification - Violence/self-harm content |
Informational | N/A |
444455556666 |
Global |
FS-36 |
No Guardrails — Content Filters Not Applicable
|
Informational | N/A |
444455556666 |
Global |
FS-37 |
ADVISORY: User Feedback Mechanism — Manual Review Required
Details and remediationDetails
User feedback mechanisms for harmful outputs cannot be verified via AWS APIs. Manual review required. Resolution
1. Implement thumbs-up/down or flag-for-review UI in GenAI applications. 2. Route flagged outputs to human reviewers via SQS/SNS. 3. Log feedback to DynamoDB/S3 for model improvement. 4. Define SLAs for reviewing flagged content. |
Informational | N/A |
444455556666 |
Global |
FS-38 |
No Guardrails — Word Filters Not Applicable
|
Informational | N/A |
444455556666 |
Global |
FS-39 |
No SageMaker Clarify Bias Monitoring
Details and remediationDetails
No SageMaker Clarify model bias monitoring schedules found. Models making financial decisions (credit, insurance) may exhibit discriminatory bias without detection. Resolution
1. Configure SageMaker Clarify bias detection for all models making credit, insurance, or employment decisions. 2. Define protected attributes (age, gender, race proxies). 3. Set bias metric thresholds and alert on violations. 4. Document bias testing results for regulatory examination. |
High | Failed |
444455556666 |
Global |
FS-40 |
ADVISORY: Bias Dataset Coverage — Manual Review Required
Details and remediationDetails
Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation jobs include bias/fairness datasets (demographic parity, equal-opportunity, counterfactual fairness) for any GenAI models used in financial decisions (ECOA/Fair Housing). Whether any evaluation jobs exist at all is assessed by FS-15. Resolution
Run Bedrock Model Evaluation with bias test datasets: - Demographic parity test cases - Equal opportunity scenarios - Counterfactual fairness tests |
Informational | N/A |
444455556666 |
Global |
FS-41 |
No SageMaker Clarify Explainability Monitoring
Details and remediationDetails
No SageMaker Clarify explainability monitoring found. Models making adverse financial decisions may not provide required explanations (ECOA adverse action notices). Resolution
1. Configure SageMaker Clarify explainability for credit/lending models. 2. Generate SHAP values for feature importance. 3. Map top features to human-readable adverse action reason codes. 4. Store explanations for regulatory examination. |
High | Failed |
444455556666 |
Global |
FS-42 |
No SageMaker Model Cards Found
Details and remediationDetails
No SageMaker Model Cards found. If GenAI workloads run on Bedrock rather than SageMaker, model documentation may legitimately live elsewhere; Model Cards are a SageMaker-specific artifact. Resolution
1. For SageMaker models, create a Model Card documenting intended use, out-of-scope uses, training data and bias evaluations. 2. For Bedrock-only estates, record the equivalent documentation in your model-governance system and reference the AWS AI Service Cards. |
Informational | N/A |
444455556666 |
Global |
FS-43 |
Bedrock Invocation Logging Not Enabled
Details and remediationDetails
Bedrock model invocation logging is not enabled, so no invocation logs are being delivered and there is no log content to mask. Prompt and completion content is therefore also unavailable for audit. Resolution
1. Enable Bedrock model invocation logging. 2. If delivering to CloudWatch Logs, attach a data protection policy masking PII to the destination log group. |
Informational | N/A |
444455556666 |
Global |
FS-44 |
COULD NOT ASSESS: Macie Automated Discovery Status
Details and remediation |
Low | N/A |
444455556666 |
Global |
FS-45 |
No Guardrails — PII Filters Not Applicable
|
Informational | N/A |
444455556666 |
Global |
FS-46 |
No AI/ML Data Buckets Identified
|
Informational | N/A |
444455556666 |
Global |
FS-47 |
No Guardrails — Grounding Threshold Not Applicable
|
Informational | N/A |
444455556666 |
Global |
FS-48 |
No Active Knowledge Bases for RAG
Details and remediationDetails
No active Bedrock Knowledge Bases found. GenAI responses are not grounded in authoritative data sources, increasing hallucination risk. Resolution
1. Create Bedrock Knowledge Bases with authoritative financial data. 2. Use RetrieveAndGenerate API to ground responses. 3. Configure data sources with current regulatory and product information. |
Medium | Failed |
444455556666 |
Global |
FS-49 |
ADVISORY: Hallucination Disclaimer — Manual Review Required
Details and remediationDetails
Application-level hallucination disclaimers cannot be verified via AWS APIs. Manual review required. Resolution
1. Add disclaimers to GenAI outputs: 'AI-generated content may contain errors. Verify with authoritative sources before acting.' 2. Implement post-processing to append disclaimers. 3. Test disclaimer presence in QA before production. |
Informational | N/A |
444455556666 |
Global |
FS-50 |
No Guardrails With Relevance Grounding Filters
Details and remediationDetails
No guardrails have RELEVANCE contextual grounding filters. Without relevance filters, responses that are off-topic or unrelated to the user query will not be blocked, increasing hallucination risk in RAG-based applications. Resolution
Enable the RELEVANCE contextual grounding filter in Bedrock Guardrails with a threshold of ≥0.7 to block responses that are not relevant to the user query. Also enable the GROUNDING filter (≥0.7) to block responses not supported by the retrieved source context. |
Medium | Failed |
444455556666 |
Global |
FS-51 |
No Guardrails — Prompt Attack Filters Not Applicable
|
Informational | N/A |
444455556666 |
Global |
FS-52 |
Bedrock Lambda Functions on Current Runtimes
|
Medium | Passed |
444455556666 |
Global |
FS-53 |
No WAF Web ACLs — Injection Rules Not Applicable
|
Informational | N/A |
444455556666 |
Global |
FS-54 |
ADVISORY: Penetration Testing — Manual Review Required
Details and remediationDetails
Penetration testing evidence cannot be verified via AWS APIs. Manual review required to confirm GenAI applications have been tested. Resolution
1. Conduct penetration testing of GenAI applications at least annually and before major releases. 2. Include AI-specific test cases: prompt injection, jailbreak, indirect (cross-domain) injection, system-prompt leakage, and data-extraction attempts. 3. Consider AWS Security Agent for on-demand, AI-driven penetration testing (GA March 2026; available in US East N. Virginia, US West Oregon, Europe Ireland, Europe Frankfurt, Asia Pacific Sydney, Asia Pacific Tokyo, with cross-account shared-VPC testing via AWS RAM). Open-source tools such as Garak or PyRIT and manual red-teaming are complementary options. Verify current regional availability on the AWS Security Agent page before relying on it. 4. Document findings and remediation for regulatory examination, and tag tested resources with a last-pentest-date for audit trail. 5. For DORA compliance, include GenAI in TLPT (Threat-Led Penetration Testing) scope. |
Informational | N/A |
444455556666 |
Global |
FS-55 |
No Output Validation Functions Found
Details and remediationDetails
No Lambda functions with output validation/sanitization naming found. GenAI outputs may be passed directly to downstream systems without validation. Resolution
1. Implement output validation Lambda functions in GenAI pipelines. 2. Validate output schema, length, and content before downstream use. 3. Sanitize outputs before rendering in web UIs (XSS prevention). 4. Encode outputs appropriately for the target context (HTML, SQL, JSON). |
Medium | Failed |
444455556666 |
Global |
FS-56 |
No WAF ACLs — XSS Prevention Not Applicable
|
Informational | N/A |
444455556666 |
Global |
FS-57 |
ADVISORY: Output Encoding — Manual Review Required
Details and remediationDetails
Output encoding practices cannot be verified via AWS APIs. Manual code review required. Resolution
1. HTML-encode GenAI outputs before rendering in web UIs. 2. Use parameterized queries when GenAI output is used in database operations. 3. JSON-encode outputs before embedding in JavaScript contexts. 4. Validate output length and format before passing to downstream APIs. |
Informational | N/A |
444455556666 |
Global |
FS-58 |
ADVISORY: Output Schema Validation — Manual Review Required
Details and remediationDetails
Found 0 Lambda function(s) whose names suggest schema/validation handling. Structured-output / JSON-schema validation of GenAI responses is an application-layer control that cannot be verified automatically — manual review required. Resolution
1. Use Bedrock structured output (response schemas) where supported. 2. Implement JSON schema validation on Lambda output processors. 3. Reject malformed outputs and return safe error responses. 4. Log schema validation failures to CloudWatch for monitoring. |
Informational | N/A |
444455556666 |
Global |
FS-59 |
No Guardrails — Topic Allowlist Not Applicable
|
Informational | N/A |
444455556666 |
Global |
FS-60 |
ADVISORY: Contextual Grounding for Off-Topic Prevention
Details and remediationDetails
Contextual grounding for off-topic prevention is covered by guardrail grounding checks (FS-47) and RAG configuration (FS-48). Additionally verify system prompts explicitly scope the assistant's role. Resolution
1. Include explicit scope instructions in system prompts. 2. Use Bedrock Guardrails relevance grounding filter. 3. Test with off-topic prompts in QA to verify rejection behavior. |
Informational | N/A |
444455556666 |
Global |
FS-61 |
No Knowledge Bases Found
|
Informational | N/A |
444455556666 |
Global |
FS-62 |
ADVISORY: Data Currency Disclaimer — Manual Review Required
Details and remediationDetails
Data currency disclaimers cannot be verified via AWS APIs. Manual review required. Resolution
1. Add data currency disclaimers to GenAI outputs: 'Information based on data current as of [KB last sync date].' 2. Expose KB last sync timestamp in application responses. 3. Alert users when KB data is older than defined threshold. |
Informational | N/A |
444455556666 |
Global |
FS-63 |
Foundation Model Lifecycle Governance Detected
Details and remediationDetails
10 AWS Config rule(s) with lifecycle- or model-related names were found, indicating some account-side model lifecycle governance: securityhub-ecr-private-lifecycle-policy-configured-cafeba10, securityhub-s3-lifecycle-policy-check-8a649ff3, securityhub-s3express-dir-bucket-lifecycle-rules-check-c0e91d6c, securityhub-sagemaker-model-bias-job-encrypt-in-transit-1a7cc7a1, securityhub-sagemaker-model-bias-job-isolation-31ba8bde. Rule names are a heuristic; whether these rules enforce model currency is not assessed. For context, 17 of 122 model(s) offered in this region are marked LEGACY (for example ai21.jamba-1-5-large-v1:0, ai21.jamba-1-5-mini-v1:0, amazon.nova-canvas-v1:0, amazon.nova-premier-v1:0, amazon.nova-premier-v1:0:1000k); this reflects the regional catalogue, not this account's usage. Resolution
Confirm the matched rules genuinely track model currency, and that deprecation notifications are monitored. |
Medium | Passed |
444455556666 |
Global |
FS-65 |
No Knowledge Bases Found
|
Informational | N/A |
444455556666 |
Global |
FS-66 |
No AgentCore Runtimes Found
|
Informational | N/A |
444455556666 |
Global |
FS-67 |
Agent Action-Group Lambdas May Lack Transaction Thresholds
Details and remediationDetails
The following agent action-group Lambda functions have no environment variables whose names suggest transaction-value threshold configuration (this is a best-effort heuristic — a threshold enforced in code or in an AgentCore Policy Engine rule would not be detected here, so treat this as a prompt for manual verification rather than a definitive gap). Without explicit limits, agents could initiate unbounded financial transactions: - resco-aiml-BedrockAssessment - resco-aiml-AgentCoreAssessment Resolution
1. Add transaction-value threshold environment variables (e.g., MAX_TRANSACTION_AMOUNT) to each agent action-group Lambda. 2. Implement threshold enforcement logic in the Lambda handler. 3. Configure AgentCore Policy Engine rules to cap financial transaction amounts. 4. Route transactions exceeding thresholds to a human-in-the-loop approval step. |
High | Failed |
444455556666 |
Global |
FS-68 |
API Gateway Request Body Size Limits Not Enforced
Details and remediationDetails
Found 5 REST API(s) and 0 regional WAF Web ACL(s), but none enforce a maximum request-body size. Note: an API Gateway request validator does NOT cap body size (it validates the schema and required params; the REST limit is a fixed 10 MB), and a WAF body SizeConstraint only inspects the first ~16 KB of the body by default. Oversized prompts can exhaust Bedrock token quotas and inflate costs. Resolution
1. Add a maxLength (or maxItems/maxProperties) bound to the request-body JSON-Schema model used by your request validator, so oversized prompts are rejected with a 400. 2. Add a WAF SizeConstraintStatement on the request Body sized within WAF's body-inspection window (default 16 KB; raise via the web ACL AssociationConfig, or set OversizeHandling=MATCH to block bodies beyond the window), and associate the ACL with the API stage. 3. Set the max_tokens parameter in Bedrock API calls to cap output length. 4. Implement client-side token counting before submitting requests. |
Medium | Failed |
444455556666 |
Global |
FS-69 |
Prompt Input Validation Functions Present
Details and remediationDetails
Found 2 Lambda function(s) with input validation/sanitization naming patterns: resco-aiml-CleanupBucket, aiml-security-aiml-security-444455556666-CleanupBucket. Resolution
Review these functions to confirm they cover: special-character stripping, format validation, size limits, and injection-sequence detection. |
Medium | Passed |
444455556666 |
us-east-1 |
FS-00 |
Responsible AI GRC — Regional Scope Not Applicable
|
Informational | N/A |
444455556666 |
us-west-2 |
FS-00 |
Responsible AI GRC — Regional Scope Not Applicable
|
Informational | N/A |
444455556666 |
us-east-2 |
FS-00 |
Responsible AI GRC — Regional Scope Not Applicable
|
Informational | N/A |
444455556666 |
Global |
BR-01 |
AmazonBedrockFullAccess role check
|
High | Passed |
444455556666 |
Global |
BR-03 |
Marketplace Subscription Access Check
|
Medium | Passed |
444455556666 |
us-east-1 |
BR-02 |
Amazon Bedrock private connectivity check
|
Informational | N/A |
444455556666 |
us-east-1 |
BR-04 |
Bedrock Model Invocation Logging Check
|
Informational | N/A |
444455556666 |
us-east-1 |
BR-05 |
Bedrock Guardrails Check
|
Informational | N/A |
444455556666 |
us-east-1 |
BR-06 |
Bedrock CloudTrail Logging Check
|
Informational | N/A |
444455556666 |
us-east-1 |
BR-07 |
Bedrock Prompt Management Check
Details and remediationDetails
Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates |
Informational | N/A |
444455556666 |
us-east-1 |
BR-08 |
Bedrock Agent IAM Roles Check
|
Informational | N/A |
444455556666 |
us-east-1 |
BR-09 |
Bedrock Knowledge Base Encryption Check
|
Informational | N/A |
444455556666 |
us-east-1 |
BR-10 |
Bedrock Guardrail IAM Enforcement Check
|
Informational | N/A |
444455556666 |
us-east-1 |
BR-11 |
Bedrock Custom Model Encryption Check
|
Informational | N/A |
444455556666 |
us-east-1 |
BR-12 |
Bedrock Invocation Log Encryption Check
|
Informational | N/A |
444455556666 |
us-east-1 |
BR-13 |
Bedrock Flows Guardrails Check
|
Informational | N/A |
444455556666 |
Global |
BR-15 |
Cross-Account Guardrails Enforcement Check
Details and remediationDetails
No account-level enforced guardrail configuration was observed, and organization policy inheritance cannot be fully established from this member account. Resolution
Run the assessment from the management or delegated administrator account, or configure account-level enforced guardrails. |
Informational | N/A |
444455556666 |
us-east-1 |
BR-16 |
Guardrail Tier Validation Check
|
Medium | N/A |
444455556666 |
us-east-1 |
BR-17 |
Custom Model Customer-Managed KMS Encryption Check
|
High | N/A |
444455556666 |
us-east-1 |
BR-18 |
Model Evaluation Implementation Check
|
Informational | N/A |
444455556666 |
us-east-1 |
BR-19 |
Prompt Flow Validation Check
|
Medium | N/A |
444455556666 |
us-east-1 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Check
|
High | N/A |
444455556666 |
us-east-1 |
BR-21 |
Agent Action Group IAM Least Privilege Check
|
High | N/A |
444455556666 |
us-east-1 |
BR-22 |
Model Invocation Throttling Limits Check
|
Informational | N/A |
444455556666 |
us-east-1 |
BR-23 |
Guardrail Content Filter Coverage Check
|
Informational | N/A |
444455556666 |
us-east-1 |
BR-24 |
Automated Reasoning Policy Implementation Check
|
Medium | N/A |
444455556666 |
us-east-1 |
BR-25 |
RAG Evaluation Jobs Check
|
Low | N/A |
444455556666 |
us-east-1 |
BR-26 |
Guardrail Sensitive Information Filter Check
|
High | N/A |
444455556666 |
us-east-1 |
BR-27 |
Guardrail Contextual Grounding Check
|
Medium | N/A |
444455556666 |
us-east-1 |
BR-28 |
Agent Guardrail Association Check
|
High | N/A |
444455556666 |
us-east-1 |
BR-29 |
Agent Idle Session TTL Check
|
Low | N/A |
444455556666 |
us-east-1 |
BR-30 |
Imported Model Customer-Managed KMS Encryption Check
|
High | N/A |
444455556666 |
us-east-1 |
BR-31 |
Batch Inference Output Encryption Check
|
Medium | N/A |
444455556666 |
us-east-1 |
BR-32 |
Bedrock CloudWatch Alarm Check
|
Informational | N/A |
444455556666 |
us-east-1 |
BR-33 |
Amazon Inspector Lambda Code Scanning Check
Details and remediation |
Medium | Passed |
444455556666 |
us-east-1 |
BR-34 |
Guardrail Prompt Attack Filter
|
Informational | N/A |
444455556666 |
us-east-1 |
BR-35 |
Guardrail Image Content Filter Coverage
|
Informational | N/A |
444455556666 |
us-east-1 |
BR-36 |
Application Inference Profile Governance
|
Informational | N/A |
444455556666 |
us-east-1 |
BR-37 |
Bedrock Account Data Retention
|
High | Failed |
444455556666 |
us-east-1 |
BR-38 |
Automated Reasoning Policy CMK Encryption
|
Informational | N/A |
444455556666 |
us-east-1 |
BR-39 |
Marketplace Model Endpoint VPC Configuration
|
Informational | N/A |
444455556666 |
us-east-1 |
BR-40 |
Marketplace Model Endpoint CMK Encryption
|
Informational | N/A |
444455556666 |
us-east-1 |
AG-07 |
Agentic AI Model Invocation Logging
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-08 |
Agentic AI API Audit Trail
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage Resolution
Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured. |
Informational | N/A |
444455556666 |
Global |
AG-09 |
Agentic AI Guardrail Enforcement Boundary
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Organization-level guardrail enforcement helps prevent agents from bypassing required safety controls across accounts. Source check BR-15: No account-level enforced guardrail configuration was observed, and organization policy inheritance cannot be fully established from this member account. Resolution
Use IAM and organization controls to require approved guardrails for model and agent invocations where supported. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-10 |
Agentic AI Adversarial Evaluation Coverage
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs Resolution
Configure model or application evaluations that include adversarial, safety, and security-relevant test cases. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-11 |
Agentic AI Prompt Flow Validation
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region Resolution
Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-06 |
Agentic AI Tool Execution Least Privilege
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region Resolution
Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-12 |
Agentic AI Invocation Abuse Controls
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas Resolution
Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-02 |
Agentic AI Harmful Content Guardrail Coverage
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-04 |
Agentic AI Automated Reasoning Guardrails
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: No Bedrock guardrails configured in this region Resolution
Configure automated reasoning policies on guardrails where formal response validation is required. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-03 |
Agentic AI Sensitive Information Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: No Bedrock guardrails configured in this region Resolution
Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-05 |
Agentic AI Grounding Controls
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: No Bedrock guardrails configured in this region Resolution
Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-01 |
Agentic AI Agent Guardrail Association
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region Resolution
Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-13 |
Agentic AI Session Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region Resolution
Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-14 |
Agentic AI Operational Abuse Alarms
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms Resolution
Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available. |
Informational | N/A |
444455556666 |
us-east-1 |
AG-30 |
Agentic AI Prompt Attack Protection
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agents should prevent prompt attacks before untrusted input can redirect planning or tool use. Source check BR-34: No Bedrock guardrails configured in this region Resolution
Enable a preventive PROMPT_ATTACK input filter on each guardrail and use Standard tier where prompt-leakage protection is required. |
Informational | N/A |
777788889999 |
Global |
AR-01 |
AWS Agent Registry IAM Full Access Check
|
High | Passed |
777788889999 |
Global |
AR-02 |
AWS Agent Registry Unused Permissions
|
Informational | N/A |
777788889999 |
us-east-1 |
AR-03 |
AWS Agent Registry Publication Approval Governance
|
Informational | N/A |
777788889999 |
us-east-1 |
AR-04 |
AWS Agent Registry Discovery Authorization
|
Informational | N/A |
777788889999 |
us-east-1 |
AR-05 |
AWS Agent Registry Customer-Managed KMS Encryption
|
Informational | N/A |
777788889999 |
us-east-1 |
AR-06 |
AWS Agent Registry Organization Auto-Detection
|
Informational | N/A |
777788889999 |
us-east-1 |
AR-07 |
AWS Agent Registry Record Lifecycle Governance
|
Informational | N/A |
777788889999 |
us-east-1 |
AR-08 |
AWS Agent Registry Record Provenance
|
Informational | N/A |
777788889999 |
us-east-1 |
AG-33 |
Agentic AI Registry Publication Approval Governance
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry approval workflows control which agents, tools, and skills become discoverable to consumers. Source check AR-03: No AWS Agent Registry registries found. Resolution
Require manual review for registry publication where organizational policy does not permit automatic approval. |
Informational | N/A |
777788889999 |
us-east-1 |
AG-34 |
Agentic AI Registry Discovery Authorization
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry discovery authorization requires review against intended callers and effective access boundaries. Source check AR-04: No AWS Agent Registry registries found. Resolution
Review effective IAM access or compare custom JWT audiences, clients, scopes, and claims with approved registry consumers. |
Informational | N/A |
777788889999 |
us-east-1 |
AG-35 |
Agentic AI Registry Metadata Encryption
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Registry records can contain agent, tool, endpoint, and ownership metadata that benefits from customer-controlled encryption. Source check AR-05: No AWS Agent Registry registries found. Resolution
Create the registry with a customer-managed KMS key when organizational policy requires customer-controlled encryption. |
Informational | N/A |
777788889999 |
us-east-1 |
AG-36 |
Agentic AI Organization Discovery Coverage
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Organization-wide auto-detection provides visibility into unmanaged agent resources. Source check AR-06: No AWS Agent Registry registries found. Resolution
Enable organization-scoped registry auto-detection where centralized discovery is required. |
Informational | N/A |
777788889999 |
us-east-1 |
AG-37 |
Agentic AI Registry Record Lifecycle Governance
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry lifecycle states provide operational visibility but do not independently prove a security control. Source check AR-07: No AWS Agent Registry registries found. Resolution
Review failed or unknown record lifecycle states operationally. |
Informational | N/A |
777788889999 |
us-east-1 |
AG-38 |
Agentic AI Registry Record Provenance
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Consumers need attributable record origin and source lineage to understand which account and resource produced an entry. Source check AR-08: No AWS Agent Registry registries found. Resolution
Ensure records retain creator attribution and auto-detected records retain source provenance. |
Informational | N/A |
777788889999 |
us-east-2 |
OW-01 |
OWASP LLM01: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis. |
Informational | N/A |
777788889999 |
us-east-2 |
OW-07 |
OWASP LLM07: Model Invocation Logging
Details and remediation |
Informational | N/A |
777788889999 |
us-east-2 |
OW-07 |
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident. |
Informational | N/A |
777788889999 |
us-east-2 |
OW-07 |
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-09 |
OWASP LLM09: Model Evaluation Jobs
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-06 |
OWASP LLM06: Agent Action-Group Least Privilege
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-10 |
OWASP LLM10: Service Quota Throttling Limits
Details and remediation |
Informational | N/A |
777788889999 |
us-east-2 |
OW-01 |
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier. |
Informational | N/A |
777788889999 |
us-east-2 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-02 |
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation |
Informational | N/A |
777788889999 |
us-east-2 |
OW-01 |
OWASP LLM01: Contextual Grounding Guardrail
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-04 |
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation |
Informational | N/A |
777788889999 |
us-east-2 |
OW-09 |
OWASP LLM09: Contextual Grounding for Faithfulness
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-06 |
OWASP LLM06: Bedrock Agent Guardrail Association
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-06 |
OWASP LLM06: Agent Idle Session TTL
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-03 |
OWASP LLM03: Imported-Model KMS Provenance
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-10 |
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation |
Informational | N/A |
777788889999 |
us-east-2 |
OW-03 |
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check BR-33: No Lambda functions with Bedrock indicators were found in us-east-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain. |
Informational | N/A |
777788889999 |
us-east-2 |
OW-01 |
OWASP LLM01: Preventive Prompt Attack Filter
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-02 |
OWASP LLM02: Bedrock Data Retention Boundary
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check BR-37: Bedrock account data retention is inherit; this does not establish an explicit account-level zero-data-retention setting. Resolution
Configure Bedrock account data retention as none and disable provider data sharing when prompts or responses may contain sensitive information. |
High | Failed |
777788889999 |
us-east-2 |
OW-02 |
OWASP LLM02: Automated Reasoning Policy Encryption
Details and remediation |
Informational | N/A |
777788889999 |
us-east-2 |
OW-03 |
OWASP LLM03: Marketplace Endpoint VPC Isolation
Details and remediation |
Informational | N/A |
777788889999 |
us-east-2 |
OW-02 |
OWASP LLM02: Marketplace Endpoint CMK Encryption
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker Internet Exposure
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-01: No SageMaker notebook instances or domains found to check Resolution
Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths. |
Informational | N/A |
777788889999 |
us-east-2 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: No SageMaker resources found to check for data protection Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
Informational | N/A |
777788889999 |
us-east-2 |
OW-01 |
OWASP LLM01: GuardDuty AI Protection
|
High | Failed |
777788889999 |
us-east-2 |
OW-10 |
OWASP LLM10: GuardDuty AI Protection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check SM-26: GuardDuty is enabled, but the AI Protection detector feature is not enabled. Resolution
Enable the GuardDuty AI_PROTECTION detector feature to detect supported anomalous model invocation and cost-harvesting activity. |
High | Failed |
777788889999 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Clarify Evaluation
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation |
Informational | N/A |
777788889999 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Model Monitor Coverage
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker Notebook VPC Deployment
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker Model Network Isolation
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-10 |
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation |
Informational | N/A |
777788889999 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker Container Repository Access
Details and remediation |
Informational | N/A |
777788889999 |
us-east-2 |
OW-02 |
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation |
Informational | N/A |
777788889999 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker AutoML Network Isolation
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically. |
Informational | N/A |
777788889999 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release. |
Informational | N/A |
777788889999 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
777788889999 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
777788889999 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain. |
Informational | N/A |
777788889999 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated. |
Informational | N/A |
777788889999 |
us-east-2 |
OW-02 |
OWASP LLM02: HyperPod Volume CMK Encryption
Details and remediation |
Informational | N/A |
777788889999 |
us-east-2 |
OW-03 |
OWASP LLM03: HyperPod VPC Boundary
Details and remediation |
Informational | N/A |
777788889999 |
us-east-2 |
OW-03 |
OWASP LLM03: Model Registry Resource Policy Boundary
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-06 |
OWASP LLM06: AgentCore Resource-Based Policies
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-02 |
OWASP LLM02: AgentCore Token Vault CMK Encryption
Details and remediation |
Informational | N/A |
777788889999 |
us-east-2 |
OW-06 |
OWASP LLM06: Code Interpreter Network Isolation
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-06 |
OWASP LLM06: Browser Tool Network Isolation
|
Informational | N/A |
777788889999 |
us-east-2 |
OW-11 |
OWASP LLM07: System Prompt Embedded in Lambda Env Var
|
Medium | Passed |
777788889999 |
us-east-2 |
OW-12 |
OWASP LLM07: System-Prompt-Disclosure Denied Topic
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-01 |
OWASP LLM01: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis. |
Informational | N/A |
777788889999 |
us-west-2 |
OW-07 |
OWASP LLM07: Model Invocation Logging
Details and remediation |
Informational | N/A |
777788889999 |
us-west-2 |
OW-07 |
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident. |
Informational | N/A |
777788889999 |
us-west-2 |
OW-07 |
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-09 |
OWASP LLM09: Model Evaluation Jobs
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-06 |
OWASP LLM06: Agent Action-Group Least Privilege
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-10 |
OWASP LLM10: Service Quota Throttling Limits
Details and remediation |
Informational | N/A |
777788889999 |
us-west-2 |
OW-01 |
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier. |
Informational | N/A |
777788889999 |
us-west-2 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-02 |
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation |
Informational | N/A |
777788889999 |
us-west-2 |
OW-01 |
OWASP LLM01: Contextual Grounding Guardrail
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-04 |
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation |
Informational | N/A |
777788889999 |
us-west-2 |
OW-09 |
OWASP LLM09: Contextual Grounding for Faithfulness
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-06 |
OWASP LLM06: Bedrock Agent Guardrail Association
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-06 |
OWASP LLM06: Agent Idle Session TTL
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-03 |
OWASP LLM03: Imported-Model KMS Provenance
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-10 |
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation |
Informational | N/A |
777788889999 |
us-west-2 |
OW-03 |
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check BR-33: No Lambda functions with Bedrock indicators were found in us-west-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain. |
Informational | N/A |
777788889999 |
us-west-2 |
OW-01 |
OWASP LLM01: Preventive Prompt Attack Filter
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-02 |
OWASP LLM02: Bedrock Data Retention Boundary
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check BR-37: Bedrock account data retention is inherit; this does not establish an explicit account-level zero-data-retention setting. Resolution
Configure Bedrock account data retention as none and disable provider data sharing when prompts or responses may contain sensitive information. |
High | Failed |
777788889999 |
us-west-2 |
OW-02 |
OWASP LLM02: Automated Reasoning Policy Encryption
Details and remediation |
Informational | N/A |
777788889999 |
us-west-2 |
OW-03 |
OWASP LLM03: Marketplace Endpoint VPC Isolation
Details and remediation |
Informational | N/A |
777788889999 |
us-west-2 |
OW-02 |
OWASP LLM02: Marketplace Endpoint CMK Encryption
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker Internet Exposure
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-01: No SageMaker notebook instances or domains found to check Resolution
Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths. |
Informational | N/A |
777788889999 |
us-west-2 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: No SageMaker resources found to check for data protection Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
Informational | N/A |
777788889999 |
us-west-2 |
OW-01 |
OWASP LLM01: GuardDuty AI Protection
|
High | Failed |
777788889999 |
us-west-2 |
OW-10 |
OWASP LLM10: GuardDuty AI Protection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check SM-26: GuardDuty is enabled, but the AI Protection detector feature is not enabled. Resolution
Enable the GuardDuty AI_PROTECTION detector feature to detect supported anomalous model invocation and cost-harvesting activity. |
High | Failed |
777788889999 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Clarify Evaluation
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation |
Informational | N/A |
777788889999 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Model Monitor Coverage
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker Notebook VPC Deployment
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker Model Network Isolation
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-10 |
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation |
Informational | N/A |
777788889999 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker Container Repository Access
Details and remediation |
Informational | N/A |
777788889999 |
us-west-2 |
OW-02 |
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation |
Informational | N/A |
777788889999 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker AutoML Network Isolation
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically. |
Informational | N/A |
777788889999 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release. |
Informational | N/A |
777788889999 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
777788889999 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
777788889999 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain. |
Informational | N/A |
777788889999 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated. |
Informational | N/A |
777788889999 |
us-west-2 |
OW-02 |
OWASP LLM02: HyperPod Volume CMK Encryption
Details and remediation |
Informational | N/A |
777788889999 |
us-west-2 |
OW-03 |
OWASP LLM03: HyperPod VPC Boundary
Details and remediation |
Informational | N/A |
777788889999 |
us-west-2 |
OW-03 |
OWASP LLM03: Model Registry Resource Policy Boundary
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-06 |
OWASP LLM06: AgentCore Resource-Based Policies
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-02 |
OWASP LLM02: AgentCore Token Vault CMK Encryption
Details and remediation |
Informational | N/A |
777788889999 |
us-west-2 |
OW-06 |
OWASP LLM06: Code Interpreter Network Isolation
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-06 |
OWASP LLM06: Browser Tool Network Isolation
|
Informational | N/A |
777788889999 |
us-west-2 |
OW-11 |
OWASP LLM07: System Prompt Embedded in Lambda Env Var
|
Medium | Passed |
777788889999 |
us-west-2 |
OW-12 |
OWASP LLM07: System-Prompt-Disclosure Denied Topic
|
Informational | N/A |
777788889999 |
us-east-2 |
AR-03 |
AWS Agent Registry Publication Approval Governance Incomplete
|
Informational | N/A |
777788889999 |
us-east-2 |
AR-04 |
AWS Agent Registry Discovery Authorization Incomplete
|
Informational | N/A |
777788889999 |
us-east-2 |
AR-05 |
AWS Agent Registry Customer-Managed KMS Encryption Incomplete
|
Informational | N/A |
777788889999 |
us-east-2 |
AR-06 |
AWS Agent Registry Organization Auto-Detection Incomplete
|
Informational | N/A |
777788889999 |
us-east-2 |
AR-07 |
AWS Agent Registry Record Lifecycle Governance Incomplete
|
Informational | N/A |
777788889999 |
us-east-2 |
AR-08 |
AWS Agent Registry Record Provenance Incomplete
|
Informational | N/A |
777788889999 |
us-east-2 |
AG-33 |
Agentic AI Registry Publication Approval Governance
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry approval workflows control which agents, tools, and skills become discoverable to consumers. Source check AR-03: Assessment could not enumerate AWS Agent Registry registries: AccessDeniedException (Unauthorized access). Resolution
Require manual review for registry publication where organizational policy does not permit automatic approval. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-34 |
Agentic AI Registry Discovery Authorization
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry discovery authorization requires review against intended callers and effective access boundaries. Source check AR-04: Assessment could not enumerate AWS Agent Registry registries: AccessDeniedException (Unauthorized access). Resolution
Review effective IAM access or compare custom JWT audiences, clients, scopes, and claims with approved registry consumers. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-35 |
Agentic AI Registry Metadata Encryption
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Registry records can contain agent, tool, endpoint, and ownership metadata that benefits from customer-controlled encryption. Source check AR-05: Assessment could not enumerate AWS Agent Registry registries: AccessDeniedException (Unauthorized access). Resolution
Create the registry with a customer-managed KMS key when organizational policy requires customer-controlled encryption. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-36 |
Agentic AI Organization Discovery Coverage
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Organization-wide auto-detection provides visibility into unmanaged agent resources. Source check AR-06: Assessment could not enumerate AWS Agent Registry registries: AccessDeniedException (Unauthorized access). Resolution
Enable organization-scoped registry auto-detection where centralized discovery is required. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-37 |
Agentic AI Registry Record Lifecycle Governance
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry lifecycle states provide operational visibility but do not independently prove a security control. Source check AR-07: Assessment could not enumerate AWS Agent Registry registries: AccessDeniedException (Unauthorized access). Resolution
Review failed or unknown record lifecycle states operationally. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-38 |
Agentic AI Registry Record Provenance
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Consumers need attributable record origin and source lineage to understand which account and resource produced an entry. Source check AR-08: Assessment could not enumerate AWS Agent Registry registries: AccessDeniedException (Unauthorized access). Resolution
Ensure records retain creator attribution and auto-detected records retain source provenance. |
Informational | N/A |
777788889999 |
us-west-2 |
AR-03 |
AWS Agent Registry Publication Approval Governance
|
Informational | N/A |
777788889999 |
us-west-2 |
AR-04 |
AWS Agent Registry Discovery Authorization
|
Informational | N/A |
777788889999 |
us-west-2 |
AR-05 |
AWS Agent Registry Customer-Managed KMS Encryption
|
Informational | N/A |
777788889999 |
us-west-2 |
AR-06 |
AWS Agent Registry Organization Auto-Detection
|
Informational | N/A |
777788889999 |
us-west-2 |
AR-07 |
AWS Agent Registry Record Lifecycle Governance
|
Informational | N/A |
777788889999 |
us-west-2 |
AR-08 |
AWS Agent Registry Record Provenance
|
Informational | N/A |
777788889999 |
us-west-2 |
AG-33 |
Agentic AI Registry Publication Approval Governance
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry approval workflows control which agents, tools, and skills become discoverable to consumers. Source check AR-03: No AWS Agent Registry registries found. Resolution
Require manual review for registry publication where organizational policy does not permit automatic approval. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-34 |
Agentic AI Registry Discovery Authorization
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry discovery authorization requires review against intended callers and effective access boundaries. Source check AR-04: No AWS Agent Registry registries found. Resolution
Review effective IAM access or compare custom JWT audiences, clients, scopes, and claims with approved registry consumers. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-35 |
Agentic AI Registry Metadata Encryption
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Registry records can contain agent, tool, endpoint, and ownership metadata that benefits from customer-controlled encryption. Source check AR-05: No AWS Agent Registry registries found. Resolution
Create the registry with a customer-managed KMS key when organizational policy requires customer-controlled encryption. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-36 |
Agentic AI Organization Discovery Coverage
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Organization-wide auto-detection provides visibility into unmanaged agent resources. Source check AR-06: No AWS Agent Registry registries found. Resolution
Enable organization-scoped registry auto-detection where centralized discovery is required. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-37 |
Agentic AI Registry Record Lifecycle Governance
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry lifecycle states provide operational visibility but do not independently prove a security control. Source check AR-07: No AWS Agent Registry registries found. Resolution
Review failed or unknown record lifecycle states operationally. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-38 |
Agentic AI Registry Record Provenance
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Consumers need attributable record origin and source lineage to understand which account and resource produced an entry. Source check AR-08: No AWS Agent Registry registries found. Resolution
Ensure records retain creator attribution and auto-detected records retain source provenance. |
Informational | N/A |
777788889999 |
us-east-1 |
OW-01 |
OWASP LLM01: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: Model invocation logging is not enabled. This limits your ability to track and audit model usage. Resolution
Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis. |
Medium | Failed |
777788889999 |
us-east-1 |
OW-07 |
OWASP LLM07: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-04: Model invocation logging is not enabled. This limits your ability to track and audit model usage. Resolution
Enable Bedrock model invocation logging so prompt-extraction attempts against the system prompt are auditable after the fact. |
Medium | Failed |
777788889999 |
us-east-1 |
OW-07 |
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management is being used with 1 prompts Resolution
Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident. |
Low | Passed |
777788889999 |
us-east-1 |
OW-07 |
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-16: Guardrail 'aiml-sec-test-test-guardrail' (ID: jkceg2tprvwh) could not be assessed because GetGuardrail returned AccessDeniedException. Resolution
Set guardrail contentPolicy.tier.tierName to STANDARD; Standard tier additionally detects prompt-leakage attacks. |
Informational | N/A |
777788889999 |
us-east-1 |
OW-09 |
OWASP LLM09: Model Evaluation Jobs
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check BR-18: No Bedrock model evaluation jobs found. Model evaluation helps assess toxicity, accuracy, semantic robustness, and other safety metrics before production deployment. Resolution
Run Bedrock model evaluation jobs that include correctness and safety datasets. |
Medium | Failed |
777788889999 |
us-east-1 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: Knowledge base 'knowledge-base-prowler-findings' (ID: 9K2QZLVCZW) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption. |
Informational | N/A |
777788889999 |
us-east-1 |
OW-10 |
OWASP LLM10: Service Quota Throttling Limits
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-22: 10 custom throttling quotas are configured. Regular quota review helps maintain appropriate rate limits. Resolution
Customise Bedrock TPM / RPM service quotas above the account default to establish an explicit consumption ceiling. |
Low | Passed |
777788889999 |
us-east-1 |
OW-01 |
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: Guardrail 'aiml-sec-test-test-guardrail' could not be assessed: AccessDeniedException. Resolution
Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier. |
Informational | N/A |
777788889999 |
us-east-1 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: Knowledge base 'knowledge-base-prowler-findings' (ID: 9K2QZLVCZW) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context. |
Low | Failed |
777788889999 |
us-east-1 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check BR-25: Knowledge base 'knowledge-base-prowler-findings' (ID: 9K2QZLVCZW) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates. |
Low | Failed |
777788889999 |
us-east-1 |
OW-02 |
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check BR-26: Guardrail 'aiml-sec-test-test-guardrail' (ID: jkceg2tprvwh) could not be assessed because GetGuardrail returned AccessDeniedException. Resolution
Configure guardrail sensitiveInformationPolicy with PII entities and regex patterns; set outputAction=ANONYMIZE or BLOCK. |
Informational | N/A |
777788889999 |
us-east-1 |
OW-01 |
OWASP LLM01: Contextual Grounding Guardrail
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-27: Guardrail 'aiml-sec-test-test-guardrail' (ID: jkceg2tprvwh) could not be assessed because GetGuardrail returned AccessDeniedException. Resolution
Enable Bedrock guardrail contextual grounding checks to reduce the surface for indirect prompt injection through retrieved context. |
Informational | N/A |
777788889999 |
us-east-1 |
OW-04 |
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-27: Guardrail 'aiml-sec-test-test-guardrail' (ID: jkceg2tprvwh) could not be assessed because GetGuardrail returned AccessDeniedException. Resolution
Enable contextual grounding guardrail filters so retrieved context that diverges from ground truth is filtered before reaching the model. |
Informational | N/A |
777788889999 |
us-east-1 |
OW-09 |
OWASP LLM09: Contextual Grounding for Faithfulness
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check BR-27: Guardrail 'aiml-sec-test-test-guardrail' (ID: jkceg2tprvwh) could not be assessed because GetGuardrail returned AccessDeniedException. Resolution
Set the contextual grounding filter threshold to at least 0.70 to reduce hallucinated responses. |
Informational | N/A |
777788889999 |
us-east-1 |
OW-06 |
OWASP LLM06: Bedrock Agent Guardrail Association
|
Low | Passed |
777788889999 |
us-east-1 |
OW-03 |
OWASP LLM03: Imported-Model KMS Provenance
|
Informational | N/A |
777788889999 |
us-east-1 |
OW-10 |
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-32: No CloudWatch alarms are configured on Amazon Bedrock runtime metrics (AWS/Bedrock namespace). Without alarms, abuse, denial-of-wallet, sustained throttling, and content-filter spikes can go undetected. Resolution
Create CloudWatch alarms on Bedrock InvocationThrottles, InputTokenCount, OutputTokenCount, and EstimatedTPMQuotaUsage. |
Medium | Failed |
777788889999 |
us-east-1 |
OW-03 |
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check BR-33: Amazon Inspector Lambda standard scanning and Lambda code scanning are both ENABLED in us-east-1. Detected 1 Lambda function(s) with Bedrock indicators: aiml-security-aiml-security-mgmt-BedrockAssessment. Resolution
Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain. |
Medium | Passed |
777788889999 |
us-east-1 |
OW-01 |
OWASP LLM01: Preventive Prompt Attack Filter
Details and remediation |
Informational | N/A |
777788889999 |
us-east-1 |
OW-02 |
OWASP LLM02: Bedrock Data Retention Boundary
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check BR-37: Bedrock account data retention is inherit; this does not establish an explicit account-level zero-data-retention setting. Resolution
Configure Bedrock account data retention as none and disable provider data sharing when prompts or responses may contain sensitive information. |
High | Failed |
777788889999 |
us-east-1 |
OW-02 |
OWASP LLM02: Automated Reasoning Policy Encryption
Details and remediation |
Informational | N/A |
777788889999 |
us-east-1 |
OW-03 |
OWASP LLM03: Marketplace Endpoint VPC Isolation
Details and remediation |
Informational | N/A |
777788889999 |
us-east-1 |
OW-02 |
OWASP LLM02: Marketplace Endpoint CMK Encryption
|
Informational | N/A |
777788889999 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Internet Exposure
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-01: SageMaker notebook instance 'aiml-sec-test-notebook-with-internet' has direct internet access enabled Resolution
Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths. |
High | Failed |
777788889999 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Internet Exposure
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-01: SageMaker domain 'd-ilmtsfeenavc' (aiml-sec-test-domain-fail-028e1010-52cbf970) is not configured for VPC-only access Resolution
Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths. |
High | Failed |
777788889999 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Internet Exposure
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-01: SageMaker domain 'd-cmz7ohkxxop3' (aiml-sec-test-domain-fail-fef4e7f0-bb429d11) is not configured for VPC-only access Resolution
Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths. |
High | Failed |
777788889999 |
us-east-1 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: Notebook Instance 'aiml-sec-test-notebook-with-internet' - No KMS key configured Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
High | Failed |
777788889999 |
us-east-1 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: Domain 'aiml-sec-test-domain-fail-028e1010-52cbf970' - No KMS key configured Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
High | Failed |
777788889999 |
us-east-1 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: Domain 'aiml-sec-test-domain-fail-fef4e7f0-bb429d11' - No KMS key configured Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
High | Failed |
777788889999 |
us-east-1 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: Training Job 'aiml-sec-test-training-no-encryption-028e1010-e2fb8765' - No output encryption configured Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
High | Failed |
777788889999 |
us-east-1 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: Training Job 'aiml-sec-test-training-no-encryption-028e1010-e2fb8765' - Inter-container traffic encryption not enabled Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
Medium | Failed |
777788889999 |
us-east-1 |
OW-01 |
OWASP LLM01: GuardDuty AI Protection
|
High | Failed |
777788889999 |
us-east-1 |
OW-10 |
OWASP LLM10: GuardDuty AI Protection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check SM-26: GuardDuty is enabled, but the AI Protection detector feature is not enabled. Resolution
Enable the GuardDuty AI_PROTECTION detector feature to detect supported anomalous model invocation and cost-harvesting activity. |
High | Failed |
777788889999 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Clarify Evaluation
|
Informational | N/A |
777788889999 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation |
Informational | N/A |
777788889999 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Model Monitor Coverage
|
Informational | N/A |
777788889999 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Notebook VPC Deployment
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-10: Notebook instance 'aiml-sec-test-notebook-with-internet' is not deployed in a custom VPC. This uses SageMaker's service VPC with reduced network isolation. Resolution
Deploy SageMaker notebook instances inside a VPC so package, data, and model artifact access can be controlled through private network paths. |
High | Failed |
777788889999 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Model Network Isolation
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-11: Model 'SageMakerModelNoIsolation-yQ7EpJeL7pgI' does not have network isolation enabled. Model containers can make outbound network calls, potentially exfiltrating data. Resolution
Enable network isolation on SageMaker models so inference containers cannot make unmanaged outbound calls that alter dependencies or exfiltrate model artifacts. |
High | Failed |
777788889999 |
us-east-1 |
OW-10 |
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check SM-11: Model 'SageMakerModelNoIsolation-yQ7EpJeL7pgI' does not have network isolation enabled. Model containers can make outbound network calls, potentially exfiltrating data. Resolution
Enable SageMaker model network isolation to prevent deployed model containers from making uncontrolled outbound calls that can amplify consumption or abuse downstream services. |
High | Failed |
777788889999 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Container Repository Access
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-14: Model 'SageMakerModelWithIsolation-JASFpUHjajdk' uses Platform repository access mode. Container images are pulled from public/external registries, exposing supply chain risks. Resolution
Configure SageMaker models to pull container images from private ECR repositories through VPC repository access instead of platform or public registry paths. |
Medium | Failed |
777788889999 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Container Repository Access
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-14: Model 'SageMakerModelNoIsolation-yQ7EpJeL7pgI' uses Platform repository access mode. Container images are pulled from public/external registries, exposing supply chain risks. Resolution
Configure SageMaker models to pull container images from private ECR repositories through VPC repository access instead of platform or public registry paths. |
Medium | Failed |
777788889999 |
us-east-1 |
OW-02 |
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-15: Feature group 'aiml-sec-test-feature-group' offline store does not have KMS encryption configured. Feature data in S3 may not be encrypted with customer-managed keys. Resolution
Encrypt SageMaker Feature Store offline stores with customer-managed KMS keys so sensitive feature data is protected at rest. |
Medium | Failed |
777788889999 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker AutoML Network Isolation
|
Informational | N/A |
777788889999 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: Checked 1 model package groups. Approval workflows appear to be properly configured. Resolution
Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically. |
Medium | Passed |
777788889999 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check SM-22: Checked 1 model package groups. Approval workflows appear to be properly configured. Resolution
Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release. |
Medium | Passed |
777788889999 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
777788889999 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
777788889999 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain. |
Informational | N/A |
777788889999 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated. |
Informational | N/A |
777788889999 |
us-east-1 |
OW-02 |
OWASP LLM02: HyperPod Volume CMK Encryption
Details and remediation |
Informational | N/A |
777788889999 |
us-east-1 |
OW-03 |
OWASP LLM03: HyperPod VPC Boundary
Details and remediation |
Informational | N/A |
777788889999 |
us-east-1 |
OW-03 |
OWASP LLM03: Model Registry Resource Policy Boundary
Details and remediation |
High | Passed |
777788889999 |
Global |
OW-06 |
OWASP LLM06: AgentCore IAM Least Privilege
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check AC-02: The following roles have wildcard or allow-except AgentCore permissions on all resources: aiml-sec-test-resources-AgentCoreOverlyPermissiveRo-IQso7VQN0jOV Resolution
Remove AmazonBedrockAgentCoreFullAccess (or equivalents) from identities that only need read/execute permissions. |
High | Failed |
777788889999 |
us-east-1 |
OW-06 |
OWASP LLM06: AgentCore Resource-Based Policies
|
Informational | N/A |
777788889999 |
us-east-1 |
OW-02 |
OWASP LLM02: AgentCore Token Vault CMK Encryption
Details and remediation |
High | Failed |
777788889999 |
us-east-1 |
OW-06 |
OWASP LLM06: Code Interpreter Network Isolation
|
Informational | N/A |
777788889999 |
us-east-1 |
OW-06 |
OWASP LLM06: Browser Tool Network Isolation
|
Informational | N/A |
777788889999 |
Global |
OW-10 |
OWASP LLM10: WAF Rate-Based & Shield Protection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-01: AWS Shield Advanced is not subscribed. GenAI API endpoints are vulnerable to volumetric DDoS attacks that can exhaust token quotas and inflate costs. Resolution
Add a WAF RateBasedStatement plus a SizeConstraintStatement on the GenAI ingress and subscribe to AWS Shield Advanced. |
Low | Failed |
777788889999 |
Global |
OW-10 |
OWASP LLM10: WAF Rate-Based & Shield Protection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-01: No AWS WAF regional Web ACLs found. Without WAF, GenAI endpoints lack rate-based rules to block abusive callers. Resolution
Add a WAF RateBasedStatement plus a SizeConstraintStatement on the GenAI ingress and subscribe to AWS Shield Advanced. |
Medium | Failed |
777788889999 |
Global |
OW-10 |
OWASP LLM10: API Gateway Usage Plans
|
Informational | N/A |
777788889999 |
Global |
OW-10 |
OWASP LLM10: Bedrock TPM/RPM Quotas Customised
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-03: Found 266 Bedrock token-based quota(s); at least one applied value exceeds the AWS default, indicating quotas have been reviewed and raised. Resolution
Customise Bedrock service quotas above the account default so consumption is explicitly bounded. |
Medium | Passed |
777788889999 |
Global |
OW-10 |
OWASP LLM10: Cost Anomaly Detection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-04: No AWS Cost Anomaly Detection monitors found. Unexpected spikes in Bedrock/SageMaker usage (e.g., from prompt injection loops) will go undetected. Resolution
Configure AWS Cost Anomaly Detection monitors that include Bedrock and SageMaker. |
Medium | Failed |
777788889999 |
Global |
OW-10 |
OWASP LLM10: Token / Throttle Alarms
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-05: No CloudWatch alarms found for Bedrock metrics. Token exhaustion and throttling events will not trigger operational alerts. Resolution
Create CloudWatch alarms on the Bedrock namespace for InvocationThrottles and token counters. |
Medium | Failed |
777788889999 |
Global |
OW-10 |
OWASP LLM10: AWS Budgets with Bedrock Filters
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-06: No AWS Budgets found scoped to Bedrock or SageMaker. Unbounded GenAI spend can go undetected until the monthly bill. Resolution
Configure AWS Budgets with FilterExpression / CostFilters targeting Bedrock or SageMaker spend, with an alerting SNS action. |
Medium | Failed |
777788889999 |
Global |
OW-06 |
OWASP LLM06: Agent Execution Role Least Privilege
|
High | Passed |
777788889999 |
Global |
OW-06 |
OWASP LLM06: AgentCore Gateway Policy Engine
|
Informational | N/A |
777788889999 |
Global |
OW-06 |
OWASP LLM06: Agent Tool Concurrency Limits
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check FS-09: Agent-related Lambda functions without reserved concurrency: aiml-sec-test-resources-SageMakerJobCustomResource-ZA5QCAi0pN3d, AIMLSecurityAssessment-CodeBuildStartBuildLambda-VYOqtzWoNo3m, aiml-security-aiml-security-mgmt-CleanupBucket, aiml-security-aiml-security-mgmt-SagemakerAssessment, aiml-security-aiml-security-mgmt-GenerateReport, aiml-security-aiml-security-mgmt-OWASPAssessment, aiml-security-aiml-security-mgmt-IAMPermissionCaching, aiml-security-aiml-security-mgmt-AgentRegistryAssessment, aiml-security-aiml-security-mgmt-RAIGRCAssessment, aiml-security-aiml-security-mgmt-AgentCoreAssessment. Unlimited concurrency allows runaway agent loops to exhaust account limits. Resolution
Set reserved concurrency on agent action-group Lambdas so a runaway agent cannot exhaust downstream capacity. |
Medium | Failed |
777788889999 |
Global |
OW-06 |
OWASP LLM06: Human-in-the-Loop Callback States
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check FS-10: No Step Functions state machines with agent/approval naming found. Verify that high-risk agent actions (e.g., fund transfers, account changes) have human approval gates. Resolution
Insert Step Functions .waitForTaskToken callback states before any high-risk agent-triggered action. |
Informational | N/A |
777788889999 |
Global |
OW-03 |
OWASP LLM03: SCP-Enforced Model Allowlist
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check FS-12: No Service Control Policies reference Bedrock. Without SCPs, any account in the organization can access any Bedrock model, including unapproved third-party models. Resolution
Attach an Organizations SCP that denies Bedrock inference outside allowlisted model and inference-profile ARNs using Resource or NotResource scoping. |
High | Failed |
777788889999 |
Global |
OW-03 |
OWASP LLM03: Custom-Model Provenance Tags
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check FS-13: 2 model(s) missing required provenance tags: - SageMaker model 'SageMakerModelWithIsolation-JASFpUHjajdk' missing tags: {'version', 'source', 'approval-date'} - SageMaker model 'SageMakerModelNoIsolation-yQ7EpJeL7pgI' missing tags: {'version', 'source', 'approval-date'} Resolution
Tag every Bedrock custom model with model-source, model-version, approval-date, and risk-tier so provenance is auditable. |
Medium | Failed |
777788889999 |
Global |
OW-03 |
OWASP LLM03: Config Rules for Model Onboarding
|
Medium | Passed |
777788889999 |
Global |
OW-03 |
OWASP LLM03: Adversarial Evaluation Coverage
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check FS-15: No Bedrock Model Evaluation jobs found. Models have not been evaluated for adversarial robustness. Model-risk management (SR 11-7) expects documented model validation/evaluation. Resolution
Run Bedrock evaluation jobs that include adversarial and safety datasets before promoting a model to production. |
Medium | Failed |
777788889999 |
Global |
OW-03 |
OWASP LLM03: ECR Image Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check FS-16: Amazon Inspector enhanced scanning for ECR is ENABLED account-wide, so all 3 repository(ies) are continuously scanned. 2 repository(ies) do not set scan-on-push (aiml-sec-test-agentcore-no-encryption, cdk-hnb659fds-container-assets-777788889999-us-east-1), which is expected when enhanced scanning supersedes basic scanning. Resolution
Enable Amazon Inspector enhanced scanning or scan-on-push on ECR repositories that hold model / agent container images. |
High | Passed |
777788889999 |
Global |
OW-04 |
OWASP LLM04: Feature Store Offline Recovery
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check FS-20: 1 of 1 feature group(s) have an OfflineStoreConfig: aiml-sec-test-feature-group. Offline-store presence enables rollback; it does not prove the offline data is retained, versioned, or complete. Resolution
Enable OfflineStoreConfig on SageMaker Feature Groups so features have a durable, point-in-time record for rollback after a poisoning event. |
Medium | Passed |
777788889999 |
Global |
OW-04 |
OWASP LLM04: Training-Data Versioning
|
High | Passed |
777788889999 |
Global |
OW-08 |
OWASP LLM08: KB IAM Scope
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-22: 822 role(s) with wildcard KB permissions: - Role 'Admin' allows '*' - Role 'aiml-sec-test-resources-BedrockAgentRole-RScmoTZfp2sC' allows 'bedrock:InvokeModel' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-test-resources-BedrockAgentRole-RScmoTZfp2sC' allows 'bedrock:InvokeModelWithResponseStream' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-test-resources-BedrockAgentRoleWithoutGuar-Z3kN5ANhP89G' allows 'bedrock:InvokeModel' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-test-resources-BedrockAgentRoleWithoutGuar-Z3kN5ANhP89G' allows 'bedrock:InvokeModelWithResponseStream' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-test-resources-BedrockFullAccessRole-zAFkGLkWQ61a' allows 'bedrock:*' - Role 'aiml-security-mgmt-BedrockSecurityAssessmentFunctio-a7GKJ6O4151K' allows 'bedrock:ListGuardrails' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-mgmt-BedrockSecurityAssessmentFunctio-a7GKJ6O4151K' allows 'bedrock:GetGuardrail' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-mgmt-BedrockSecurityAssessmentFunctio-a7GKJ6O4151K' allows 'bedrock:ListModelInvocationJobs' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-mgmt-BedrockSecurityAssessmentFunctio-a7GKJ6O4151K' allows 'bedrock:GetModelInvocationLoggingConfiguration' on Resource '*' (no ARN scoping to specific Knowledge Bases) Resolution
Scope Knowledge Base IAM roles to specific KB ARNs; remove wildcard bedrock:* on KB actions. |
High | Failed |
777788889999 |
Global |
OW-08 |
OWASP LLM08: KB Metadata Filtering
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-24: Found 1 Knowledge Base(s). Tenant-isolation metadata filtering is a design pattern that cannot be verified via API — manual review required. Verify that metadata attributes (e.g., tenantId, classification) are indexed and that Retrieve calls include RetrievalFilter conditions for tenant isolation. Resolution
Define Knowledge Base metadata fields so tenant / document-level filtering can be applied at retrieval time. |
Informational | N/A |
777788889999 |
Global |
OW-08 |
OWASP LLM08: OpenSearch Serverless Encryption
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-25: 1 of 1 collection(s) are encrypted with an AWS-owned key (kmsKeyArn="auto"): bedrock-knowledge-base-mjnkl5. Financial-services data-protection controls typically require a customer-managed KMS key for key lifecycle control and auditability. Resolution
Use a customer-managed KMS key on the OpenSearch Serverless encryption policy for the vector collection. |
High | Failed |
777788889999 |
Global |
OW-08 |
OWASP LLM08: OpenSearch Serverless Network Policy
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-26: Found 1 network policy(ies) but none restrict to VPC. Vector stores may be accessible from the public internet. Resolution
Set AllowFromPublic=false on the OpenSearch Serverless network policy and restrict access to bedrock.amazonaws.com or a specific VPC endpoint. |
High | Failed |
777788889999 |
Global |
OW-09 |
OWASP LLM09: Knowledge-Base Ingestion Freshness
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check FS-31: 1 data source(s) not synced in >7 days (a configurable review threshold, NOT an AWS-mandated limit): - KB 'knowledge-base-prowler-findings' source 'knowledge-base-quick-start-9lb68-data-source' last completed ingestion 478 days ago Confirm this age is acceptable for each data source's currency requirement — slow-changing reference data may legitimately sync infrequently. Resolution
Sync Knowledge Base data sources on a schedule (weekly at most); stale KB content increases hallucination risk. |
Medium | Failed |
777788889999 |
Global |
OW-09 |
OWASP LLM09: Source Attribution
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check FS-32: Source attribution in GenAI responses cannot be verified via AWS APIs. Manual review required to confirm responses include citations. Resolution
Return citations in RetrieveAndGenerate responses so end users can verify grounding. |
Informational | N/A |
777788889999 |
Global |
OW-09 |
OWASP LLM09: KB S3 Data-Source Integrity
|
Medium | Passed |
777788889999 |
Global |
OW-04 |
OWASP LLM04: SageMaker Model Card Documentation
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check FS-42: No SageMaker Model Cards found. If GenAI workloads run on Bedrock rather than SageMaker, model documentation may legitimately live elsewhere; Model Cards are a SageMaker-specific artifact. Resolution
Create SageMaker Model Cards for production models that document intended use, training data provenance, and bias/fairness evaluations so poisoned or drifted models are detectable against a documented baseline. |
Informational | N/A |
777788889999 |
Global |
OW-09 |
OWASP LLM09: SageMaker Model Card Documentation
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check FS-42: No SageMaker Model Cards found. If GenAI workloads run on Bedrock rather than SageMaker, model documentation may legitimately live elsewhere; Model Cards are a SageMaker-specific artifact. Resolution
Document each production model's intended use, known limitations, and evaluation results in a SageMaker Model Card so misinformation risks tied to model behaviour are traceable to a reviewed system card. |
Informational | N/A |
777788889999 |
Global |
OW-02 |
OWASP LLM02: CloudWatch Log Data Protection Policies
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-43: Bedrock model invocation logging is not enabled, so no invocation logs are being delivered and there is no log content to mask. Prompt and completion content is therefore also unavailable for audit. Resolution
Apply a CloudWatch Logs data protection policy to log groups that receive Bedrock invocation logs. |
Informational | N/A |
777788889999 |
Global |
OW-02 |
OWASP LLM02: Macie Sensitive-Data Discovery
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-44: Amazon Macie is not enabled in this region (status: NOT_ENABLED). S3 buckets containing training data and KB data sources are not being scanned for PII or other sensitive data. Resolution
Enable Amazon Macie with automated discovery on S3 buckets that hold training or knowledge-base data. |
High | Failed |
777788889999 |
Global |
OW-02 |
OWASP LLM02: Guardrail PII Entities Coverage
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-45: This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved. Resolution
Add the required PII entity types to the guardrail sensitiveInformationPolicy so PII in prompts/responses is filtered. |
Informational | N/A |
777788889999 |
Global |
OW-02 |
OWASP LLM02: S3 Data-Classification Tagging
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-46: 3 AI/ML bucket(s) without data-classification tags: aiml-sec-test-resources-bedrockloggingbucket-wtuvpinrlpmd, aiml-sec-test-resources-sagemakerbucket-6zzmxxaxco6g, aiml-security-mgmt-aimlassessmentbucket-kbitsdgexylv. Resolution
Tag training and knowledge-base S3 buckets with a data-classification tag so downstream automations enforce controls consistent with the sensitivity level. |
Medium | Failed |
777788889999 |
Global |
OW-09 |
OWASP LLM09: Grounding Filter Threshold
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check FS-47: This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved. Resolution
Set the contextual grounding filter threshold to at least 0.70 on guardrails used for RAG workflows. |
Informational | N/A |
777788889999 |
Global |
OW-09 |
OWASP LLM09: Active Knowledge Base Present
|
Medium | Passed |
777788889999 |
Global |
OW-01 |
OWASP LLM01: PROMPT_ATTACK Filter at Standard Tier
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check FS-51: This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved. Resolution
Set guardrail PROMPT_ATTACK filter to Standard tier with inputStrength=HIGH. |
Informational | N/A |
777788889999 |
Global |
OW-01 |
OWASP LLM01: Bedrock-Calling Lambda Runtimes
|
Medium | Passed |
777788889999 |
Global |
OW-01 |
OWASP LLM01: WAF SQLi & KnownBadInputs Coverage
|
Informational | N/A |
777788889999 |
Global |
OW-01 |
OWASP LLM01: Adversarial Testing Evidence
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check FS-54: Penetration testing evidence cannot be verified via AWS APIs. Manual review required to confirm GenAI applications have been tested. Resolution
Track adversarial / red-team penetration test evidence for the GenAI application via resource tags or an equivalent audit trail. |
Informational | N/A |
777788889999 |
Global |
OW-05 |
OWASP LLM05: Output-Validation Lambda
Details and remediationDetails
OWASP category: LLM05:2025 Improper Output Handling. Source check FS-55: No Lambda functions with output validation/sanitization naming found. GenAI outputs may be passed directly to downstream systems without validation. Resolution
Deploy an output-validation / sanitisation Lambda between the model response and any downstream consumer to filter injection payloads in generated output. |
Medium | Failed |
777788889999 |
Global |
OW-05 |
OWASP LLM05: WAF XSS Protection
|
Informational | N/A |
777788889999 |
Global |
OW-05 |
OWASP LLM05: Output Encoding Libraries
Details and remediationDetails
OWASP category: LLM05:2025 Improper Output Handling. Source check FS-57: Output encoding practices cannot be verified via AWS APIs. Manual code review required. Resolution
Ensure Lambdas that render model output use a well-known output-encoding library appropriate to the downstream sink (HTML, SQL, shell, etc.). |
Informational | N/A |
777788889999 |
Global |
OW-05 |
OWASP LLM05: Step Functions Output Schema Validation
Details and remediationDetails
OWASP category: LLM05:2025 Improper Output Handling. Source check FS-58: Found 0 Lambda function(s) whose names suggest schema/validation handling. Structured-output / JSON-schema validation of GenAI responses is an application-layer control that cannot be verified automatically — manual review required. Resolution
Add explicit schema-validation states in Step Functions workflows that consume model output. |
Informational | N/A |
777788889999 |
Global |
OW-06 |
OWASP LLM06: Agent Transaction Thresholds
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check FS-67: No Lambda functions matching agent action-group naming patterns found. If agents perform financial transactions, verify transaction-value limits are enforced in the action-group implementation. Resolution
Encode agent transaction thresholds in Cedar policies or Lambda configuration so per-action limits are enforced. |
Informational | N/A |
777788889999 |
Global |
OW-10 |
OWASP LLM10: API Gateway Request Body Size Limits
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-68: No API Gateway REST APIs and no regional WAF Web ACLs were found in this region. There is no input-payload surface to assess for body-size limits. Resolution
Configure API Gateway request validation or an equivalent ingress control so GenAI endpoints reject oversized request bodies before they can drive excessive model consumption. |
Informational | N/A |
777788889999 |
Global |
OW-01 |
OWASP LLM01: Prompt-Input Validation Lambda
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check FS-69: Found 1 Lambda function(s) with input validation/sanitization naming patterns: aiml-security-aiml-security-mgmt-CleanupBucket. Resolution
Deploy a prompt-input validation Lambda in front of Bedrock invocations to sanitise untrusted input before it reaches the model. |
Medium | Passed |
777788889999 |
us-east-1 |
OW-11 |
OWASP LLM07: System Prompt Embedded in Lambda Env Var
|
Medium | Passed |
777788889999 |
us-east-1 |
OW-12 |
OWASP LLM07: System-Prompt-Disclosure Denied Topic
Details and remediationDetails
Could not inspect 1 of 1 Bedrock guardrail(s) in us-east-1 for system-prompt-disclosure DENY topics. Readable guardrails inspected: 0. Sample unreadable guardrails: jkceg2tprvwh (AccessDeniedException). Resolution
Grant bedrock:GetGuardrail for the listed guardrails or resolve the read errors, then rerun the assessment. Do not treat this as proof that a DENY topic is absent. |
Informational | N/A |
777788889999 |
Global |
AC-02 |
AgentCore IAM Wildcard Permissions
Details and remediation |
High | Failed |
777788889999 |
Global |
AC-03 |
AgentCore Unused Permissions
Details and remediationDetails
The following principals have AgentCore permissions but have never accessed the service: role 'aiml-sec-test-resources-AgentCoreOverlyPermissiveRo-IQso7VQN0jOV', role 'AIMLSecurityMemberRole', role 'AwsSecurityAudit', role 'AWSServiceRoleForSupport', role 'cdk-hnb659fds-lookup-role-777788889999-us-east-1', role 'cdk-hnb659fds-lookup-role-777788889999-us-east-2', role 'cdk-hnb659fds-lookup-role-777788889999-us-west-2', role 'CloudSecAuditRole', role 'CloudSeerTrustedServiceRole', role 'EpoxyAccessRole', role 'IibsAdminAccess-DO-NOT-DELETE', role 'InternalAuditInternal', role 'ManagedInstance-CrossAccountExecutionRole', role 'Nova-DO-NOT-DELETE', role 'ProwlerMemberRole' Resolution
Review and remove unused AgentCore permissions following least privilege principle |
Informational | N/A |
777788889999 |
Global |
AC-09 |
AgentCore Service-Linked Role Missing
Details and remediationDetails
Service-linked role 'AWSServiceRoleForBedrockAgentCoreNetwork' does not exist. VPC configuration for AgentCore Runtimes will fail without this role. Resolution
Allow iam:CreateServiceLinkedRole for arn:PARTITION:iam::*:role/aws-service-role/network.bedrock-agentcore.amazonaws.com/AWSServiceRoleForBedrockAgentCoreNetwork, replacing PARTITION with the deployment partition, and add StringEquals for iam:AWSServiceName = network.bedrock-agentcore.amazonaws.com. Then configure VPC networking on an AgentCore Runtime so AWS creates the service-linked role. |
Medium | Failed |
777788889999 |
us-east-1 |
AC-01 |
AgentCore VPC Configuration Check
|
Informational | N/A |
777788889999 |
us-east-1 |
AC-04 |
AgentCore Observability Check
|
Informational | N/A |
777788889999 |
us-east-1 |
AC-05 |
AgentCore ECR Repository AWS-Managed Keys
|
Low | Failed |
777788889999 |
us-east-1 |
AC-06 |
AgentCore Browser Session Recording
|
Informational | N/A |
777788889999 |
us-east-1 |
AC-07 |
AgentCore Memory Configuration Check
|
Informational | N/A |
777788889999 |
us-east-1 |
AC-13 |
AgentCore Gateway Configuration Check
|
Informational | N/A |
777788889999 |
us-east-1 |
AC-08 |
AgentCore VPC Endpoints Check
|
Informational | N/A |
777788889999 |
us-east-1 |
AC-10 |
AgentCore Resource-Based Policies Check
|
Informational | N/A |
777788889999 |
us-east-1 |
AC-11 |
AgentCore Policy Engine Encryption Check
|
Informational | N/A |
777788889999 |
us-east-1 |
AC-12 |
AgentCore Gateway Encryption Check
|
Informational | N/A |
777788889999 |
us-east-1 |
AC-14 |
AgentCore Identity Token Vault CMK Encryption
|
High | Failed |
777788889999 |
us-east-1 |
AC-15 |
AgentCore Code Interpreter Network Isolation
|
Informational | N/A |
777788889999 |
us-east-1 |
AC-16 |
AgentCore Custom Browser Network Isolation
|
Informational | N/A |
777788889999 |
us-east-1 |
AC-17 |
AgentCore Online Evaluation Coverage
|
Medium | Failed |
777788889999 |
us-east-1 |
AG-24 |
Agentic AI Gateway Inbound Authorization
|
Informational | N/A |
777788889999 |
us-east-1 |
AG-25 |
Agentic AI Gateway Tool Policy Enforcement
|
Informational | N/A |
777788889999 |
us-east-1 |
AG-26 |
Agentic AI Gateway Error Detail Exposure
|
Informational | N/A |
777788889999 |
us-east-1 |
AG-27 |
Agentic AI Gateway WAF Protection
|
Informational | N/A |
777788889999 |
Global |
AG-16 |
Agentic AI AgentCore Least Privilege
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Over-permissive AgentCore principals can let agents or operators bypass intended autonomy and tool boundaries. Source check AC-02: The following roles have wildcard or allow-except AgentCore permissions on all resources: aiml-sec-test-resources-AgentCoreOverlyPermissiveRo-IQso7VQN0jOV Resolution
Replace full-access AgentCore permissions with least-privilege IAM policies scoped to required resources and actions. |
High | Failed |
777788889999 |
Global |
AG-17 |
Agentic AI Stale AgentCore Access
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Unused AgentCore permissions increase the blast radius of compromised principals. Source check AC-03: The following principals have AgentCore permissions but have never accessed the service: role 'aiml-sec-test-resources-AgentCoreOverlyPermissiveRo-IQso7VQN0jOV', role 'AIMLSecurityMemberRole', role 'AwsSecurityAudit', role 'AWSServiceRoleForSupport', role 'cdk-hnb659fds-lookup-role-777788889999-us-east-1', role 'cdk-hnb659fds-lookup-role-777788889999-us-east-2', role 'cdk-hnb659fds-lookup-role-777788889999-us-west-2', role 'CloudSecAuditRole', role 'CloudSeerTrustedServiceRole', role 'EpoxyAccessRole', role 'IibsAdminAccess-DO-NOT-DELETE', role 'InternalAuditInternal', role 'ManagedInstance-CrossAccountExecutionRole', role 'Nova-DO-NOT-DELETE', role 'ProwlerMemberRole' Resolution
Remove or restrict stale AgentCore permissions for principals that no longer need access. |
Informational | N/A |
777788889999 |
us-east-1 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
Informational | N/A |
777788889999 |
us-east-1 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Informational | N/A |
777788889999 |
us-east-1 |
AG-19 |
Agentic AI Memory Data Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found Resolution
Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions. |
Informational | N/A |
777788889999 |
us-east-1 |
AG-20 |
Agentic AI Private AgentCore Connectivity
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found Resolution
Create required VPC endpoints for AgentCore services and validate endpoint availability. |
Informational | N/A |
777788889999 |
us-east-1 |
AG-21 |
Agentic AI Resource Policy Boundary
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies Resolution
Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources. |
Informational | N/A |
777788889999 |
us-east-1 |
AG-22 |
Agentic AI Policy Engine Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found Resolution
Configure policy engines with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
777788889999 |
us-east-1 |
AG-23 |
Agentic AI Gateway Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found Resolution
Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
777788889999 |
us-east-1 |
AG-28 |
Agentic AI Identity Token Vault Protection
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Agent credentials stored in the Identity token vault should use customer-controlled encryption where enhanced key control is required. Source check AC-14: AgentCore token vault 'default' uses a service-managed or AWS-owned key. Resolution
Configure the AgentCore Identity token vault with a customer-managed KMS key. |
High | Failed |
777788889999 |
us-east-1 |
AG-29 |
Agentic AI Code Interpreter Isolation
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent-executed code should run inside an explicit VPC boundary with controlled network paths. Source check AC-15: No custom AgentCore Code Interpreters found Resolution
Configure custom AgentCore Code Interpreters in VPC mode with approved subnets and security groups. |
Informational | N/A |
777788889999 |
us-east-1 |
AG-31 |
Agentic AI Browser Tool Isolation
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Browser tools can reach external systems and should use explicit private network boundaries. Source check AC-16: No custom AgentCore browsers found Resolution
Configure custom AgentCore browsers in VPC mode with approved subnets and security groups. |
Informational | N/A |
777788889999 |
us-east-1 |
AG-32 |
Agentic AI Online Evaluation Assurance
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Online evaluation provides continuous evidence about agent behavior, quality, and policy-relevant outcomes. Source check AC-17: No AgentCore online evaluation configurations found. Resolution
Configure an active AgentCore online evaluation with sampling, evaluators, CloudWatch input logs, and an output log group. |
Medium | Failed |
777788889999 |
us-east-2 |
AC-01 |
AgentCore VPC Configuration Check
|
Informational | N/A |
777788889999 |
us-east-2 |
AC-04 |
AgentCore Observability Check
|
Informational | N/A |
777788889999 |
us-east-2 |
AC-05 |
AgentCore Encryption Check
|
Informational | N/A |
777788889999 |
us-east-2 |
AC-06 |
AgentCore Browser Session Recording
|
Informational | N/A |
777788889999 |
us-east-2 |
AC-07 |
AgentCore Memory Configuration Check
|
Informational | N/A |
777788889999 |
us-east-2 |
AC-13 |
AgentCore Gateway Configuration Check
|
Informational | N/A |
777788889999 |
us-east-2 |
AC-08 |
AgentCore VPC Endpoints Check
|
Informational | N/A |
777788889999 |
us-east-2 |
AC-10 |
AgentCore Resource-Based Policies Check
|
Informational | N/A |
777788889999 |
us-east-2 |
AC-11 |
AgentCore Policy Engine Encryption Check
|
Informational | N/A |
777788889999 |
us-east-2 |
AC-12 |
AgentCore Gateway Encryption Check
|
Informational | N/A |
777788889999 |
us-east-2 |
AC-14 |
AgentCore Identity Token Vault CMK Encryption
|
Informational | N/A |
777788889999 |
us-east-2 |
AC-15 |
AgentCore Code Interpreter Network Isolation
|
Informational | N/A |
777788889999 |
us-east-2 |
AC-16 |
AgentCore Custom Browser Network Isolation
|
Informational | N/A |
777788889999 |
us-east-2 |
AC-17 |
AgentCore Online Evaluation Coverage
|
Medium | Failed |
777788889999 |
us-east-2 |
AG-24 |
Agentic AI Gateway Inbound Authorization
|
Informational | N/A |
777788889999 |
us-east-2 |
AG-25 |
Agentic AI Gateway Tool Policy Enforcement
|
Informational | N/A |
777788889999 |
us-east-2 |
AG-26 |
Agentic AI Gateway Error Detail Exposure
|
Informational | N/A |
777788889999 |
us-east-2 |
AG-27 |
Agentic AI Gateway WAF Protection
|
Informational | N/A |
777788889999 |
us-east-2 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-19 |
Agentic AI Memory Data Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found Resolution
Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-20 |
Agentic AI Private AgentCore Connectivity
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found Resolution
Create required VPC endpoints for AgentCore services and validate endpoint availability. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-21 |
Agentic AI Resource Policy Boundary
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies Resolution
Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-22 |
Agentic AI Policy Engine Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found Resolution
Configure policy engines with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-23 |
Agentic AI Gateway Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found Resolution
Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-28 |
Agentic AI Identity Token Vault Protection
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Agent credentials stored in the Identity token vault should use customer-controlled encryption where enhanced key control is required. Source check AC-14: No assessable AgentCore Identity token vault was found. Resolution
Configure the AgentCore Identity token vault with a customer-managed KMS key. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-29 |
Agentic AI Code Interpreter Isolation
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent-executed code should run inside an explicit VPC boundary with controlled network paths. Source check AC-15: No custom AgentCore Code Interpreters found Resolution
Configure custom AgentCore Code Interpreters in VPC mode with approved subnets and security groups. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-31 |
Agentic AI Browser Tool Isolation
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Browser tools can reach external systems and should use explicit private network boundaries. Source check AC-16: No custom AgentCore browsers found Resolution
Configure custom AgentCore browsers in VPC mode with approved subnets and security groups. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-32 |
Agentic AI Online Evaluation Assurance
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Online evaluation provides continuous evidence about agent behavior, quality, and policy-relevant outcomes. Source check AC-17: No AgentCore online evaluation configurations found. Resolution
Configure an active AgentCore online evaluation with sampling, evaluators, CloudWatch input logs, and an output log group. |
Medium | Failed |
777788889999 |
us-west-2 |
BR-02 |
Amazon Bedrock private connectivity check
|
Informational | N/A |
777788889999 |
us-west-2 |
BR-04 |
Bedrock Model Invocation Logging Check
|
Informational | N/A |
777788889999 |
us-west-2 |
BR-05 |
Bedrock Guardrails Check
|
Informational | N/A |
777788889999 |
us-west-2 |
BR-06 |
Bedrock CloudTrail Logging Check
|
Informational | N/A |
777788889999 |
us-west-2 |
BR-07 |
Bedrock Prompt Management Check
Details and remediationDetails
Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates |
Informational | N/A |
777788889999 |
us-west-2 |
BR-08 |
Bedrock Agent IAM Roles Check
|
Informational | N/A |
777788889999 |
us-west-2 |
BR-09 |
Bedrock Knowledge Base Encryption Check
|
Informational | N/A |
777788889999 |
us-west-2 |
BR-10 |
Bedrock Guardrail IAM Enforcement Check
|
Informational | N/A |
777788889999 |
us-west-2 |
BR-11 |
Bedrock Custom Model Encryption Check
|
Informational | N/A |
777788889999 |
us-west-2 |
BR-12 |
Bedrock Invocation Log Encryption Check
|
Informational | N/A |
777788889999 |
us-west-2 |
BR-13 |
Bedrock Flows Guardrails Check
|
Informational | N/A |
777788889999 |
us-west-2 |
BR-16 |
Guardrail Tier Validation Check
|
Medium | N/A |
777788889999 |
us-west-2 |
BR-17 |
Custom Model Customer-Managed KMS Encryption Check
|
High | N/A |
777788889999 |
us-west-2 |
BR-18 |
Model Evaluation Implementation Check
|
Informational | N/A |
777788889999 |
us-west-2 |
BR-19 |
Prompt Flow Validation Check
|
Medium | N/A |
777788889999 |
us-west-2 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Check
|
High | N/A |
777788889999 |
us-west-2 |
BR-21 |
Agent Action Group IAM Least Privilege Check
|
High | N/A |
777788889999 |
us-west-2 |
BR-22 |
Model Invocation Throttling Limits Check
|
Informational | N/A |
777788889999 |
us-west-2 |
BR-23 |
Guardrail Content Filter Coverage Check
|
Informational | N/A |
777788889999 |
us-west-2 |
BR-24 |
Automated Reasoning Policy Implementation Check
|
Medium | N/A |
777788889999 |
us-west-2 |
BR-25 |
RAG Evaluation Jobs Check
|
Low | N/A |
777788889999 |
us-west-2 |
BR-26 |
Guardrail Sensitive Information Filter Check
|
High | N/A |
777788889999 |
us-west-2 |
BR-27 |
Guardrail Contextual Grounding Check
|
Medium | N/A |
777788889999 |
us-west-2 |
BR-28 |
Agent Guardrail Association Check
|
High | N/A |
777788889999 |
us-west-2 |
BR-29 |
Agent Idle Session TTL Check
|
Low | N/A |
777788889999 |
us-west-2 |
BR-30 |
Imported Model Customer-Managed KMS Encryption Check
|
High | N/A |
777788889999 |
us-west-2 |
BR-31 |
Batch Inference Output Encryption Check
|
Medium | N/A |
777788889999 |
us-west-2 |
BR-32 |
Bedrock CloudWatch Alarm Check
|
Informational | N/A |
777788889999 |
us-west-2 |
BR-33 |
Amazon Inspector Lambda Code Scanning Check
Details and remediationDetails
No Lambda functions with Bedrock indicators were found in us-west-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
No action required. If Bedrock-calling Lambda functions exist, ensure their function name, ARN, description, handler, role, or environment variables contain a Bedrock identifier that the assessment can detect, or evaluate Inspector coverage manually. |
Informational | N/A |
777788889999 |
us-west-2 |
BR-34 |
Guardrail Prompt Attack Filter
|
Informational | N/A |
777788889999 |
us-west-2 |
BR-35 |
Guardrail Image Content Filter Coverage
|
Informational | N/A |
777788889999 |
us-west-2 |
BR-36 |
Application Inference Profile Governance
|
Informational | N/A |
777788889999 |
us-west-2 |
BR-37 |
Bedrock Account Data Retention
|
High | Failed |
777788889999 |
us-west-2 |
BR-38 |
Automated Reasoning Policy CMK Encryption
|
Informational | N/A |
777788889999 |
us-west-2 |
BR-39 |
Marketplace Model Endpoint VPC Configuration
|
Informational | N/A |
777788889999 |
us-west-2 |
BR-40 |
Marketplace Model Endpoint CMK Encryption
|
Informational | N/A |
777788889999 |
us-west-2 |
AG-07 |
Agentic AI Model Invocation Logging
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-08 |
Agentic AI API Audit Trail
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage Resolution
Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-10 |
Agentic AI Adversarial Evaluation Coverage
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs Resolution
Configure model or application evaluations that include adversarial, safety, and security-relevant test cases. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-11 |
Agentic AI Prompt Flow Validation
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region Resolution
Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-06 |
Agentic AI Tool Execution Least Privilege
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region Resolution
Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-12 |
Agentic AI Invocation Abuse Controls
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas Resolution
Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-02 |
Agentic AI Harmful Content Guardrail Coverage
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-04 |
Agentic AI Automated Reasoning Guardrails
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: No Bedrock guardrails configured in this region Resolution
Configure automated reasoning policies on guardrails where formal response validation is required. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-03 |
Agentic AI Sensitive Information Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: No Bedrock guardrails configured in this region Resolution
Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-05 |
Agentic AI Grounding Controls
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: No Bedrock guardrails configured in this region Resolution
Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-01 |
Agentic AI Agent Guardrail Association
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region Resolution
Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-13 |
Agentic AI Session Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region Resolution
Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-14 |
Agentic AI Operational Abuse Alarms
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms Resolution
Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-30 |
Agentic AI Prompt Attack Protection
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agents should prevent prompt attacks before untrusted input can redirect planning or tool use. Source check BR-34: No Bedrock guardrails configured in this region Resolution
Enable a preventive PROMPT_ATTACK input filter on each guardrail and use Standard tier where prompt-leakage protection is required. |
Informational | N/A |
777788889999 |
Global |
FS-01 |
AWS Shield Advanced Not Enabled
Details and remediationDetails
AWS Shield Advanced is not subscribed. GenAI API endpoints are vulnerable to volumetric DDoS attacks that can exhaust token quotas and inflate costs. Resolution
1. Subscribe to AWS Shield Advanced for DDoS protection. 2. After subscribing, explicitly add resource protections in the Shield Advanced console for each Bedrock-facing resource (API Gateway stages, ALBs, CloudFront distributions, Route 53 hosted zones). Shield Advanced subscription alone does NOT automatically protect resources — each resource must be individually added to receive protection. 3. Enable Shield Response Team (SRT) access and configure proactive engagement. 4. Alternatively, use AWS Firewall Manager with a Shield Advanced policy to automate resource protection based on tags or resource types. |
Low | Failed |
777788889999 |
Global |
FS-01 |
No Regional WAF Web ACLs Found
Details and remediationDetails
No AWS WAF regional Web ACLs found. Without WAF, GenAI endpoints lack rate-based rules to block abusive callers. Resolution
1. Create a WAF Web ACL with rate-based rules (e.g., 1000 req/5 min per IP). 2. Associate the ACL with API Gateway stages or ALBs fronting Bedrock. 3. Add AWS Managed Rules for known bad inputs. |
Medium | Failed |
777788889999 |
Global |
FS-02 |
No API Gateway Usage Plans Found
|
Informational | N/A |
777788889999 |
Global |
FS-03 |
Bedrock Token Quotas Customized
|
Medium | Passed |
777788889999 |
Global |
FS-04 |
No Cost Anomaly Detection Monitors
Details and remediationDetails
No AWS Cost Anomaly Detection monitors found. Unexpected spikes in Bedrock/SageMaker usage (e.g., from prompt injection loops) will go undetected. Resolution
1. Create a Cost Anomaly Detection monitor scoped to AWS/Bedrock and AWS/SageMaker. 2. Configure alert subscriptions (SNS/email) for anomalies above threshold. 3. Set daily spend budgets with AWS Budgets as a secondary control. |
Medium | Failed |
777788889999 |
Global |
FS-05 |
No Bedrock CloudWatch Alarms Found
Details and remediationDetails
No CloudWatch alarms found for Bedrock metrics. Token exhaustion and throttling events will not trigger operational alerts. Resolution
Create CloudWatch alarms for: - AWS/Bedrock InvocationThrottles (threshold > 0) - AWS/Bedrock TokensProcessed (threshold based on quota) - Custom application-level token counters via EMF |
Medium | Failed |
777788889999 |
Global |
FS-06 |
No AI/ML Service Budgets Configured
Details and remediationDetails
No AWS Budgets found scoped to Bedrock or SageMaker. Unbounded GenAI spend can go undetected until the monthly bill. Resolution
1. Create cost budgets for AWS Bedrock and SageMaker with 80%/100% alert thresholds. 2. Add SNS notifications to on-call channels. 3. Consider budget actions to apply IAM deny policies when thresholds are breached. |
Medium | Failed |
777788889999 |
Global |
FS-07 |
Agent Action Boundaries Look Appropriate
|
High | Passed |
777788889999 |
Global |
FS-08 |
No AgentCore Runtimes Found
|
Informational | N/A |
777788889999 |
Global |
FS-09 |
Agent Lambda Functions Without Concurrency Limits
Details and remediationDetails
Agent-related Lambda functions without reserved concurrency: aiml-sec-test-resources-SageMakerJobCustomResource-ZA5QCAi0pN3d, AIMLSecurityAssessment-CodeBuildStartBuildLambda-VYOqtzWoNo3m, aiml-security-aiml-security-mgmt-CleanupBucket, aiml-security-aiml-security-mgmt-SagemakerAssessment, aiml-security-aiml-security-mgmt-GenerateReport, aiml-security-aiml-security-mgmt-OWASPAssessment, aiml-security-aiml-security-mgmt-IAMPermissionCaching, aiml-security-aiml-security-mgmt-AgentRegistryAssessment, aiml-security-aiml-security-mgmt-RAIGRCAssessment, aiml-security-aiml-security-mgmt-AgentCoreAssessment. Unlimited concurrency allows runaway agent loops to exhaust account limits. Resolution
1. Set reserved concurrency on agent Lambda functions. 2. Implement maximum iteration counts in agent orchestration logic. 3. Use Step Functions with MaxConcurrency and timeout states. 4. Add circuit-breaker patterns to agent tool invocations. |
Medium | Failed |
777788889999 |
Global |
FS-10 |
Human-in-the-Loop Check — No Agent Workflows Found
Details and remediationDetails
No Step Functions state machines with agent/approval naming found. Verify that high-risk agent actions (e.g., fund transfers, account changes) have human approval gates. Resolution
Implement Step Functions .waitForTaskToken patterns for high-risk agent actions. Route approval requests to human reviewers via SNS/SES/Slack. |
Informational | N/A |
777788889999 |
Global |
FS-11 |
No Agent Rate Alarms Found
Details and remediationDetails
No CloudWatch alarms found for agent invocation rates. Looping or runaway agents will not trigger operational alerts. Resolution
Create CloudWatch alarms on: - Bedrock agent invocation counts (threshold based on expected max) - Lambda invocation errors for agent functions - Step Functions execution failures and timeouts |
Medium | Failed |
777788889999 |
Global |
FS-12 |
No Bedrock-Scoped SCPs Found
Details and remediationDetails
No Service Control Policies reference Bedrock. Without SCPs, any account in the organization can access any Bedrock model, including unapproved third-party models. Resolution
1. Create an SCP that denies bedrock:InvokeModel, bedrock:InvokeModelWithResponseStream, and bedrock:CreateModelInvocationJob outside approved model access. 2. Use Resource or NotResource with approved foundation-model, custom-model, provisioned-model, and inference-profile ARNs to express the allowlist. 3. Maintain a model inventory and update the SCP when models are approved/retired. |
High | Failed |
777788889999 |
Global |
FS-13 |
Models Missing Provenance Tags
Details and remediationDetails
2 model(s) missing required provenance tags: - SageMaker model 'SageMakerModelWithIsolation-JASFpUHjajdk' missing tags: {'version', 'source', 'approval-date'} - SageMaker model 'SageMakerModelNoIsolation-yQ7EpJeL7pgI' missing tags: {'version', 'source', 'approval-date'} Resolution
Tag all models with: source (e.g., 'aws-marketplace', 'internal'), version, and approval-date. Enforce tagging via SCP or AWS Config rule. |
Medium | Failed |
777788889999 |
Global |
FS-14 |
Model Governance Config Rules Present
|
Medium | Passed |
777788889999 |
Global |
FS-15 |
No Bedrock Evaluation Jobs Found
Details and remediationDetails
No Bedrock Model Evaluation jobs found. Models have not been evaluated for adversarial robustness. Model-risk management (SR 11-7) expects documented model validation/evaluation. Resolution
1. Run Bedrock Model Evaluation with adversarial/red-team datasets. 2. Use FMEval library for automated robustness testing. 3. Schedule periodic re-evaluation after model updates. |
Medium | Failed |
777788889999 |
Global |
FS-16 |
ECR Image Scanning Covered by Inspector Enhanced Scanning
Details and remediationDetails
Amazon Inspector enhanced scanning for ECR is ENABLED account-wide, so all 3 repository(ies) are continuously scanned. 2 repository(ies) do not set scan-on-push (aiml-sec-test-agentcore-no-encryption, cdk-hnb659fds-container-assets-777788889999-us-east-1), which is expected when enhanced scanning supersedes basic scanning. Resolution
No action required while Inspector enhanced scanning stays enabled. If it is disabled, enable scan-on-push per repository. |
High | Passed |
777788889999 |
Global |
FS-20 |
Feature Groups With Offline Store Configured
Details and remediationDetails
1 of 1 feature group(s) have an OfflineStoreConfig: aiml-sec-test-feature-group. Offline-store presence enables rollback; it does not prove the offline data is retained, versioned, or complete. Resolution
1. Enable S3 versioning on each offline store bucket. 2. Document rollback procedures for poisoned feature data. |
Medium | Passed |
777788889999 |
Global |
FS-21 |
Training Data Buckets Have Versioning
|
High | Passed |
777788889999 |
Global |
FS-22 |
Overly Permissive Knowledge Base IAM Roles
Details and remediationDetails
822 role(s) with wildcard KB permissions: - Role 'Admin' allows '*' - Role 'aiml-sec-test-resources-BedrockAgentRole-RScmoTZfp2sC' allows 'bedrock:InvokeModel' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-test-resources-BedrockAgentRole-RScmoTZfp2sC' allows 'bedrock:InvokeModelWithResponseStream' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-test-resources-BedrockAgentRoleWithoutGuar-Z3kN5ANhP89G' allows 'bedrock:InvokeModel' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-test-resources-BedrockAgentRoleWithoutGuar-Z3kN5ANhP89G' allows 'bedrock:InvokeModelWithResponseStream' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-test-resources-BedrockFullAccessRole-zAFkGLkWQ61a' allows 'bedrock:*' - Role 'aiml-security-mgmt-BedrockSecurityAssessmentFunctio-a7GKJ6O4151K' allows 'bedrock:ListGuardrails' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-mgmt-BedrockSecurityAssessmentFunctio-a7GKJ6O4151K' allows 'bedrock:GetGuardrail' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-mgmt-BedrockSecurityAssessmentFunctio-a7GKJ6O4151K' allows 'bedrock:ListModelInvocationJobs' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-mgmt-BedrockSecurityAssessmentFunctio-a7GKJ6O4151K' allows 'bedrock:GetModelInvocationLoggingConfiguration' on Resource '*' (no ARN scoping to specific Knowledge Bases) Resolution
Replace wildcard bedrock:* with specific actions such as bedrock:Retrieve, bedrock:RetrieveAndGenerate. Scope resources to specific Knowledge Base ARNs. |
High | Failed |
777788889999 |
Global |
FS-24 |
ADVISORY: Knowledge Base Metadata Filtering — Manual Review Required
Details and remediationDetails
Found 1 Knowledge Base(s). Tenant-isolation metadata filtering is a design pattern that cannot be verified via API — manual review required. Verify that metadata attributes (e.g., tenantId, classification) are indexed and that Retrieve calls include RetrievalFilter conditions for tenant isolation. Resolution
1. Add metadata fields (tenantId, dataClassification) to KB data sources. 2. Pass RetrievalFilter in all Retrieve/RetrieveAndGenerate calls. 3. Validate filters in integration tests to prevent cross-tenant data leakage. |
Informational | N/A |
777788889999 |
Global |
FS-25 |
OpenSearch Serverless Collections Using AWS-Owned Encryption Keys
Details and remediationDetails
1 of 1 collection(s) are encrypted with an AWS-owned key (kmsKeyArn="auto"): bedrock-knowledge-base-mjnkl5. Financial-services data-protection controls typically require a customer-managed KMS key for key lifecycle control and auditability. Resolution
1. Create a customer-managed KMS key and grant aoss.amazonaws.com the required key permissions. 2. Create an encryption policy for the collection with AWSOwnedKey=false and KmsARN set to that key. 3. The encryption key is fixed at collection creation, so the collection must be recreated and re-indexed to change it. |
High | Failed |
777788889999 |
Global |
FS-26 |
OpenSearch Serverless Collections Not VPC-Restricted
|
High | Failed |
777788889999 |
Global |
FS-27 |
COULD NOT ASSESS: Guardrail Contextual Grounding Check
Details and remediationDetails
This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved. Resolution
1. Confirm the assessment role grants the actions this check requires (see the documented IAM permission set in the README). 2. Confirm the service/feature is supported in the assessed region. 3. Ensure botocore meets the version floor in requirements.txt. 4. Re-run the assessment; assess this control manually until it succeeds. |
Low | N/A |
777788889999 |
Global |
FS-27 |
No Automated Reasoning Policies Found
Details and remediationDetails
No Bedrock Automated Reasoning policies have been created. ARC (GA August 2025) uses formal verification to guarantee that GenAI outputs comply with authored business rules — e.g., loan criteria, regulatory thresholds, policy constraints. Without ARC policies, factual accuracy of outputs is not formally verified, only heuristically filtered by contextual grounding thresholds. Resolution
1. In the Amazon Bedrock console → Guardrails → Automated Reasoning, create a policy document encoding your business rules (e.g., eligibility criteria, rate limits, regulatory thresholds). 2. Associate the ARC policy with your guardrail (automatedReasoningPolicy.policies field in CreateGuardrail/UpdateGuardrail). 3. Set confidenceThreshold on the policy to control strictness. 4. ARC requires cross-Region inference — ensure your guardrail has a guardrailProfileArn configured (crossRegionDetails in GetGuardrail response). 5. Reference: AWS Announcement — Automated Reasoning checks GA (August 2025). |
Medium | Failed |
777788889999 |
Global |
FS-28 |
COULD NOT ASSESS: Guardrail Topic Policy Check
Details and remediationDetails
This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved. Resolution
1. Confirm the assessment role grants the actions this check requires (see the documented IAM permission set in the README). 2. Confirm the service/feature is supported in the assessed region. 3. Ensure botocore meets the version floor in requirements.txt. 4. Re-run the assessment; assess this control manually until it succeeds. |
Low | N/A |
777788889999 |
Global |
FS-29 |
ADVISORY: Compliance Disclaimer — Manual Review Required
Details and remediationDetails
Application-level compliance disclaimers cannot be verified via AWS APIs. Manual review required to confirm GenAI outputs include required regulatory disclosures. Resolution
1. Implement post-processing to append required disclaimers to GenAI outputs. 2. Use Bedrock Guardrails word filters to block outputs that omit required disclosures. 3. Document disclaimer requirements in the AI use case register. 4. Test disclaimer presence in QA/UAT before production deployment. |
Informational | N/A |
777788889999 |
Global |
FS-30 |
ADVISORY: Compliance Dataset Coverage — Manual Review Required
Details and remediationDetails
Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation jobs include compliance-specific datasets (fair lending/ECOA, Fair Housing Act, UDAP/UDAAP, AML/KYC edge cases). Whether any evaluation jobs exist at all is assessed by FS-15. Resolution
Run Bedrock Model Evaluation with compliance-specific datasets: - Fair lending test cases (ECOA, Fair Housing Act) - UDAP/UDAAP unfair/deceptive practice scenarios - AML/KYC edge cases |
Informational | N/A |
777788889999 |
Global |
FS-31 |
Knowledge Base Data Sources Past Review Threshold
Details and remediationDetails
1 data source(s) not synced in >7 days (a configurable review threshold, NOT an AWS-mandated limit): - KB 'knowledge-base-prowler-findings' source 'knowledge-base-quick-start-9lb68-data-source' last completed ingestion 478 days ago Confirm this age is acceptable for each data source's currency requirement — slow-changing reference data may legitimately sync infrequently. Resolution
1. Define the maximum acceptable data age per use case (e.g., intraday for market data, daily for product terms, weekly/monthly for regulatory guidance) and adjust the review threshold to match. 2. Configure automated sync (EventBridge Scheduler → StartIngestionJob) at that cadence — see FS-61. 3. Set CloudWatch alarms on sync job failures. |
Medium | Failed |
777788889999 |
Global |
FS-32 |
ADVISORY: Source Attribution — Manual Review Required
Details and remediationDetails
Source attribution in GenAI responses cannot be verified via AWS APIs. Manual review required to confirm responses include citations. Resolution
1. Use Bedrock RetrieveAndGenerate with citations enabled. 2. Include source document references in response post-processing. 3. Test citation accuracy in QA before production deployment. 4. Consider Bedrock Guardrails grounding checks to validate response accuracy. |
Informational | N/A |
777788889999 |
Global |
FS-33 |
KB Data Source Buckets Have Versioning
|
Medium | Passed |
777788889999 |
Global |
FS-34 |
Legacy Foundation Models Available in Region
Details and remediationDetails
Legacy/deprecated foundation models are available in this account/region: anthropic.claude-sonnet-4-20250514-v1:0, twelvelabs.marengo-embed-2-7-v1:0, anthropic.claude-opus-4-1-20250805-v1:0, amazon.nova-premier-v1:0:8k, amazon.nova-premier-v1:0:20k, amazon.nova-premier-v1:0:1000k, amazon.nova-premier-v1:0:mm, amazon.nova-premier-v1:0, amazon.nova-canvas-v1:0, amazon.nova-reel-v1:0. This API reports model *availability*, not actual usage — it cannot determine which models your applications invoke. Legacy models have older training-data cutoffs and may produce outdated information if used. Review whether any are in active use. Resolution
1. Identify which (if any) of these legacy models your applications invoke (e.g., via CloudTrail InvokeModel events or application config). 2. Migrate active usage to current model versions. 3. Document training-data cutoff dates for all models in use. 4. Add data-currency disclaimers to outputs from models with old cutoffs. |
Informational | N/A |
777788889999 |
Global |
FS-35 |
ADVISORY: Harmful-Content Test Coverage — Manual Review Required
Details and remediationDetails
Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation/FMEval jobs include harmful-content datasets (toxicity, hate speech, violence/self-harm). Whether any evaluation jobs exist at all is assessed by FS-15. Resolution
Run Bedrock Model Evaluation or FMEval with harmful content datasets: - Toxicity detection - Hate speech classification - Violence/self-harm content |
Informational | N/A |
777788889999 |
Global |
FS-36 |
COULD NOT ASSESS: Guardrail Content Filters Check
Details and remediationDetails
This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved. Resolution
1. Confirm the assessment role grants the actions this check requires (see the documented IAM permission set in the README). 2. Confirm the service/feature is supported in the assessed region. 3. Ensure botocore meets the version floor in requirements.txt. 4. Re-run the assessment; assess this control manually until it succeeds. |
Low | N/A |
777788889999 |
Global |
FS-37 |
ADVISORY: User Feedback Mechanism — Manual Review Required
Details and remediationDetails
User feedback mechanisms for harmful outputs cannot be verified via AWS APIs. Manual review required. Resolution
1. Implement thumbs-up/down or flag-for-review UI in GenAI applications. 2. Route flagged outputs to human reviewers via SQS/SNS. 3. Log feedback to DynamoDB/S3 for model improvement. 4. Define SLAs for reviewing flagged content. |
Informational | N/A |
777788889999 |
Global |
FS-38 |
COULD NOT ASSESS: Guardrail Word Filters Check
Details and remediationDetails
This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved. Resolution
1. Confirm the assessment role grants the actions this check requires (see the documented IAM permission set in the README). 2. Confirm the service/feature is supported in the assessed region. 3. Ensure botocore meets the version floor in requirements.txt. 4. Re-run the assessment; assess this control manually until it succeeds. |
Low | N/A |
777788889999 |
Global |
FS-39 |
No SageMaker Clarify Bias Monitoring
Details and remediationDetails
No SageMaker Clarify model bias monitoring schedules found. Models making financial decisions (credit, insurance) may exhibit discriminatory bias without detection. Resolution
1. Configure SageMaker Clarify bias detection for all models making credit, insurance, or employment decisions. 2. Define protected attributes (age, gender, race proxies). 3. Set bias metric thresholds and alert on violations. 4. Document bias testing results for regulatory examination. |
High | Failed |
777788889999 |
Global |
FS-40 |
ADVISORY: Bias Dataset Coverage — Manual Review Required
Details and remediationDetails
Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation jobs include bias/fairness datasets (demographic parity, equal-opportunity, counterfactual fairness) for any GenAI models used in financial decisions (ECOA/Fair Housing). Whether any evaluation jobs exist at all is assessed by FS-15. Resolution
Run Bedrock Model Evaluation with bias test datasets: - Demographic parity test cases - Equal opportunity scenarios - Counterfactual fairness tests |
Informational | N/A |
777788889999 |
Global |
FS-41 |
No SageMaker Clarify Explainability Monitoring
Details and remediationDetails
No SageMaker Clarify explainability monitoring found. Models making adverse financial decisions may not provide required explanations (ECOA adverse action notices). Resolution
1. Configure SageMaker Clarify explainability for credit/lending models. 2. Generate SHAP values for feature importance. 3. Map top features to human-readable adverse action reason codes. 4. Store explanations for regulatory examination. |
High | Failed |
777788889999 |
Global |
FS-42 |
No SageMaker Model Cards Found
Details and remediationDetails
No SageMaker Model Cards found. If GenAI workloads run on Bedrock rather than SageMaker, model documentation may legitimately live elsewhere; Model Cards are a SageMaker-specific artifact. Resolution
1. For SageMaker models, create a Model Card documenting intended use, out-of-scope uses, training data and bias evaluations. 2. For Bedrock-only estates, record the equivalent documentation in your model-governance system and reference the AWS AI Service Cards. |
Informational | N/A |
777788889999 |
Global |
FS-43 |
Bedrock Invocation Logging Not Enabled
Details and remediationDetails
Bedrock model invocation logging is not enabled, so no invocation logs are being delivered and there is no log content to mask. Prompt and completion content is therefore also unavailable for audit. Resolution
1. Enable Bedrock model invocation logging. 2. If delivering to CloudWatch Logs, attach a data protection policy masking PII to the destination log group. |
Informational | N/A |
777788889999 |
Global |
FS-44 |
Amazon Macie Not Enabled
Details and remediationDetails
Amazon Macie is not enabled in this region (status: NOT_ENABLED). S3 buckets containing training data and KB data sources are not being scanned for PII or other sensitive data. Resolution
1. Enable Amazon Macie in every region where AI/ML data is stored. 2. Enable automated sensitive data discovery. 3. Route Macie findings to Security Hub and SNS. 4. Remediate PII findings before using data for model training. |
High | Failed |
777788889999 |
Global |
FS-45 |
COULD NOT ASSESS: Guardrail PII Filters Check
Details and remediationDetails
This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved. Resolution
1. Confirm the assessment role grants the actions this check requires (see the documented IAM permission set in the README). 2. Confirm the service/feature is supported in the assessed region. 3. Ensure botocore meets the version floor in requirements.txt. 4. Re-run the assessment; assess this control manually until it succeeds. |
Low | N/A |
777788889999 |
Global |
FS-46 |
AI/ML Buckets Without Data Classification Tags
Details and remediationDetails
3 AI/ML bucket(s) without data-classification tags: aiml-sec-test-resources-bedrockloggingbucket-wtuvpinrlpmd, aiml-sec-test-resources-sagemakerbucket-6zzmxxaxco6g, aiml-security-mgmt-aimlassessmentbucket-kbitsdgexylv. Resolution
Tag all AI/ML data buckets with 'data-classification' key. Values: Public, Internal, Confidential, Restricted. Enforce via SCP or AWS Config rule. |
Medium | Failed |
777788889999 |
Global |
FS-47 |
COULD NOT ASSESS: Guardrail Grounding Threshold Check
Details and remediationDetails
This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved. Resolution
1. Confirm the assessment role grants the actions this check requires (see the documented IAM permission set in the README). 2. Confirm the service/feature is supported in the assessed region. 3. Ensure botocore meets the version floor in requirements.txt. 4. Re-run the assessment; assess this control manually until it succeeds. |
Low | N/A |
777788889999 |
Global |
FS-48 |
Active Knowledge Bases for RAG Present
|
Medium | Passed |
777788889999 |
Global |
FS-49 |
ADVISORY: Hallucination Disclaimer — Manual Review Required
Details and remediationDetails
Application-level hallucination disclaimers cannot be verified via AWS APIs. Manual review required. Resolution
1. Add disclaimers to GenAI outputs: 'AI-generated content may contain errors. Verify with authoritative sources before acting.' 2. Implement post-processing to append disclaimers. 3. Test disclaimer presence in QA before production. |
Informational | N/A |
777788889999 |
Global |
FS-50 |
COULD NOT ASSESS: Guardrail Relevance Grounding Check
Details and remediationDetails
This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved. Resolution
1. Confirm the assessment role grants the actions this check requires (see the documented IAM permission set in the README). 2. Confirm the service/feature is supported in the assessed region. 3. Ensure botocore meets the version floor in requirements.txt. 4. Re-run the assessment; assess this control manually until it succeeds. |
Low | N/A |
777788889999 |
Global |
FS-51 |
COULD NOT ASSESS: Prompt Injection Input Validation Check
Details and remediationDetails
This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved. Resolution
1. Confirm the assessment role grants the actions this check requires (see the documented IAM permission set in the README). 2. Confirm the service/feature is supported in the assessed region. 3. Ensure botocore meets the version floor in requirements.txt. 4. Re-run the assessment; assess this control manually until it succeeds. |
Low | N/A |
777788889999 |
Global |
FS-52 |
Bedrock Lambda Functions on Current Runtimes
|
Medium | Passed |
777788889999 |
Global |
FS-53 |
No WAF Web ACLs — Injection Rules Not Applicable
|
Informational | N/A |
777788889999 |
Global |
FS-54 |
ADVISORY: Penetration Testing — Manual Review Required
Details and remediationDetails
Penetration testing evidence cannot be verified via AWS APIs. Manual review required to confirm GenAI applications have been tested. Resolution
1. Conduct penetration testing of GenAI applications at least annually and before major releases. 2. Include AI-specific test cases: prompt injection, jailbreak, indirect (cross-domain) injection, system-prompt leakage, and data-extraction attempts. 3. Consider AWS Security Agent for on-demand, AI-driven penetration testing (GA March 2026; available in US East N. Virginia, US West Oregon, Europe Ireland, Europe Frankfurt, Asia Pacific Sydney, Asia Pacific Tokyo, with cross-account shared-VPC testing via AWS RAM). Open-source tools such as Garak or PyRIT and manual red-teaming are complementary options. Verify current regional availability on the AWS Security Agent page before relying on it. 4. Document findings and remediation for regulatory examination, and tag tested resources with a last-pentest-date for audit trail. 5. For DORA compliance, include GenAI in TLPT (Threat-Led Penetration Testing) scope. |
Informational | N/A |
777788889999 |
Global |
FS-55 |
No Output Validation Functions Found
Details and remediationDetails
No Lambda functions with output validation/sanitization naming found. GenAI outputs may be passed directly to downstream systems without validation. Resolution
1. Implement output validation Lambda functions in GenAI pipelines. 2. Validate output schema, length, and content before downstream use. 3. Sanitize outputs before rendering in web UIs (XSS prevention). 4. Encode outputs appropriately for the target context (HTML, SQL, JSON). |
Medium | Failed |
777788889999 |
Global |
FS-56 |
No WAF ACLs — XSS Prevention Not Applicable
|
Informational | N/A |
777788889999 |
Global |
FS-57 |
ADVISORY: Output Encoding — Manual Review Required
Details and remediationDetails
Output encoding practices cannot be verified via AWS APIs. Manual code review required. Resolution
1. HTML-encode GenAI outputs before rendering in web UIs. 2. Use parameterized queries when GenAI output is used in database operations. 3. JSON-encode outputs before embedding in JavaScript contexts. 4. Validate output length and format before passing to downstream APIs. |
Informational | N/A |
777788889999 |
Global |
FS-58 |
ADVISORY: Output Schema Validation — Manual Review Required
Details and remediationDetails
Found 0 Lambda function(s) whose names suggest schema/validation handling. Structured-output / JSON-schema validation of GenAI responses is an application-layer control that cannot be verified automatically — manual review required. Resolution
1. Use Bedrock structured output (response schemas) where supported. 2. Implement JSON schema validation on Lambda output processors. 3. Reject malformed outputs and return safe error responses. 4. Log schema validation failures to CloudWatch for monitoring. |
Informational | N/A |
777788889999 |
Global |
FS-59 |
COULD NOT ASSESS: Guardrail Topic Allowlist Check
Details and remediationDetails
This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved. Resolution
1. Confirm the assessment role grants the actions this check requires (see the documented IAM permission set in the README). 2. Confirm the service/feature is supported in the assessed region. 3. Ensure botocore meets the version floor in requirements.txt. 4. Re-run the assessment; assess this control manually until it succeeds. |
Low | N/A |
777788889999 |
Global |
FS-60 |
ADVISORY: Contextual Grounding for Off-Topic Prevention
Details and remediationDetails
Contextual grounding for off-topic prevention is covered by guardrail grounding checks (FS-47) and RAG configuration (FS-48). Additionally verify system prompts explicitly scope the assistant's role. Resolution
1. Include explicit scope instructions in system prompts. 2. Use Bedrock Guardrails relevance grounding filter. 3. Test with off-topic prompts in QA to verify rejection behavior. |
Informational | N/A |
777788889999 |
Global |
FS-61 |
No Automated KB Sync Schedules Detected
Details and remediationDetails
Found 1 Knowledge Base(s) but no EventBridge Scheduler schedules or EventBridge rules with 'bedrock'/'knowledge' naming were found. Note: this check uses a name/target heuristic — sync automation with other naming conventions, AWS Step Functions-based orchestration, or native Bedrock API-triggered syncs (StartIngestionJob called directly) will not be detected. Verify sync automation manually if applicable. Resolution
1. Use EventBridge Scheduler (the AWS-recommended approach) to create a recurring schedule (e.g., rate(1 day) or a cron expression) that triggers a Lambda function calling the Bedrock StartIngestionJob API for each data source. Classic EventBridge scheduled rules also work but are a legacy feature. 2. As of December 2024, Bedrock Knowledge Bases supports custom connectors and streaming data ingestion — use direct document ingestion (KnowledgeBaseDocuments API) for real-time updates without a full S3 sync. 3. Set sync frequency based on data currency requirements (e.g., hourly for market data, daily for regulatory guidance). 4. Configure CloudWatch alarms or SNS notifications on IngestionJob FAILED status for sync failure alerting. |
Medium | Failed |
777788889999 |
Global |
FS-62 |
ADVISORY: Data Currency Disclaimer — Manual Review Required
Details and remediationDetails
Data currency disclaimers cannot be verified via AWS APIs. Manual review required. Resolution
1. Add data currency disclaimers to GenAI outputs: 'Information based on data current as of [KB last sync date].' 2. Expose KB last sync timestamp in application responses. 3. Alert users when KB data is older than defined threshold. |
Informational | N/A |
777788889999 |
Global |
FS-63 |
Foundation Model Lifecycle Governance Detected
Details and remediationDetails
10 AWS Config rule(s) with lifecycle- or model-related names were found, indicating some account-side model lifecycle governance: securityhub-ecr-private-lifecycle-policy-configured-4aa530ee, securityhub-s3-lifecycle-policy-check-703561e8, securityhub-s3express-dir-bucket-lifecycle-rules-check-dcc1ba9a, securityhub-sagemaker-model-bias-job-encrypt-in-transit-da9310a7, securityhub-sagemaker-model-bias-job-isolation-1e4b37af. Rule names are a heuristic; whether these rules enforce model currency is not assessed. For context, 17 of 122 model(s) offered in this region are marked LEGACY (for example ai21.jamba-1-5-large-v1:0, ai21.jamba-1-5-mini-v1:0, amazon.nova-canvas-v1:0, amazon.nova-premier-v1:0, amazon.nova-premier-v1:0:1000k); this reflects the regional catalogue, not this account's usage. Resolution
Confirm the matched rules genuinely track model currency, and that deprecation notifications are monitored. |
Medium | Passed |
777788889999 |
Global |
FS-65 |
KB Data Source Buckets Missing S3 Event Notifications
Details and remediationDetails
The following KB data-source S3 buckets have no event notifications configured. Unauthorized document modifications will not be detected in real time: - sat2-prowler-2025-prowlerfindingsbucket-wc1k0mza7lpk Resolution
1. Enable Amazon EventBridge notifications on each KB data-source S3 bucket. 2. Create an EventBridge rule to route s3:ObjectCreated, s3:ObjectRemoved, and s3:ObjectModified events to an SNS topic or Lambda for alerting. 3. Integrate alerts into your security incident response workflow. |
Medium | Failed |
777788889999 |
Global |
FS-66 |
No AgentCore Runtimes Found
|
Informational | N/A |
777788889999 |
Global |
FS-67 |
No Agent Action-Group Lambda Functions Found
Details and remediationDetails
No Lambda functions matching agent action-group naming patterns found. If agents perform financial transactions, verify transaction-value limits are enforced in the action-group implementation. Resolution
1. Implement transaction-value threshold checks in all agent action-group Lambda functions that initiate financial operations. 2. Use AgentCore Policy Engine to enforce maximum transaction amounts as a policy constraint on tool calls. 3. Reject or escalate to human review any transaction exceeding defined limits. |
Informational | N/A |
777788889999 |
Global |
FS-68 |
API Gateway Request Body Size Limits — Not Applicable
Details and remediationDetails
No API Gateway REST APIs and no regional WAF Web ACLs were found in this region. There is no input-payload surface to assess for body-size limits. Resolution
If GenAI endpoints are fronted by API Gateway or WAF in another region, run the assessment there. Otherwise no action is required. |
Informational | N/A |
777788889999 |
Global |
FS-69 |
Prompt Input Validation Functions Present
Details and remediation |
Medium | Passed |
777788889999 |
us-west-2 |
FS-00 |
Responsible AI GRC — Regional Scope Not Applicable
|
Informational | N/A |
777788889999 |
us-east-2 |
FS-00 |
Responsible AI GRC — Regional Scope Not Applicable
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-02 |
Amazon Bedrock private connectivity check
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-04 |
Bedrock Model Invocation Logging Check
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-05 |
Bedrock Guardrails Check
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-06 |
Bedrock CloudTrail Logging Check
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-07 |
Bedrock Prompt Management Check
Details and remediationDetails
Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates |
Informational | N/A |
777788889999 |
us-east-2 |
BR-08 |
Bedrock Agent IAM Roles Check
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-09 |
Bedrock Knowledge Base Encryption Check
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-10 |
Bedrock Guardrail IAM Enforcement Check
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-11 |
Bedrock Custom Model Encryption Check
|
Low | N/A |
777788889999 |
us-east-2 |
BR-12 |
Bedrock Invocation Log Encryption Check
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-13 |
Bedrock Flows Guardrails Check
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-16 |
Guardrail Tier Validation Check
|
Medium | N/A |
777788889999 |
us-east-2 |
BR-17 |
Custom Model Customer-Managed KMS Encryption Check
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-18 |
Model Evaluation Implementation Check
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-19 |
Prompt Flow Validation Check
|
Medium | N/A |
777788889999 |
us-east-2 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Check
|
High | N/A |
777788889999 |
us-east-2 |
BR-21 |
Agent Action Group IAM Least Privilege Check
|
High | N/A |
777788889999 |
us-east-2 |
BR-22 |
Model Invocation Throttling Limits Check
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-23 |
Guardrail Content Filter Coverage Check
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-24 |
Automated Reasoning Policy Implementation Check
|
Medium | N/A |
777788889999 |
us-east-2 |
BR-25 |
RAG Evaluation Jobs Check
|
Low | N/A |
777788889999 |
us-east-2 |
BR-26 |
Guardrail Sensitive Information Filter Check
|
High | N/A |
777788889999 |
us-east-2 |
BR-27 |
Guardrail Contextual Grounding Check
|
Medium | N/A |
777788889999 |
us-east-2 |
BR-28 |
Agent Guardrail Association Check
|
High | N/A |
777788889999 |
us-east-2 |
BR-29 |
Agent Idle Session TTL Check
|
Low | N/A |
777788889999 |
us-east-2 |
BR-30 |
Imported Model Customer-Managed KMS Encryption Check
|
High | N/A |
777788889999 |
us-east-2 |
BR-31 |
Batch Inference Output Encryption Check
|
Medium | N/A |
777788889999 |
us-east-2 |
BR-32 |
Bedrock CloudWatch Alarm Check
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-33 |
Amazon Inspector Lambda Code Scanning Check
Details and remediationDetails
No Lambda functions with Bedrock indicators were found in us-east-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
No action required. If Bedrock-calling Lambda functions exist, ensure their function name, ARN, description, handler, role, or environment variables contain a Bedrock identifier that the assessment can detect, or evaluate Inspector coverage manually. |
Informational | N/A |
777788889999 |
us-east-2 |
BR-34 |
Guardrail Prompt Attack Filter
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-35 |
Guardrail Image Content Filter Coverage
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-36 |
Application Inference Profile Governance
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-37 |
Bedrock Account Data Retention
|
High | Failed |
777788889999 |
us-east-2 |
BR-38 |
Automated Reasoning Policy CMK Encryption
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-39 |
Marketplace Model Endpoint VPC Configuration
|
Informational | N/A |
777788889999 |
us-east-2 |
BR-40 |
Marketplace Model Endpoint CMK Encryption
|
Informational | N/A |
777788889999 |
us-east-2 |
AG-07 |
Agentic AI Model Invocation Logging
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-08 |
Agentic AI API Audit Trail
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage Resolution
Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-10 |
Agentic AI Adversarial Evaluation Coverage
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs Resolution
Configure model or application evaluations that include adversarial, safety, and security-relevant test cases. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-11 |
Agentic AI Prompt Flow Validation
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region Resolution
Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-06 |
Agentic AI Tool Execution Least Privilege
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region Resolution
Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-12 |
Agentic AI Invocation Abuse Controls
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas Resolution
Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-02 |
Agentic AI Harmful Content Guardrail Coverage
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-04 |
Agentic AI Automated Reasoning Guardrails
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: No Bedrock guardrails configured in this region Resolution
Configure automated reasoning policies on guardrails where formal response validation is required. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-03 |
Agentic AI Sensitive Information Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: No Bedrock guardrails configured in this region Resolution
Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-05 |
Agentic AI Grounding Controls
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: No Bedrock guardrails configured in this region Resolution
Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-01 |
Agentic AI Agent Guardrail Association
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region Resolution
Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-13 |
Agentic AI Session Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region Resolution
Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-14 |
Agentic AI Operational Abuse Alarms
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms Resolution
Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available. |
Informational | N/A |
777788889999 |
us-east-2 |
AG-30 |
Agentic AI Prompt Attack Protection
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agents should prevent prompt attacks before untrusted input can redirect planning or tool use. Source check BR-34: No Bedrock guardrails configured in this region Resolution
Enable a preventive PROMPT_ATTACK input filter on each guardrail and use Standard tier where prompt-leakage protection is required. |
Informational | N/A |
777788889999 |
Global |
BR-01 |
AmazonBedrockFullAccess role check
|
High | Failed |
777788889999 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
Role 'aiml-sec-test-resources-BedrockFullAccessRole-zAFkGLkWQ61a' has overly permissive marketplace subscription access through policy 'AmazonBedrockFullAccess' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | Failed |
777788889999 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
Role 'aiml-sec-test-resources-MarketplaceOverlyPermissive-igL3hGIapee1' has overly permissive marketplace subscription access through policy 'OverlyPermissiveMarketplace' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | Failed |
777788889999 |
us-east-1 |
BR-02 |
Amazon Bedrock private connectivity
|
High | Passed |
777788889999 |
us-east-1 |
BR-04 |
Bedrock Model Invocation Logging Check
Details and remediationDetails
Model invocation logging is not enabled. This limits your ability to track and audit model usage. Resolution
Enable model invocation logging to collect invocation logs, model input data, and model output data. Configure logging to deliver to Amazon S3, CloudWatch Logs, or both for comprehensive monitoring. |
Medium | Failed |
777788889999 |
us-east-1 |
BR-05 |
Bedrock Guardrails Check
|
High | Passed |
777788889999 |
us-east-1 |
BR-06 |
Bedrock CloudTrail Logging Check
|
Medium | Passed |
777788889999 |
us-east-1 |
BR-07 |
Bedrock Prompt Management Check
|
Low | Passed |
777788889999 |
us-east-1 |
BR-08 |
Bedrock Agent IAM Roles Check
|
Informational | N/A |
777788889999 |
us-east-1 |
BR-09 |
Bedrock Knowledge Base Encryption Review
Details and remediationDetails
Knowledge Base 'knowledge-base-prowler-findings' (9K2QZLVCZW) uses 'OPENSEARCH_SERVERLESS' storage. Encryption is managed at the storage layer and cannot be validated from the KB API. Verify encryption configuration on the underlying storage resource. Resolution
1. For OpenSearch Serverless: Verify encryption with CMK at collection level 2. For S3 data sources: Verify CMK-encrypted S3 buckets 3. For RDS: Verify KMS encryption on the database 4. Consider using CMK for transient data during ingestion |
Informational | N/A |
777788889999 |
us-east-1 |
BR-10 |
Bedrock Guardrail IAM Enforcement Missing
Details and remediationDetails
The following roles can invoke Bedrock models without enforced guardrails: aiml-sec-test-resources-BedrockAgentRoleWithoutGuar-Z3kN5ANhP89G, aiml-sec-test-resources-BedrockFullAccessRole-zAFkGLkWQ61a, aiml-sec-test-resources-BedrockKnowledgeBaseRole-6NNC1i9FuTbM, AmazonBedrockExecutionRoleForKnowledgeBase_7erx6 Resolution
Add IAM policy conditions to enforce guardrail usage: 1. Use 'bedrock:GuardrailIdentifier' condition key 2. Specify required guardrail ARN or ID 3. Example: "Condition": {"StringEquals": {"bedrock:GuardrailIdentifier": "arn:aws:bedrock:region:account:guardrail/guardrail-id"}} |
High | Failed |
777788889999 |
us-east-1 |
BR-11 |
Bedrock Custom Model Encryption Check
|
Informational | N/A |
777788889999 |
us-east-1 |
BR-12 |
Bedrock Invocation Log Encryption Check
|
Informational | N/A |
777788889999 |
us-east-1 |
BR-13 |
Bedrock Flows Guardrails Check
|
Informational | N/A |
777788889999 |
Global |
BR-15 |
Cross-Account Guardrails Enforcement Check
Details and remediationDetails
No account-level enforced guardrail configuration was observed, and organization policy inheritance cannot be fully established from this member account. Resolution
Run the assessment from the management or delegated administrator account, or configure account-level enforced guardrails. |
Informational | N/A |
777788889999 |
us-east-1 |
BR-16 |
Guardrail Tier Validation Check
|
Informational | N/A |
777788889999 |
us-east-1 |
BR-17 |
Custom Model Customer-Managed KMS Encryption Check
|
High | N/A |
777788889999 |
us-east-1 |
BR-18 |
Model Evaluation Implementation Check
Details and remediationDetails
No Bedrock model evaluation jobs found. Model evaluation helps assess toxicity, accuracy, semantic robustness, and other safety metrics before production deployment. Resolution
Create model evaluation jobs using Amazon Bedrock Evaluations to assess foundation model performance against safety and quality metrics. Use built-in datasets or custom test sets. Enable LLM-as-a-judge evaluation for comprehensive assessment. |
Medium | Failed |
777788889999 |
us-east-1 |
BR-19 |
Prompt Flow Validation Check
|
Medium | N/A |
777788889999 |
us-east-1 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Review
Details and remediationDetails
Knowledge base 'knowledge-base-prowler-findings' (ID: 9K2QZLVCZW) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store. Resolution
1. For OpenSearch Serverless: verify the collection uses a customer-managed KMS key 2. For Amazon RDS/Aurora: verify KMS encryption on the database 3. For third-party stores (Pinecone, Redis, MongoDB): verify the provider's encryption configuration 4. Verify the customer-managed KMS key used for transient data during ingestion |
Informational | N/A |
777788889999 |
us-east-1 |
BR-22 |
Model Invocation Throttling Limits Check
|
Low | Passed |
777788889999 |
us-east-1 |
BR-23 |
Guardrail Content Filter Coverage Check
|
Informational | N/A |
777788889999 |
us-east-1 |
BR-25 |
RAG Evaluation Jobs Check
Details and remediationDetails
Knowledge base 'knowledge-base-prowler-findings' (ID: 9K2QZLVCZW) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations. Resolution
Create RAG evaluation jobs for knowledge bases using Amazon Bedrock Model Evaluation. Configure evaluations to test context relevance, answer correctness, and faithfulness metrics. Run evaluations regularly (monthly or after significant KB updates) to maintain quality. |
Low | Failed |
777788889999 |
us-east-1 |
BR-26 |
Guardrail Sensitive Information Filter Check
|
Informational | N/A |
777788889999 |
us-east-1 |
BR-27 |
Guardrail Contextual Grounding Check
|
Informational | N/A |
777788889999 |
us-east-1 |
BR-28 |
Agent Guardrail Association Check
|
Low | Passed |
777788889999 |
us-east-1 |
BR-30 |
Imported Model Customer-Managed KMS Encryption Check
|
High | N/A |
777788889999 |
us-east-1 |
BR-31 |
Batch Inference Output Encryption Check
|
Medium | N/A |
777788889999 |
us-east-1 |
BR-32 |
Bedrock CloudWatch Alarm Check
Details and remediationDetails
No CloudWatch alarms are configured on Amazon Bedrock runtime metrics (AWS/Bedrock namespace). Without alarms, abuse, denial-of-wallet, sustained throttling, and content-filter spikes can go undetected. Resolution
Create CloudWatch alarms on AWS/Bedrock runtime metrics such as Invocations, InvocationThrottles, InputTokenCount, OutputTokenCount, and ContentFilteredCount, and route them to an Amazon SNS topic for notification. |
Medium | Failed |
777788889999 |
us-east-1 |
BR-33 |
Amazon Inspector Lambda Code Scanning Check
|
Medium | Passed |
777788889999 |
us-east-1 |
BR-34 |
Guardrail Prompt Attack Filter
|
Informational | N/A |
777788889999 |
us-east-1 |
BR-35 |
Guardrail Image Content Filter Coverage
|
Informational | N/A |
777788889999 |
us-east-1 |
BR-36 |
Application Inference Profile Governance
|
Informational | N/A |
777788889999 |
us-east-1 |
BR-37 |
Bedrock Account Data Retention
|
High | Failed |
777788889999 |
us-east-1 |
BR-38 |
Automated Reasoning Policy CMK Encryption
|
Informational | N/A |
777788889999 |
us-east-1 |
BR-39 |
Marketplace Model Endpoint VPC Configuration
|
Informational | N/A |
777788889999 |
us-east-1 |
BR-40 |
Marketplace Model Endpoint CMK Encryption
|
Informational | N/A |
777788889999 |
us-east-1 |
AG-07 |
Agentic AI Model Invocation Logging
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: Model invocation logging is not enabled. This limits your ability to track and audit model usage. Resolution
Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements. |
Medium | Failed |
777788889999 |
us-east-1 |
AG-08 |
Agentic AI API Audit Trail
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: CloudTrail is properly configured to log Bedrock API activity in trails: GuardTrail-DO-NOT-DELETE Resolution
Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured. |
Medium | Passed |
777788889999 |
Global |
AG-09 |
Agentic AI Guardrail Enforcement Boundary
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Organization-level guardrail enforcement helps prevent agents from bypassing required safety controls across accounts. Source check BR-15: No account-level enforced guardrail configuration was observed, and organization policy inheritance cannot be fully established from this member account. Resolution
Use IAM and organization controls to require approved guardrails for model and agent invocations where supported. |
Informational | N/A |
777788889999 |
us-east-1 |
AG-10 |
Agentic AI Adversarial Evaluation Coverage
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No Bedrock model evaluation jobs found. Model evaluation helps assess toxicity, accuracy, semantic robustness, and other safety metrics before production deployment. Resolution
Configure model or application evaluations that include adversarial, safety, and security-relevant test cases. |
Medium | Failed |
777788889999 |
us-east-1 |
AG-11 |
Agentic AI Prompt Flow Validation
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region Resolution
Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions. |
Informational | N/A |
777788889999 |
us-east-1 |
AG-12 |
Agentic AI Invocation Abuse Controls
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: 10 custom throttling quotas are configured. Regular quota review helps maintain appropriate rate limits. Resolution
Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns. |
Low | Passed |
777788889999 |
us-east-1 |
AG-02 |
Agentic AI Harmful Content Guardrail Coverage
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: Guardrail 'aiml-sec-test-test-guardrail' could not be assessed: AccessDeniedException. Resolution
Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads. |
Informational | N/A |
777788889999 |
us-east-1 |
AG-03 |
Agentic AI Sensitive Information Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: Guardrail 'aiml-sec-test-test-guardrail' (ID: jkceg2tprvwh) could not be assessed because GetGuardrail returned AccessDeniedException. Resolution
Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns. |
Informational | N/A |
777788889999 |
us-east-1 |
AG-05 |
Agentic AI Grounding Controls
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: Guardrail 'aiml-sec-test-test-guardrail' (ID: jkceg2tprvwh) could not be assessed because GetGuardrail returned AccessDeniedException. Resolution
Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows. |
Informational | N/A |
777788889999 |
us-east-1 |
AG-01 |
Agentic AI Agent Guardrail Association
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: 1 agents have an associated guardrail Resolution
Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating. |
Low | Passed |
777788889999 |
us-east-1 |
AG-14 |
Agentic AI Operational Abuse Alarms
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No CloudWatch alarms are configured on Amazon Bedrock runtime metrics (AWS/Bedrock namespace). Without alarms, abuse, denial-of-wallet, sustained throttling, and content-filter spikes can go undetected. Resolution
Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available. |
Medium | Failed |
777788889999 |
us-east-1 |
AG-30 |
Agentic AI Prompt Attack Protection
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agents should prevent prompt attacks before untrusted input can redirect planning or tool use. Source check BR-34: Guardrail 'aiml-sec-test-test-guardrail' could not be assessed: AccessDeniedException. Resolution
Enable a preventive PROMPT_ATTACK input filter on each guardrail and use Standard tier where prompt-leakage protection is required. |
Informational | N/A |
777788889999 |
us-west-2 |
AC-01 |
AgentCore VPC Configuration Check
|
Informational | N/A |
777788889999 |
us-west-2 |
AC-04 |
AgentCore Observability Check
|
Informational | N/A |
777788889999 |
us-west-2 |
AC-05 |
AgentCore Encryption Check
|
Informational | N/A |
777788889999 |
us-west-2 |
AC-06 |
AgentCore Browser Session Recording
|
Informational | N/A |
777788889999 |
us-west-2 |
AC-07 |
AgentCore Memory Configuration Check
|
Informational | N/A |
777788889999 |
us-west-2 |
AC-13 |
AgentCore Gateway Configuration Check
|
Informational | N/A |
777788889999 |
us-west-2 |
AC-08 |
AgentCore VPC Endpoints Check
|
Informational | N/A |
777788889999 |
us-west-2 |
AC-10 |
AgentCore Resource-Based Policies Check
|
Informational | N/A |
777788889999 |
us-west-2 |
AC-11 |
AgentCore Policy Engine Encryption Check
|
Informational | N/A |
777788889999 |
us-west-2 |
AC-12 |
AgentCore Gateway Encryption Check
|
Informational | N/A |
777788889999 |
us-west-2 |
AC-14 |
AgentCore Identity Token Vault CMK Encryption
|
Informational | N/A |
777788889999 |
us-west-2 |
AC-15 |
AgentCore Code Interpreter Network Isolation
|
Informational | N/A |
777788889999 |
us-west-2 |
AC-16 |
AgentCore Custom Browser Network Isolation
|
Informational | N/A |
777788889999 |
us-west-2 |
AC-17 |
AgentCore Online Evaluation Coverage
|
Medium | Failed |
777788889999 |
us-west-2 |
AG-24 |
Agentic AI Gateway Inbound Authorization
|
Informational | N/A |
777788889999 |
us-west-2 |
AG-25 |
Agentic AI Gateway Tool Policy Enforcement
|
Informational | N/A |
777788889999 |
us-west-2 |
AG-26 |
Agentic AI Gateway Error Detail Exposure
|
Informational | N/A |
777788889999 |
us-west-2 |
AG-27 |
Agentic AI Gateway WAF Protection
|
Informational | N/A |
777788889999 |
us-west-2 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-19 |
Agentic AI Memory Data Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found Resolution
Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-20 |
Agentic AI Private AgentCore Connectivity
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found Resolution
Create required VPC endpoints for AgentCore services and validate endpoint availability. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-21 |
Agentic AI Resource Policy Boundary
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies Resolution
Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-22 |
Agentic AI Policy Engine Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found Resolution
Configure policy engines with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-23 |
Agentic AI Gateway Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found Resolution
Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-28 |
Agentic AI Identity Token Vault Protection
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Agent credentials stored in the Identity token vault should use customer-controlled encryption where enhanced key control is required. Source check AC-14: No assessable AgentCore Identity token vault was found. Resolution
Configure the AgentCore Identity token vault with a customer-managed KMS key. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-29 |
Agentic AI Code Interpreter Isolation
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent-executed code should run inside an explicit VPC boundary with controlled network paths. Source check AC-15: No custom AgentCore Code Interpreters found Resolution
Configure custom AgentCore Code Interpreters in VPC mode with approved subnets and security groups. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-31 |
Agentic AI Browser Tool Isolation
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Browser tools can reach external systems and should use explicit private network boundaries. Source check AC-16: No custom AgentCore browsers found Resolution
Configure custom AgentCore browsers in VPC mode with approved subnets and security groups. |
Informational | N/A |
777788889999 |
us-west-2 |
AG-32 |
Agentic AI Online Evaluation Assurance
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Online evaluation provides continuous evidence about agent behavior, quality, and policy-relevant outcomes. Source check AC-17: No AgentCore online evaluation configurations found. Resolution
Configure an active AgentCore online evaluation with sampling, evaluators, CloudWatch input logs, and an output log group. |
Medium | Failed |
777788889999 |
Global |
SM-02 |
SageMaker Full Access Policy Used
|
High | Failed |
777788889999 |
us-east-1 |
SM-01 |
Direct Internet Access Enabled
|
High | Failed |
777788889999 |
us-east-1 |
SM-01 |
Non-VPC Only Network Access
|
High | Failed |
777788889999 |
us-east-1 |
SM-01 |
Non-VPC Only Network Access
|
High | Failed |
777788889999 |
us-east-1 |
SM-02 |
SSO Not Properly Configured
Details and remediation |
Medium | Failed |
777788889999 |
us-east-1 |
SM-02 |
SSO Not Properly Configured
Details and remediation |
Medium | Failed |
777788889999 |
us-east-1 |
SM-02 |
SSO Not Properly Configured
Details and remediation |
Medium | Failed |
777788889999 |
us-east-1 |
SM-02 |
SSO Not Properly Configured
Details and remediation |
Medium | Failed |
777788889999 |
us-east-1 |
SM-03 |
Missing Encryption Configuration
|
High | Failed |
777788889999 |
us-east-1 |
SM-03 |
Missing Encryption Configuration
|
High | Failed |
777788889999 |
us-east-1 |
SM-03 |
Missing Encryption Configuration
|
High | Failed |
777788889999 |
us-east-1 |
SM-03 |
Missing Encryption Configuration
|
High | Failed |
777788889999 |
us-east-1 |
SM-03 |
Missing VPC Encryption
|
Medium | Failed |
777788889999 |
us-east-1 |
SM-04 |
GuardDuty Enabled
|
Medium | Passed |
777788889999 |
us-east-1 |
SM-26 |
GuardDuty AI Protection
|
High | Failed |
777788889999 |
us-east-1 |
SM-05 |
SageMaker Model Registry Issue
|
Low | Failed |
777788889999 |
us-east-1 |
SM-05 |
SageMaker Pipelines Issue
|
Informational | N/A |
777788889999 |
us-east-1 |
SM-06 |
SageMaker Clarify No Clarify Usage
|
Informational | N/A |
777788889999 |
us-east-1 |
SM-07 |
SageMaker Model Monitor No Model Monitoring
|
Informational | N/A |
777788889999 |
us-east-1 |
SM-08 |
Model Registry Empty Model Group
|
Low | Failed |
777788889999 |
us-east-1 |
SM-09 |
SageMaker Notebook Root Access Enabled
Details and remediationDetails
Notebook instance 'aiml-sec-test-notebook-with-internet' has root access enabled. Root access allows users to install arbitrary software, modify system configurations, and potentially escalate privileges. Resolution
Disable root access by updating the notebook instance with RootAccess=Disabled. Note: Lifecycle configurations will still run with root access. |
High | Failed |
777788889999 |
us-east-1 |
SM-10 |
SageMaker Notebook Not in VPC
Details and remediationDetails
Notebook instance 'aiml-sec-test-notebook-with-internet' is not deployed in a custom VPC. This uses SageMaker's service VPC with reduced network isolation. Resolution
Create the notebook instance within a custom VPC by specifying SubnetId and SecurityGroupIds. This provides network isolation and allows use of VPC endpoints. |
High | Failed |
777788889999 |
us-east-1 |
SM-11 |
SageMaker Model Network Isolation Disabled
Details and remediationDetails
Model 'SageMakerModelNoIsolation-yQ7EpJeL7pgI' does not have network isolation enabled. Model containers can make outbound network calls, potentially exfiltrating data. Resolution
Enable network isolation by setting EnableNetworkIsolation=True when creating models. This prevents containers from making outbound network calls. |
High | Failed |
777788889999 |
us-east-1 |
SM-12 |
SageMaker Endpoint Instance Count Check
|
Informational | N/A |
777788889999 |
us-east-1 |
SM-13 |
SageMaker Monitoring Network Isolation Check
|
Informational | N/A |
777788889999 |
us-east-1 |
SM-14 |
SageMaker Model Platform Repository Access
Details and remediationDetails
Model 'SageMakerModelWithIsolation-JASFpUHjajdk' uses Platform repository access mode. Container images are pulled from public/external registries, exposing supply chain risks. Resolution
Configure RepositoryAccessMode=Vpc in ImageConfig to pull images from private ECR repositories through VPC. This provides supply chain security. |
Medium | Failed |
777788889999 |
us-east-1 |
SM-14 |
SageMaker Model Platform Repository Access
Details and remediationDetails
Model 'SageMakerModelNoIsolation-yQ7EpJeL7pgI' uses Platform repository access mode. Container images are pulled from public/external registries, exposing supply chain risks. Resolution
Configure RepositoryAccessMode=Vpc in ImageConfig to pull images from private ECR repositories through VPC. This provides supply chain security. |
Medium | Failed |
777788889999 |
us-east-1 |
SM-15 |
SageMaker Feature Store Offline Encryption Missing
Details and remediationDetails
Feature group 'aiml-sec-test-feature-group' offline store does not have KMS encryption configured. Feature data in S3 may not be encrypted with customer-managed keys. Resolution
Configure KmsKeyId in OfflineStoreConfig.S3StorageConfig when creating feature groups to encrypt offline store data with customer-managed KMS keys. |
Medium | Failed |
777788889999 |
us-east-1 |
SM-16 |
SageMaker Data Quality Job Encryption Check
|
Informational | N/A |
777788889999 |
us-east-1 |
SM-17 |
SageMaker Processing Job Encryption Check
|
Medium | Passed |
777788889999 |
us-east-1 |
SM-18 |
SageMaker Transform Job Encryption Check
|
Medium | Passed |
777788889999 |
us-east-1 |
SM-19 |
SageMaker Hyperparameter Tuning Job Encryption Check
|
Informational | N/A |
777788889999 |
us-east-1 |
SM-20 |
SageMaker Compilation Job Encryption Check
|
Informational | N/A |
777788889999 |
us-east-1 |
SM-21 |
SageMaker AutoML Job Network Isolation Check
|
Informational | N/A |
777788889999 |
us-east-1 |
SM-22 |
Model Approval Workflow Check
|
Medium | Passed |
777788889999 |
us-east-1 |
SM-23 |
Model Drift Detection Check
|
Medium | Passed |
777788889999 |
us-east-1 |
SM-24 |
A/B Testing and Shadow Deployment Check
|
Low | Passed |
777788889999 |
us-east-1 |
SM-25 |
ML Lineage Tracking - Experiments Not Used
|
Informational | N/A |
777788889999 |
us-east-1 |
SM-27 |
HyperPod EBS CMK Encryption
|
Informational | N/A |
777788889999 |
us-east-1 |
SM-28 |
HyperPod VPC Configuration
|
Informational | N/A |
777788889999 |
us-east-1 |
SM-30 |
Model Package Group Resource Policy Exposure
|
High | Passed |
777788889999 |
us-east-2 |
SM-01 |
SageMaker Internet Access Check
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-02 |
SageMaker SSO Configuration Check
|
Medium | Passed |
777788889999 |
us-east-2 |
SM-03 |
Data Protection Check
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-04 |
GuardDuty Enabled
|
Medium | Passed |
777788889999 |
us-east-2 |
SM-26 |
GuardDuty AI Protection
|
High | Failed |
777788889999 |
us-east-2 |
SM-05 |
SageMaker Model Registry Issue
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-05 |
SageMaker Feature Store Issue
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-05 |
SageMaker Pipelines Issue
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-06 |
SageMaker Clarify No Clarify Usage
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-07 |
SageMaker Model Monitor No Model Monitoring
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-08 |
Model Registry Registry Not Used
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-09 |
SageMaker Notebook Root Access Check
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-10 |
SageMaker Notebook VPC Deployment Check
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-11 |
SageMaker Model Network Isolation Check
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-12 |
SageMaker Endpoint Instance Count Check
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-13 |
SageMaker Monitoring Network Isolation Check
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-14 |
SageMaker Model Repository Access Check
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-15 |
SageMaker Feature Store Encryption Check
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-16 |
SageMaker Data Quality Job Encryption Check
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-17 |
SageMaker Processing Job Encryption Check
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-18 |
SageMaker Transform Job Encryption Check
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-19 |
SageMaker Hyperparameter Tuning Job Encryption Check
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-20 |
SageMaker Compilation Job Encryption Check
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-21 |
SageMaker AutoML Job Network Isolation Check
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-22 |
Model Approval Workflow Check
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-23 |
Model Drift Detection Check
|
Medium | Passed |
777788889999 |
us-east-2 |
SM-24 |
A/B Testing and Shadow Deployment Check
|
Low | Passed |
777788889999 |
us-east-2 |
SM-25 |
ML Lineage Tracking - Experiments Not Used
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-27 |
HyperPod EBS CMK Encryption
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-28 |
HyperPod VPC Configuration
|
Informational | N/A |
777788889999 |
us-east-2 |
SM-30 |
Model Package Group Resource Policy Exposure
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-01 |
SageMaker Internet Access Check
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-02 |
SageMaker SSO Configuration Check
|
Medium | Passed |
777788889999 |
us-west-2 |
SM-03 |
Data Protection Check
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-04 |
GuardDuty Enabled
|
Medium | Passed |
777788889999 |
us-west-2 |
SM-26 |
GuardDuty AI Protection
|
High | Failed |
777788889999 |
us-west-2 |
SM-05 |
SageMaker Model Registry Issue
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-05 |
SageMaker Feature Store Issue
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-05 |
SageMaker Pipelines Issue
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-06 |
SageMaker Clarify No Clarify Usage
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-07 |
SageMaker Model Monitor No Model Monitoring
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-08 |
Model Registry Registry Not Used
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-09 |
SageMaker Notebook Root Access Check
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-10 |
SageMaker Notebook VPC Deployment Check
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-11 |
SageMaker Model Network Isolation Check
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-12 |
SageMaker Endpoint Instance Count Check
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-13 |
SageMaker Monitoring Network Isolation Check
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-14 |
SageMaker Model Repository Access Check
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-15 |
SageMaker Feature Store Encryption Check
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-16 |
SageMaker Data Quality Job Encryption Check
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-17 |
SageMaker Processing Job Encryption Check
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-18 |
SageMaker Transform Job Encryption Check
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-19 |
SageMaker Hyperparameter Tuning Job Encryption Check
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-20 |
SageMaker Compilation Job Encryption Check
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-21 |
SageMaker AutoML Job Network Isolation Check
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-22 |
Model Approval Workflow Check
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-23 |
Model Drift Detection Check
|
Medium | Passed |
777788889999 |
us-west-2 |
SM-24 |
A/B Testing and Shadow Deployment Check
|
Low | Passed |
777788889999 |
us-west-2 |
SM-25 |
ML Lineage Tracking - Experiments Not Used
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-27 |
HyperPod EBS CMK Encryption
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-28 |
HyperPod VPC Configuration
|
Informational | N/A |
777788889999 |
us-west-2 |
SM-30 |
Model Package Group Resource Policy Exposure
|
Informational | N/A |
Scope: API-provable Agentic AI security controls mapped to the AWS Well-Architected Agentic AI Lens security guidance. Human-in-the-loop governance is referenced in methodology but not scored automatically unless an AWS API can prove the control.
Scope: Responsible AI GRC comprises 64 automated checks that evaluate selected AWS configuration evidence against project-authored technical controls informed by the AWS User Guide to Governance, Risk, and Compliance for Responsible AI Adoption and by AWS financial-services generative-AI risk guidance. The controls originated as financial-services controls and were found applicable across multiple industries. They do not establish regulatory compliance, certify a system as responsible AI, or provide complete Responsible AI or GRC coverage. Regulatory framework mappings are preliminary. Manual legal, policy, model-risk, fairness, and use-case review remains required. This assessment records findings against each resolved CloudFormation TargetRegions entry. These checks are based on the AWS User Guide to Governance, Risk, and Compliance for Responsible AI Adoption. Severities follow a documented Likelihood × Impact methodology. Responsible AI GRC is not the AWS Well-Architected Responsible AI Lens. The Lens (November 2025) is a separate architectural review framework with eight focus areas. These checks do not implement, validate, or measure conformance to it, and passing them does not indicate Lens alignment.
Scope: mapping-based derivation from existing BR/SM/AC/AG/FS checks plus two net-new checks for LLM07 (System Prompt Leakage). Each finding's OWASP category (LLM01–LLM10) is encoded in the Finding_Details text. Preliminary and illustrative — validate mappings with your Security/Compliance team before using as evidence.
Assessment Notes
Assessment Scope
Bedrock, SageMaker, AgentCore, and AWS Agent Registry checks are based on the AWS Well-Architected Framework Generative AI Lens. Agentic AI Security references the AWS Well-Architected Agentic AI Lens. Controls that cannot be proven using AWS APIs, including semantic human-in-the-loop workflow quality, are not automatically scored. Responsible AI GRC checks are based on the AWS User Guide to Governance, Risk, and Compliance for Responsible AI Adoption. Responsible AI GRC is not the AWS Well-Architected Responsible AI Lens. The Lens (November 2025) is a separate architectural review framework with eight focus areas. These checks do not implement, validate, or measure conformance to it, and passing them does not indicate Lens alignment. OWASP Top 10 LLM references OWASP Top 10 LLM.