Unique Check IDs
174
Distinct Check_ID values represented
Report Rows
2159
Visible rows across 3 accounts · 4 regions
Open Action Items
254
Direct failed service rows
Lens / Compliance Rows
1003
214 failed; may map to service rows
Failed High
106
32 of 205 direct high rows passed
Failed Medium / Low
127/21
Direct Medium / Low failed rows

Priority Recommendations

1
AgentCore IAM Full Access Policy
AgentCore
1
AgentCore IAM Wildcard Permissions
AgentCore
2
AgentCore Runtime VPC Configuration
AgentCore
1
AgentCore Stale Access
AgentCore

Severity Legend

View full methodology
SeverityMeaningRecommended Action
HighDirect security risk - IAM/access control gaps, missing audit trails, guardrail bypasses that could lead to unauthorized access or data exposureRemediate within 7 days
MediumDefense-in-depth gaps - encryption, logging, or configuration issues that reduce security postureRemediate within 30 days
LowBest practice deviations - optimization opportunities that improve security hygieneRemediate within 90 days
InformationalNot applicable, unavailable, no resources found, or advisory-only rowsNo action required
Risk Distribution

Direct Service Scored Row Results by Severity

HIGH
15.6%
32 of 205 scored rows passed
MEDIUM
29.6%
76 of 257 scored rows passed
LOW
26.3%
20 of 76 scored rows passed
Overall
23.8%
128 of 538 scored rows passed

Direct Failed Rows by Account

111122223333
190
77 High · 97 Med · 16 Low
444455556666
5
3 High · 2 Med · 0 Low
777788889999
59
26 High · 28 Med · 5 Low

Direct Failed Rows by Region / Scope

eu-west-1
0
0 High · 0 Med · 0 Low
us-east-1
126
42 High · 72 Med · 12 Low
us-east-2
40
17 High · 22 Med · 1 Low
us-west-2
54
18 High · 28 Med · 8 Low
Global
34
29 High · 5 Med · 0 Low

Findings by Assessment Area

Bedrock
389
51 Failed · 20 Passed
SageMaker
343
42 Failed · 50 Passed
AgentCore
152
39 Failed · 3 Passed
Agentic AI Security
316
47 Failed · 18 Passed · 251 N/A
Financial Services Risk
272
122 Failed · 55 Passed · 95 N/A
OWASP Top 10 LLM
687
167 Failed · 87 Passed · 433 N/A
All Security Findings
Account IDRegionCheck IDFindingSeverityStatus
111122223333 eu-west-1 AC-01
AgentCore VPC Configuration Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 AC-04
AgentCore Observability Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 AC-05
AgentCore Encryption Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 AC-06
AgentCore Browser Tool Recording Check
Details and remediation
Details

No AgentCore Runtimes found to check browser tool configuration

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 AC-07
AgentCore Memory Configuration Check
Details and remediation
Details

No Memory resources found

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 AC-13
AgentCore Gateway Configuration Check
Details and remediation
Details

No Gateway resources found

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 AC-08
AgentCore VPC Endpoints Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 AC-10
AgentCore Resource-Based Policies Check
Details and remediation
Details

No AgentCore resources found to check for resource-based policies

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 AC-11
AgentCore Policy Engine Encryption Check
Details and remediation
Details

No Policy Engines found

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 AC-12
AgentCore Gateway Encryption Check
Details and remediation
Details

No Gateways found

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 AG-24
Agentic AI Gateway Inbound Authorization
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 AG-25
Agentic AI Gateway Tool Policy Enforcement
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 AG-26
Agentic AI Gateway Error Detail Exposure
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 AG-27
Agentic AI Gateway WAF Protection
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 AG-15
Agentic AI Runtime Network Boundary
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found

Resolution

Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services.

Reference

Informational N/A
111122223333 eu-west-1 AG-18
Agentic AI AgentCore Observability
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found

Resolution

Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported.

Reference

Informational N/A
111122223333 eu-west-1 AG-19
Agentic AI Memory Data Protection
Details and remediation
Details

Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found

Resolution

Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions.

Reference

Informational N/A
111122223333 eu-west-1 AG-20
Agentic AI Private AgentCore Connectivity
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found

Resolution

Create required VPC endpoints for AgentCore services and validate endpoint availability.

Reference

Informational N/A
111122223333 eu-west-1 AG-21
Agentic AI Resource Policy Boundary
Details and remediation
Details

Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies

Resolution

Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources.

Reference

Informational N/A
111122223333 eu-west-1 AG-22
Agentic AI Policy Engine Data Protection
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found

Resolution

Configure policy engines with customer-managed KMS keys where enhanced key control is required.

Reference

Informational N/A
111122223333 eu-west-1 AG-23
Agentic AI Gateway Data Protection
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found

Resolution

Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required.

Reference

Informational N/A
111122223333 Global AC-02
AgentCore IAM Full Access Policy
Details and remediation
Details

The following roles have BedrockAgentCoreFullAccess policy: AmazonSageMaker-ExecutionRole-20250525T153161

Resolution

Replace with least-privilege policies scoped to specific AgentCore resources and actions

Reference

High Failed
111122223333 Global AC-02
AgentCore IAM Wildcard Permissions
Details and remediation
Details

The following roles have wildcard AgentCore permissions on all resources: agentcore-wildrydes_gateway_role_ab3991f6-role

Resolution

Scope permissions to specific AgentCore resources using resource ARNs

Reference

High Failed
111122223333 Global AC-03
AgentCore Stale Access
Details and remediation
Details

The following principals have not accessed AgentCore in 60+ days: role 'AmazonSageMaker-ExecutionRole-20250525T153161' (208 days), role 'AWSServiceRoleForBedrockAgentCoreRuntimeIdentity' (208 days), role 'CustomerSupportAssistantBedrockAgentCoreRole-us-east-1' (208 days), role 'resco-aiml-security-19304-AgentCoreSecurityAssessme-w773pPsFWNsn' (91 days)

Resolution

Review and remove unused AgentCore permissions following least privilege principle

Reference

Medium Failed
111122223333 Global AC-03
AgentCore Unused Permissions
Details and remediation
Details

The following principals have AgentCore permissions but have never accessed the service: role 'agentcore-wildrydes_gateway_role_ab3991f6-role', role 'AIMLSecurityMemberRole', role 'AmazonBedrockAgentCoreSDKRuntime-us-east-1-a6ddf3fc76', role 'AmazonBedrockAgentCoreSDKRuntime-us-east-1-ed660add8b', role 'aws-api-mcp-server-execution-role', role 'CloudSeerTrustedServiceRole', role 'CustomerSupportStackInfra-RuntimeAgentCoreRole-N188nLB5RtLO', role 'IDP-AnalyticsProcessorFunctionRole-H3gwkJtNqrqW'

Resolution

Review and remove unused AgentCore permissions following least privilege principle

Reference

Informational N/A
111122223333 Global AC-09
AgentCore Service-Linked Role Missing
Details and remediation
Details

Service-linked role 'AWSServiceRoleForBedrockAgentCoreNetwork' does not exist. VPC configuration for AgentCore Runtimes will fail without this role.

Resolution

The service-linked role is automatically created when you configure VPC for an AgentCore Runtime. Ensure IAM permissions allow service-linked role creation.

Reference

Medium Failed
111122223333 us-east-1 AC-01
AgentCore Runtime VPC Configuration
Details and remediation
Details

Runtime 'origami_expeditions' (origami_expeditions-TR4jDoHXe8) is not configured with VPC. This exposes the runtime to public internet.

Resolution

Configure VPC with private subnets and required VPC endpoints (ECR, S3, CloudWatch Logs)

Reference

High Failed
111122223333 us-east-1 AC-01
AgentCore Runtime VPC Configuration
Details and remediation
Details

Runtime 'neoCyan_Agent' (neoCyan_Agent-yAFXSWFaA3) is not configured with VPC. This exposes the runtime to public internet.

Resolution

Configure VPC with private subnets and required VPC endpoints (ECR, S3, CloudWatch Logs)

Reference

High Failed
111122223333 us-east-1 AC-01
AgentCore Runtime VPC Configuration
Details and remediation
Details

Runtime 'customer_support_agent' (customer_support_agent-ZP4e8z55dP) is not configured with VPC. This exposes the runtime to public internet.

Resolution

Configure VPC with private subnets and required VPC endpoints (ECR, S3, CloudWatch Logs)

Reference

High Failed
111122223333 us-east-1 AC-01
AgentCore Runtime VPC Configuration
Details and remediation
Details

Runtime 'cdk_agent_core' (cdk_agent_core-7FqFlD86LW) is not configured with VPC. This exposes the runtime to public internet.

Resolution

Configure VPC with private subnets and required VPC endpoints (ECR, S3, CloudWatch Logs)

Reference

High Failed
111122223333 us-east-1 AC-01
AgentCore Runtime VPC Configuration
Details and remediation
Details

Runtime 'awsapimcpserver' (awsapimcpserver-mJrqgt37GO) is not configured with VPC. This exposes the runtime to public internet.

Resolution

Configure VPC with private subnets and required VPC endpoints (ECR, S3, CloudWatch Logs)

Reference

High Failed
111122223333 us-east-1 AC-04
AgentCore Runtime CloudWatch Logs
Details and remediation
Details

Runtime 'origami_expeditions' (origami_expeditions-TR4jDoHXe8) does not have CloudWatch Logs configured

Resolution

Enable CloudWatch Logs for monitoring and troubleshooting

Reference

Medium Failed
111122223333 us-east-1 AC-04
AgentCore Runtime X-Ray Tracing
Details and remediation
Details

Runtime 'origami_expeditions' (origami_expeditions-TR4jDoHXe8) does not have X-Ray tracing enabled

Resolution

Enable X-Ray tracing for distributed tracing and performance analysis

Reference

Medium Failed
111122223333 us-east-1 AC-04
AgentCore Runtime CloudWatch Logs
Details and remediation
Details

Runtime 'neoCyan_Agent' (neoCyan_Agent-yAFXSWFaA3) does not have CloudWatch Logs configured

Resolution

Enable CloudWatch Logs for monitoring and troubleshooting

Reference

Medium Failed
111122223333 us-east-1 AC-04
AgentCore Runtime X-Ray Tracing
Details and remediation
Details

Runtime 'neoCyan_Agent' (neoCyan_Agent-yAFXSWFaA3) does not have X-Ray tracing enabled

Resolution

Enable X-Ray tracing for distributed tracing and performance analysis

Reference

Medium Failed
111122223333 us-east-1 AC-04
AgentCore Runtime CloudWatch Logs
Details and remediation
Details

Runtime 'customer_support_agent' (customer_support_agent-ZP4e8z55dP) does not have CloudWatch Logs configured

Resolution

Enable CloudWatch Logs for monitoring and troubleshooting

Reference

Medium Failed
111122223333 us-east-1 AC-04
AgentCore Runtime X-Ray Tracing
Details and remediation
Details

Runtime 'customer_support_agent' (customer_support_agent-ZP4e8z55dP) does not have X-Ray tracing enabled

Resolution

Enable X-Ray tracing for distributed tracing and performance analysis

Reference

Medium Failed
111122223333 us-east-1 AC-04
AgentCore Runtime CloudWatch Logs
Details and remediation
Details

Runtime 'cdk_agent_core' (cdk_agent_core-7FqFlD86LW) does not have CloudWatch Logs configured

Resolution

Enable CloudWatch Logs for monitoring and troubleshooting

Reference

Medium Failed
111122223333 us-east-1 AC-04
AgentCore Runtime X-Ray Tracing
Details and remediation
Details

Runtime 'cdk_agent_core' (cdk_agent_core-7FqFlD86LW) does not have X-Ray tracing enabled

Resolution

Enable X-Ray tracing for distributed tracing and performance analysis

Reference

Medium Failed
111122223333 us-east-1 AC-04
AgentCore Runtime CloudWatch Logs
Details and remediation
Details

Runtime 'awsapimcpserver' (awsapimcpserver-mJrqgt37GO) does not have CloudWatch Logs configured

Resolution

Enable CloudWatch Logs for monitoring and troubleshooting

Reference

Medium Failed
111122223333 us-east-1 AC-04
AgentCore Runtime X-Ray Tracing
Details and remediation
Details

Runtime 'awsapimcpserver' (awsapimcpserver-mJrqgt37GO) does not have X-Ray tracing enabled

Resolution

Enable X-Ray tracing for distributed tracing and performance analysis

Reference

Medium Failed
111122223333 us-east-1 AC-05
AgentCore ECR Repository AWS-Managed Keys
Details and remediation
Details

ECR repository 'bedrock-agentcore-customer_support_agent' uses AWS-managed keys instead of customer-managed KMS keys

Resolution

Consider using customer-managed KMS keys for better control and audit capabilities

Reference

Low Failed
111122223333 us-east-1 AC-05
AgentCore ECR Repository AWS-Managed Keys
Details and remediation
Details

ECR repository 'bedrock-agentcore-origami_expeditions' uses AWS-managed keys instead of customer-managed KMS keys

Resolution

Consider using customer-managed KMS keys for better control and audit capabilities

Reference

Low Failed
111122223333 us-east-1 AC-06
AgentCore Runtime Storage Configuration
Details and remediation
Details

Runtime 'origami_expeditions' (origami_expeditions-TR4jDoHXe8) does not have storage configuration for browser tools

Resolution

Configure S3 storage for browser tool session recordings and artifacts

Reference

Medium Failed
111122223333 us-east-1 AC-06
AgentCore Runtime Storage Configuration
Details and remediation
Details

Runtime 'neoCyan_Agent' (neoCyan_Agent-yAFXSWFaA3) does not have storage configuration for browser tools

Resolution

Configure S3 storage for browser tool session recordings and artifacts

Reference

Medium Failed
111122223333 us-east-1 AC-06
AgentCore Runtime Storage Configuration
Details and remediation
Details

Runtime 'customer_support_agent' (customer_support_agent-ZP4e8z55dP) does not have storage configuration for browser tools

Resolution

Configure S3 storage for browser tool session recordings and artifacts

Reference

Medium Failed
111122223333 us-east-1 AC-06
AgentCore Runtime Storage Configuration
Details and remediation
Details

Runtime 'cdk_agent_core' (cdk_agent_core-7FqFlD86LW) does not have storage configuration for browser tools

Resolution

Configure S3 storage for browser tool session recordings and artifacts

Reference

Medium Failed
111122223333 us-east-1 AC-06
AgentCore Runtime Storage Configuration
Details and remediation
Details

Runtime 'awsapimcpserver' (awsapimcpserver-mJrqgt37GO) does not have storage configuration for browser tools

Resolution

Configure S3 storage for browser tool session recordings and artifacts

Reference

Medium Failed
111122223333 us-east-1 AC-07
AgentCore Memory Encryption
Details and remediation
Details

Memory 'CustomerSupportMemory-x69jBq5GLp' (CustomerSupportMemory-x69jBq5GLp) does not have customer-managed encryption configured

Resolution

Enable encryption with customer-managed KMS keys

Reference

Medium Failed
111122223333 us-east-1 AC-07
AgentCore Memory Encryption
Details and remediation
Details

Memory 'cdk_agent_core_mem-uxfIagADuF' (cdk_agent_core_mem-uxfIagADuF) does not have customer-managed encryption configured

Resolution

Enable encryption with customer-managed KMS keys

Reference

Medium Failed
111122223333 us-east-1 AC-07
AgentCore Memory Encryption
Details and remediation
Details

Memory 'wildrydes_memory_ab3991f6-9FjiHOHjT2' (wildrydes_memory_ab3991f6-9FjiHOHjT2) does not have customer-managed encryption configured

Resolution

Enable encryption with customer-managed KMS keys

Reference

Medium Failed
111122223333 us-east-1 AC-13
AgentCore Gateway Configuration Check
Details and remediation
Details

Found 2 Gateway resources

Resolution

No action required

Reference

Medium Passed
111122223333 us-east-1 AC-08
AgentCore VPC Endpoints Missing
Details and remediation
Details

No AgentCore VPC endpoints found in 4 VPCs. AgentCore API traffic traverses public internet, exposing it to interception.

Resolution

Create VPC interface endpoints for AgentCore services: 1. com.amazonaws.region.bedrock-agentcore 2. com.amazonaws.region.bedrock-agentcore-control 3. com.amazonaws.region.bedrock-agentcore-runtime This enables private connectivity via AWS PrivateLink

Reference

High Failed
111122223333 us-east-1 AC-10
AgentCore Resource-Based Policies Missing
Details and remediation
Details

The following AgentCore resources do not have resource-based policies: Runtime 'origami_expeditions', Runtime 'neoCyan_Agent', Runtime 'customer_support_agent', Runtime 'cdk_agent_core', Runtime 'awsapimcpserver' and 2 more. Without RBPs, access control relies solely on identity-based policies.

Resolution

Attach resource-based policies to AgentCore resources to: 1. Implement defense-in-depth access control 2. Enable cross-account access control 3. Restrict access based on source VPC or IP 4. Implement hierarchical authorization for Agent Runtimes

Reference

High Failed
111122223333 us-east-1 AC-11
AgentCore Policy Engine Encryption Check
Details and remediation
Details

No Policy Engines found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-1 AC-12
AgentCore Gateway Encryption Missing
Details and remediation
Details

The following Gateways do not use customer-managed KMS encryption: 'customersupport-gw', 'wildrydes-gateway-ab3991f6'. Gateway configuration data uses AWS-managed keys.

Resolution

1. Create gateways with customer-managed KMS keys for additional control 2. AWS-managed keys are single-tenant and region-specific 3. Consider CMK for enhanced audit capabilities and key rotation control

Reference

Low Failed
111122223333 us-east-1 AG-24
Agentic AI Gateway Inbound Authorization
Details and remediation
Details

Gateway 'customersupport-gw' (customersupport-gw-oxqopzjxae) uses authorizerType CUSTOM_JWT.

Resolution

No action required

Reference

High Passed
111122223333 us-east-1 AG-25
Agentic AI Gateway Tool Policy Enforcement Missing
Details and remediation
Details

Gateway 'customersupport-gw' (customersupport-gw-oxqopzjxae) does not have a policy engine configuration. Tool calls are not evaluated by AgentCore policy enforcement.

Resolution

Attach an AgentCore policy engine to the gateway and use ENFORCE mode for production tool authorization.

Reference

High Failed
111122223333 us-east-1 AG-26
Agentic AI Gateway Error Detail Exposure
Details and remediation
Details

Gateway 'customersupport-gw' (customersupport-gw-oxqopzjxae) does not expose DEBUG-level exception detail.

Resolution

No action required

Reference

Medium Passed
111122223333 us-east-1 AG-27
Agentic AI Gateway WAF Protection Missing
Details and remediation
Details

Gateway 'customersupport-gw' (customersupport-gw-oxqopzjxae) is not associated with an AWS WAF web ACL.

Resolution

Associate an AWS WAF web ACL with internet-facing AgentCore gateways to add request filtering and abuse protection.

Reference

Low Failed
111122223333 us-east-1 AG-24
Agentic AI Gateway Inbound Authorization
Details and remediation
Details

Gateway 'wildrydes-gateway-ab3991f6' (wildrydes-gateway-ab3991f6-jrlh9ok6ya) uses authorizerType CUSTOM_JWT.

Resolution

No action required

Reference

High Passed
111122223333 us-east-1 AG-25
Agentic AI Gateway Tool Policy Enforcement Missing
Details and remediation
Details

Gateway 'wildrydes-gateway-ab3991f6' (wildrydes-gateway-ab3991f6-jrlh9ok6ya) does not have a policy engine configuration. Tool calls are not evaluated by AgentCore policy enforcement.

Resolution

Attach an AgentCore policy engine to the gateway and use ENFORCE mode for production tool authorization.

Reference

High Failed
111122223333 us-east-1 AG-26
Agentic AI Gateway Error Detail Exposure
Details and remediation
Details

Gateway 'wildrydes-gateway-ab3991f6' (wildrydes-gateway-ab3991f6-jrlh9ok6ya) does not expose DEBUG-level exception detail.

Resolution

No action required

Reference

Medium Passed
111122223333 us-east-1 AG-27
Agentic AI Gateway WAF Protection Missing
Details and remediation
Details

Gateway 'wildrydes-gateway-ab3991f6' (wildrydes-gateway-ab3991f6-jrlh9ok6ya) is not associated with an AWS WAF web ACL.

Resolution

Associate an AWS WAF web ACL with internet-facing AgentCore gateways to add request filtering and abuse protection.

Reference

Low Failed
111122223333 Global AG-16
Agentic AI AgentCore Least Privilege
Details and remediation
Details

Agentic AI security domain: Agent Identity & Access. Over-permissive AgentCore principals can let agents or operators bypass intended autonomy and tool boundaries. Source check AC-02: The following roles have BedrockAgentCoreFullAccess policy: AmazonSageMaker-ExecutionRole-20250525T153161

Resolution

Replace full-access AgentCore permissions with least-privilege IAM policies scoped to required resources and actions.

Reference

High Failed
111122223333 Global AG-16
Agentic AI AgentCore Least Privilege
Details and remediation
Details

Agentic AI security domain: Agent Identity & Access. Over-permissive AgentCore principals can let agents or operators bypass intended autonomy and tool boundaries. Source check AC-02: The following roles have wildcard AgentCore permissions on all resources: agentcore-wildrydes_gateway_role_ab3991f6-role

Resolution

Replace full-access AgentCore permissions with least-privilege IAM policies scoped to required resources and actions.

Reference

High Failed
111122223333 Global AG-17
Agentic AI Stale AgentCore Access
Details and remediation
Details

Agentic AI security domain: Agent Identity & Access. Unused AgentCore permissions increase the blast radius of compromised principals. Source check AC-03: The following principals have not accessed AgentCore in 60+ days: role 'AmazonSageMaker-ExecutionRole-20250525T153161' (208 days), role 'AWSServiceRoleForBedrockAgentCoreRuntimeIdentity' (208 days), role 'CustomerSupportAssistantBedrockAgentCoreRole-us-east-1' (208 days), role 'resco-aiml-security-19304-AgentCoreSecurityAssessme-w773pPsFWNsn' (91 days)

Resolution

Remove or restrict stale AgentCore permissions for principals that no longer need access.

Reference

Medium Failed
111122223333 Global AG-17
Agentic AI Stale AgentCore Access
Details and remediation
Details

Agentic AI security domain: Agent Identity & Access. Unused AgentCore permissions increase the blast radius of compromised principals. Source check AC-03: The following principals have AgentCore permissions but have never accessed the service: role 'agentcore-wildrydes_gateway_role_ab3991f6-role', role 'AIMLSecurityMemberRole', role 'AmazonBedrockAgentCoreSDKRuntime-us-east-1-a6ddf3fc76', role 'AmazonBedrockAgentCoreSDKRuntime-us-east-1-ed660add8b', role 'aws-api-mcp-server-execution-role', role 'CloudSeerTrustedServiceRole', role 'CustomerSupportStackInfra-RuntimeAgentCoreRole-N188nLB5RtLO', role 'IDP-AnalyticsProcessorFunctionRole-H3gwkJtNqrqW'

Resolution

Remove or restrict stale AgentCore permissions for principals that no longer need access.

Reference

Informational N/A
111122223333 us-east-1 AG-15
Agentic AI Runtime Network Boundary
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: Runtime 'origami_expeditions' (origami_expeditions-TR4jDoHXe8) is not configured with VPC. This exposes the runtime to public internet.

Resolution

Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services.

Reference

High Failed
111122223333 us-east-1 AG-15
Agentic AI Runtime Network Boundary
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: Runtime 'neoCyan_Agent' (neoCyan_Agent-yAFXSWFaA3) is not configured with VPC. This exposes the runtime to public internet.

Resolution

Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services.

Reference

High Failed
111122223333 us-east-1 AG-15
Agentic AI Runtime Network Boundary
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: Runtime 'customer_support_agent' (customer_support_agent-ZP4e8z55dP) is not configured with VPC. This exposes the runtime to public internet.

Resolution

Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services.

Reference

High Failed
111122223333 us-east-1 AG-15
Agentic AI Runtime Network Boundary
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: Runtime 'cdk_agent_core' (cdk_agent_core-7FqFlD86LW) is not configured with VPC. This exposes the runtime to public internet.

Resolution

Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services.

Reference

High Failed
111122223333 us-east-1 AG-15
Agentic AI Runtime Network Boundary
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: Runtime 'awsapimcpserver' (awsapimcpserver-mJrqgt37GO) is not configured with VPC. This exposes the runtime to public internet.

Resolution

Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services.

Reference

High Failed
111122223333 us-east-1 AG-18
Agentic AI AgentCore Observability
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: Runtime 'origami_expeditions' (origami_expeditions-TR4jDoHXe8) does not have CloudWatch Logs configured

Resolution

Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported.

Reference

Medium Failed
111122223333 us-east-1 AG-18
Agentic AI AgentCore Observability
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: Runtime 'origami_expeditions' (origami_expeditions-TR4jDoHXe8) does not have X-Ray tracing enabled

Resolution

Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported.

Reference

Medium Failed
111122223333 us-east-1 AG-18
Agentic AI AgentCore Observability
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: Runtime 'neoCyan_Agent' (neoCyan_Agent-yAFXSWFaA3) does not have CloudWatch Logs configured

Resolution

Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported.

Reference

Medium Failed
111122223333 us-east-1 AG-18
Agentic AI AgentCore Observability
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: Runtime 'neoCyan_Agent' (neoCyan_Agent-yAFXSWFaA3) does not have X-Ray tracing enabled

Resolution

Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported.

Reference

Medium Failed
111122223333 us-east-1 AG-18
Agentic AI AgentCore Observability
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: Runtime 'customer_support_agent' (customer_support_agent-ZP4e8z55dP) does not have CloudWatch Logs configured

Resolution

Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported.

Reference

Medium Failed
111122223333 us-east-1 AG-18
Agentic AI AgentCore Observability
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: Runtime 'customer_support_agent' (customer_support_agent-ZP4e8z55dP) does not have X-Ray tracing enabled

Resolution

Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported.

Reference

Medium Failed
111122223333 us-east-1 AG-18
Agentic AI AgentCore Observability
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: Runtime 'cdk_agent_core' (cdk_agent_core-7FqFlD86LW) does not have CloudWatch Logs configured

Resolution

Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported.

Reference

Medium Failed
111122223333 us-east-1 AG-18
Agentic AI AgentCore Observability
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: Runtime 'cdk_agent_core' (cdk_agent_core-7FqFlD86LW) does not have X-Ray tracing enabled

Resolution

Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported.

Reference

Medium Failed
111122223333 us-east-1 AG-18
Agentic AI AgentCore Observability
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: Runtime 'awsapimcpserver' (awsapimcpserver-mJrqgt37GO) does not have CloudWatch Logs configured

Resolution

Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported.

Reference

Medium Failed
111122223333 us-east-1 AG-18
Agentic AI AgentCore Observability
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: Runtime 'awsapimcpserver' (awsapimcpserver-mJrqgt37GO) does not have X-Ray tracing enabled

Resolution

Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported.

Reference

Medium Failed
111122223333 us-east-1 AG-19
Agentic AI Memory Data Protection
Details and remediation
Details

Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: Memory 'CustomerSupportMemory-x69jBq5GLp' (CustomerSupportMemory-x69jBq5GLp) does not have customer-managed encryption configured

Resolution

Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions.

Reference

Medium Failed
111122223333 us-east-1 AG-19
Agentic AI Memory Data Protection
Details and remediation
Details

Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: Memory 'cdk_agent_core_mem-uxfIagADuF' (cdk_agent_core_mem-uxfIagADuF) does not have customer-managed encryption configured

Resolution

Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions.

Reference

Medium Failed
111122223333 us-east-1 AG-19
Agentic AI Memory Data Protection
Details and remediation
Details

Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: Memory 'wildrydes_memory_ab3991f6-9FjiHOHjT2' (wildrydes_memory_ab3991f6-9FjiHOHjT2) does not have customer-managed encryption configured

Resolution

Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions.

Reference

Medium Failed
111122223333 us-east-1 AG-20
Agentic AI Private AgentCore Connectivity
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore VPC endpoints found in 4 VPCs. AgentCore API traffic traverses public internet, exposing it to interception.

Resolution

Create required VPC endpoints for AgentCore services and validate endpoint availability.

Reference

High Failed
111122223333 us-east-1 AG-21
Agentic AI Resource Policy Boundary
Details and remediation
Details

Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: The following AgentCore resources do not have resource-based policies: Runtime 'origami_expeditions', Runtime 'neoCyan_Agent', Runtime 'customer_support_agent', Runtime 'cdk_agent_core', Runtime 'awsapimcpserver' and 2 more. Without RBPs, access control relies solely on identity-based policies.

Resolution

Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources.

Reference

High Failed
111122223333 us-east-1 AG-22
Agentic AI Policy Engine Data Protection
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found

Resolution

Configure policy engines with customer-managed KMS keys where enhanced key control is required.

Reference

Informational N/A
111122223333 us-east-1 AG-23
Agentic AI Gateway Data Protection
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: The following Gateways do not use customer-managed KMS encryption: 'customersupport-gw', 'wildrydes-gateway-ab3991f6'. Gateway configuration data uses AWS-managed keys.

Resolution

Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required.

Reference

Low Failed
111122223333 us-east-1 FS-01
AWS Shield Advanced Not Enabled
Details and remediation
Details

AWS Shield Advanced is not subscribed. GenAI API endpoints are vulnerable to volumetric DDoS attacks that can exhaust token quotas and inflate costs.

Resolution

1. Subscribe to AWS Shield Advanced for DDoS protection. 2. After subscribing, explicitly add resource protections in the Shield Advanced console for each Bedrock-facing resource (API Gateway stages, ALBs, CloudFront distributions, Route 53 hosted zones). Shield Advanced subscription alone does NOT automatically protect resources — each resource must be individually added to receive protection. 3. Enable Shield Response Team (SRT) access and configure proactive engagement. 4. Alternatively, use AWS Firewall Manager with a Shield Advanced policy to automate resource protection based on tags or resource types.

Reference

Low Failed
111122223333 us-east-2 FS-01
AWS Shield Advanced Not Enabled
Details and remediation
Details

AWS Shield Advanced is not subscribed. GenAI API endpoints are vulnerable to volumetric DDoS attacks that can exhaust token quotas and inflate costs.

Resolution

1. Subscribe to AWS Shield Advanced for DDoS protection. 2. After subscribing, explicitly add resource protections in the Shield Advanced console for each Bedrock-facing resource (API Gateway stages, ALBs, CloudFront distributions, Route 53 hosted zones). Shield Advanced subscription alone does NOT automatically protect resources — each resource must be individually added to receive protection. 3. Enable Shield Response Team (SRT) access and configure proactive engagement. 4. Alternatively, use AWS Firewall Manager with a Shield Advanced policy to automate resource protection based on tags or resource types.

Reference

Low Failed
111122223333 us-west-2 FS-01
AWS Shield Advanced Not Enabled
Details and remediation
Details

AWS Shield Advanced is not subscribed. GenAI API endpoints are vulnerable to volumetric DDoS attacks that can exhaust token quotas and inflate costs.

Resolution

1. Subscribe to AWS Shield Advanced for DDoS protection. 2. After subscribing, explicitly add resource protections in the Shield Advanced console for each Bedrock-facing resource (API Gateway stages, ALBs, CloudFront distributions, Route 53 hosted zones). Shield Advanced subscription alone does NOT automatically protect resources — each resource must be individually added to receive protection. 3. Enable Shield Response Team (SRT) access and configure proactive engagement. 4. Alternatively, use AWS Firewall Manager with a Shield Advanced policy to automate resource protection based on tags or resource types.

Reference

Low Failed
111122223333 us-east-1 FS-01
No Regional WAF Web ACLs Found
Details and remediation
Details

No AWS WAF regional Web ACLs found. Without WAF, GenAI endpoints lack rate-based rules to block abusive callers.

Resolution

1. Create a WAF Web ACL with rate-based rules (e.g., 1000 req/5 min per IP). 2. Associate the ACL with API Gateway stages or ALBs fronting Bedrock. 3. Add AWS Managed Rules for known bad inputs.

Reference

Medium Failed
111122223333 us-east-2 FS-01
No Regional WAF Web ACLs Found
Details and remediation
Details

No AWS WAF regional Web ACLs found. Without WAF, GenAI endpoints lack rate-based rules to block abusive callers.

Resolution

1. Create a WAF Web ACL with rate-based rules (e.g., 1000 req/5 min per IP). 2. Associate the ACL with API Gateway stages or ALBs fronting Bedrock. 3. Add AWS Managed Rules for known bad inputs.

Reference

Medium Failed
111122223333 us-west-2 FS-01
No Regional WAF Web ACLs Found
Details and remediation
Details

No AWS WAF regional Web ACLs found. Without WAF, GenAI endpoints lack rate-based rules to block abusive callers.

Resolution

1. Create a WAF Web ACL with rate-based rules (e.g., 1000 req/5 min per IP). 2. Associate the ACL with API Gateway stages or ALBs fronting Bedrock. 3. Add AWS Managed Rules for known bad inputs.

Reference

Medium Failed
111122223333 us-east-1 FS-02
API Gateway Usage Plans Missing Throttle
Details and remediation
Details

Usage plans without throttling: myAskMeAnything-UsagePlan. Unbounded API calls can exhaust Bedrock token quotas and inflate costs.

Resolution

Set rateLimit and burstLimit on all usage plans associated with GenAI API stages. Consider per-consumer API keys with individual quotas.

Reference

Medium Failed
111122223333 us-east-2 FS-02
API Gateway Usage Plans Missing Throttle
Details and remediation
Details

Usage plans without throttling: myAskMeAnything-UsagePlan. Unbounded API calls can exhaust Bedrock token quotas and inflate costs.

Resolution

Set rateLimit and burstLimit on all usage plans associated with GenAI API stages. Consider per-consumer API keys with individual quotas.

Reference

Medium Failed
111122223333 us-west-2 FS-02
API Gateway Usage Plans Missing Throttle
Details and remediation
Details

Usage plans without throttling: myAskMeAnything-UsagePlan. Unbounded API calls can exhaust Bedrock token quotas and inflate costs.

Resolution

Set rateLimit and burstLimit on all usage plans associated with GenAI API stages. Consider per-consumer API keys with individual quotas.

Reference

Medium Failed
111122223333 us-east-1 FS-03
Bedrock Token Quotas Customized
Details and remediation
Details

Found 240 Bedrock token-based quota(s); at least one applied value exceeds the AWS default, indicating quotas have been reviewed and raised.

Resolution

No action required. Periodically re-review quotas against expected peak load.

Reference

Medium Passed
111122223333 us-east-2 FS-03
Bedrock Token Quotas Customized
Details and remediation
Details

Found 240 Bedrock token-based quota(s); at least one applied value exceeds the AWS default, indicating quotas have been reviewed and raised.

Resolution

No action required. Periodically re-review quotas against expected peak load.

Reference

Medium Passed
111122223333 us-west-2 FS-03
Bedrock Token Quotas Customized
Details and remediation
Details

Found 240 Bedrock token-based quota(s); at least one applied value exceeds the AWS default, indicating quotas have been reviewed and raised.

Resolution

No action required. Periodically re-review quotas against expected peak load.

Reference

Medium Passed
111122223333 us-east-1 FS-04
No Cost Anomaly Detection Monitors
Details and remediation
Details

No AWS Cost Anomaly Detection monitors found. Unexpected spikes in Bedrock/SageMaker usage (e.g., from prompt injection loops) will go undetected.

Resolution

1. Create a Cost Anomaly Detection monitor scoped to AWS/Bedrock and AWS/SageMaker. 2. Configure alert subscriptions (SNS/email) for anomalies above threshold. 3. Set daily spend budgets with AWS Budgets as a secondary control.

Reference

Medium Failed
111122223333 us-east-2 FS-04
No Cost Anomaly Detection Monitors
Details and remediation
Details

No AWS Cost Anomaly Detection monitors found. Unexpected spikes in Bedrock/SageMaker usage (e.g., from prompt injection loops) will go undetected.

Resolution

1. Create a Cost Anomaly Detection monitor scoped to AWS/Bedrock and AWS/SageMaker. 2. Configure alert subscriptions (SNS/email) for anomalies above threshold. 3. Set daily spend budgets with AWS Budgets as a secondary control.

Reference

Medium Failed
111122223333 us-west-2 FS-04
No Cost Anomaly Detection Monitors
Details and remediation
Details

No AWS Cost Anomaly Detection monitors found. Unexpected spikes in Bedrock/SageMaker usage (e.g., from prompt injection loops) will go undetected.

Resolution

1. Create a Cost Anomaly Detection monitor scoped to AWS/Bedrock and AWS/SageMaker. 2. Configure alert subscriptions (SNS/email) for anomalies above threshold. 3. Set daily spend budgets with AWS Budgets as a secondary control.

Reference

Medium Failed
111122223333 us-east-1 FS-05
No Bedrock CloudWatch Alarms Found
Details and remediation
Details

No CloudWatch alarms found for Bedrock metrics. Token exhaustion and throttling events will not trigger operational alerts.

Resolution

Create CloudWatch alarms for: - AWS/Bedrock InvocationThrottles (threshold > 0) - AWS/Bedrock TokensProcessed (threshold based on quota) - Custom application-level token counters via EMF

Reference

Medium Failed
111122223333 us-east-2 FS-05
No Bedrock CloudWatch Alarms Found
Details and remediation
Details

No CloudWatch alarms found for Bedrock metrics. Token exhaustion and throttling events will not trigger operational alerts.

Resolution

Create CloudWatch alarms for: - AWS/Bedrock InvocationThrottles (threshold > 0) - AWS/Bedrock TokensProcessed (threshold based on quota) - Custom application-level token counters via EMF

Reference

Medium Failed
111122223333 us-west-2 FS-05
No Bedrock CloudWatch Alarms Found
Details and remediation
Details

No CloudWatch alarms found for Bedrock metrics. Token exhaustion and throttling events will not trigger operational alerts.

Resolution

Create CloudWatch alarms for: - AWS/Bedrock InvocationThrottles (threshold > 0) - AWS/Bedrock TokensProcessed (threshold based on quota) - Custom application-level token counters via EMF

Reference

Medium Failed
111122223333 us-east-1 FS-06
No AI/ML Service Budgets Configured
Details and remediation
Details

No AWS Budgets found scoped to Bedrock or SageMaker. Unbounded GenAI spend can go undetected until the monthly bill.

Resolution

1. Create cost budgets for AWS Bedrock and SageMaker with 80%/100% alert thresholds. 2. Add SNS notifications to on-call channels. 3. Consider budget actions to apply IAM deny policies when thresholds are breached.

Reference

Medium Failed
111122223333 us-east-2 FS-06
No AI/ML Service Budgets Configured
Details and remediation
Details

No AWS Budgets found scoped to Bedrock or SageMaker. Unbounded GenAI spend can go undetected until the monthly bill.

Resolution

1. Create cost budgets for AWS Bedrock and SageMaker with 80%/100% alert thresholds. 2. Add SNS notifications to on-call channels. 3. Consider budget actions to apply IAM deny policies when thresholds are breached.

Reference

Medium Failed
111122223333 us-west-2 FS-06
No AI/ML Service Budgets Configured
Details and remediation
Details

No AWS Budgets found scoped to Bedrock or SageMaker. Unbounded GenAI spend can go undetected until the monthly bill.

Resolution

1. Create cost budgets for AWS Bedrock and SageMaker with 80%/100% alert thresholds. 2. Add SNS notifications to on-call channels. 3. Consider budget actions to apply IAM deny policies when thresholds are breached.

Reference

Medium Failed
111122223333 us-east-1 FS-07
Agent Action Boundary Check
Details and remediation
Details

No Bedrock agents found.

Resolution

No action required.

Reference

Informational N/A
111122223333 us-east-2 FS-07
Agent Action Boundary Check
Details and remediation
Details

No Bedrock agents found.

Resolution

No action required.

Reference

Informational N/A
111122223333 us-west-2 FS-07
Agent Action Boundary Check
Details and remediation
Details

No Bedrock agents found.

Resolution

No action required.

Reference

Informational N/A
111122223333 us-east-1 FS-08
AgentCore Runtimes Missing Policy Engine
Details and remediation
Details

Runtimes without authorizer configuration: origami_expeditions, neoCyan_Agent, customer_support_agent, cdk_agent_core, awsapimcpserver. Without a policy engine, agents can invoke any registered tool without authorization checks.

Resolution

Configure an authorizer (Lambda or Cedar policy store) on each AgentCore runtime to enforce fine-grained tool-call authorization.

Reference

High Failed
111122223333 us-east-2 FS-08
AgentCore Runtimes Missing Policy Engine
Details and remediation
Details

Runtimes without authorizer configuration: origami_expeditions, neoCyan_Agent, customer_support_agent, cdk_agent_core, awsapimcpserver. Without a policy engine, agents can invoke any registered tool without authorization checks.

Resolution

Configure an authorizer (Lambda or Cedar policy store) on each AgentCore runtime to enforce fine-grained tool-call authorization.

Reference

High Failed
111122223333 us-west-2 FS-08
AgentCore Runtimes Missing Policy Engine
Details and remediation
Details

Runtimes without authorizer configuration: origami_expeditions, neoCyan_Agent, customer_support_agent, cdk_agent_core, awsapimcpserver. Without a policy engine, agents can invoke any registered tool without authorization checks.

Resolution

Configure an authorizer (Lambda or Cedar policy store) on each AgentCore runtime to enforce fine-grained tool-call authorization.

Reference

High Failed
111122223333 us-east-1 FS-09
Agent Lambda Functions Without Concurrency Limits
Details and remediation
Details

Agent-related Lambda functions without reserved concurrency: aiml-security-aiml-security-111122223333-FinServAssessment, resco-aiml-IAMPermissionCaching, aiml-security-aiml-security-111122223333-OWASPAssessment, aiml-security-aiml-security-111122223333-SagemakerAssessment, resco-aiml-CleanupBucket, aiml-security-aiml-security-111122223333-BedrockAssessment, resco-aiml-BedrockAssessment, aiml-security-aiml-security-111122223333-CleanupBucket, aiml-security-aiml-security-111122223333-AgentCoreAssessment, e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk. Unlimited concurrency allows runaway agent loops to exhaust account limits.

Resolution

1. Set reserved concurrency on agent Lambda functions. 2. Implement maximum iteration counts in agent orchestration logic. 3. Use Step Functions with MaxConcurrency and timeout states. 4. Add circuit-breaker patterns to agent tool invocations.

Reference

Medium Failed
111122223333 us-east-2 FS-09
Agent Lambda Functions Without Concurrency Limits
Details and remediation
Details

Agent-related Lambda functions without reserved concurrency: aiml-security-aiml-security-111122223333-FinServAssessment, resco-aiml-IAMPermissionCaching, aiml-security-aiml-security-111122223333-OWASPAssessment, aiml-security-aiml-security-111122223333-SagemakerAssessment, resco-aiml-CleanupBucket, aiml-security-aiml-security-111122223333-BedrockAssessment, resco-aiml-BedrockAssessment, aiml-security-aiml-security-111122223333-CleanupBucket, aiml-security-aiml-security-111122223333-AgentCoreAssessment, e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk. Unlimited concurrency allows runaway agent loops to exhaust account limits.

Resolution

1. Set reserved concurrency on agent Lambda functions. 2. Implement maximum iteration counts in agent orchestration logic. 3. Use Step Functions with MaxConcurrency and timeout states. 4. Add circuit-breaker patterns to agent tool invocations.

Reference

Medium Failed
111122223333 us-west-2 FS-09
Agent Lambda Functions Without Concurrency Limits
Details and remediation
Details

Agent-related Lambda functions without reserved concurrency: aiml-security-aiml-security-111122223333-FinServAssessment, resco-aiml-IAMPermissionCaching, aiml-security-aiml-security-111122223333-OWASPAssessment, aiml-security-aiml-security-111122223333-SagemakerAssessment, resco-aiml-CleanupBucket, aiml-security-aiml-security-111122223333-BedrockAssessment, resco-aiml-BedrockAssessment, aiml-security-aiml-security-111122223333-CleanupBucket, aiml-security-aiml-security-111122223333-AgentCoreAssessment, e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk. Unlimited concurrency allows runaway agent loops to exhaust account limits.

Resolution

1. Set reserved concurrency on agent Lambda functions. 2. Implement maximum iteration counts in agent orchestration logic. 3. Use Step Functions with MaxConcurrency and timeout states. 4. Add circuit-breaker patterns to agent tool invocations.

Reference

Medium Failed
111122223333 us-east-1 FS-10
Human-in-the-Loop Check — No Agent Workflows Found
Details and remediation
Details

No Step Functions state machines with agent/approval naming found. Verify that high-risk agent actions (e.g., fund transfers, account changes) have human approval gates.

Resolution

Implement Step Functions .waitForTaskToken patterns for high-risk agent actions. Route approval requests to human reviewers via SNS/SES/Slack.

Reference

Informational N/A
111122223333 us-east-2 FS-10
Human-in-the-Loop Check — No Agent Workflows Found
Details and remediation
Details

No Step Functions state machines with agent/approval naming found. Verify that high-risk agent actions (e.g., fund transfers, account changes) have human approval gates.

Resolution

Implement Step Functions .waitForTaskToken patterns for high-risk agent actions. Route approval requests to human reviewers via SNS/SES/Slack.

Reference

Informational N/A
111122223333 us-west-2 FS-10
Human-in-the-Loop Check — No Agent Workflows Found
Details and remediation
Details

No Step Functions state machines with agent/approval naming found. Verify that high-risk agent actions (e.g., fund transfers, account changes) have human approval gates.

Resolution

Implement Step Functions .waitForTaskToken patterns for high-risk agent actions. Route approval requests to human reviewers via SNS/SES/Slack.

Reference

Informational N/A
111122223333 us-east-1 FS-11
No Agent Rate Alarms Found
Details and remediation
Details

No CloudWatch alarms found for agent invocation rates. Looping or runaway agents will not trigger operational alerts.

Resolution

Create CloudWatch alarms on: - Bedrock agent invocation counts (threshold based on expected max) - Lambda invocation errors for agent functions - Step Functions execution failures and timeouts

Reference

Medium Failed
111122223333 us-east-2 FS-11
No Agent Rate Alarms Found
Details and remediation
Details

No CloudWatch alarms found for agent invocation rates. Looping or runaway agents will not trigger operational alerts.

Resolution

Create CloudWatch alarms on: - Bedrock agent invocation counts (threshold based on expected max) - Lambda invocation errors for agent functions - Step Functions execution failures and timeouts

Reference

Medium Failed
111122223333 us-west-2 FS-11
No Agent Rate Alarms Found
Details and remediation
Details

No CloudWatch alarms found for agent invocation rates. Looping or runaway agents will not trigger operational alerts.

Resolution

Create CloudWatch alarms on: - Bedrock agent invocation counts (threshold based on expected max) - Lambda invocation errors for agent functions - Step Functions execution failures and timeouts

Reference

Medium Failed
111122223333 us-east-1 FS-12
No Bedrock-Scoped SCPs Found
Details and remediation
Details

No Service Control Policies reference Bedrock. Without SCPs, any account in the organization can access any Bedrock model, including unapproved third-party models.

Resolution

1. Create an SCP that denies bedrock:InvokeModel for model IDs not on the approved list. 2. Use bedrock:ModelId condition key to allowlist approved models. 3. Maintain a model inventory and update the SCP when models are approved/retired.

Reference

High Failed
111122223333 us-east-2 FS-12
No Bedrock-Scoped SCPs Found
Details and remediation
Details

No Service Control Policies reference Bedrock. Without SCPs, any account in the organization can access any Bedrock model, including unapproved third-party models.

Resolution

1. Create an SCP that denies bedrock:InvokeModel for model IDs not on the approved list. 2. Use bedrock:ModelId condition key to allowlist approved models. 3. Maintain a model inventory and update the SCP when models are approved/retired.

Reference

High Failed
111122223333 us-west-2 FS-12
No Bedrock-Scoped SCPs Found
Details and remediation
Details

No Service Control Policies reference Bedrock. Without SCPs, any account in the organization can access any Bedrock model, including unapproved third-party models.

Resolution

1. Create an SCP that denies bedrock:InvokeModel for model IDs not on the approved list. 2. Use bedrock:ModelId condition key to allowlist approved models. 3. Maintain a model inventory and update the SCP when models are approved/retired.

Reference

High Failed
111122223333 us-east-1 FS-13
Model Provenance Tags Present
Details and remediation
Details

All reviewed models have required provenance tags.

Resolution

No action required.

Reference

Medium Passed
111122223333 us-east-2 FS-13
Model Provenance Tags Present
Details and remediation
Details

All reviewed models have required provenance tags.

Resolution

No action required.

Reference

Medium Passed
111122223333 us-west-2 FS-13
Model Provenance Tags Present
Details and remediation
Details

All reviewed models have required provenance tags.

Resolution

No action required.

Reference

Medium Passed
111122223333 us-east-1 FS-14
Model Governance Config Rules Present
Details and remediation
Details

Found 11 model-related Config rule(s).

Resolution

No action required.

Reference

Medium Passed
111122223333 us-east-2 FS-14
Model Governance Config Rules Present
Details and remediation
Details

Found 11 model-related Config rule(s).

Resolution

No action required.

Reference

Medium Passed
111122223333 us-west-2 FS-14
Model Governance Config Rules Present
Details and remediation
Details

Found 11 model-related Config rule(s).

Resolution

No action required.

Reference

Medium Passed
111122223333 us-east-1 FS-15
No Bedrock Evaluation Jobs Found
Details and remediation
Details

No Bedrock Model Evaluation jobs found. Models have not been evaluated for adversarial robustness. FinServ model-risk management (SR 11-7) expects documented model validation/evaluation.

Resolution

1. Run Bedrock Model Evaluation with adversarial/red-team datasets. 2. Use FMEval library for automated robustness testing. 3. Schedule periodic re-evaluation after model updates.

Reference

Medium Failed
111122223333 us-east-2 FS-15
No Bedrock Evaluation Jobs Found
Details and remediation
Details

No Bedrock Model Evaluation jobs found. Models have not been evaluated for adversarial robustness. FinServ model-risk management (SR 11-7) expects documented model validation/evaluation.

Resolution

1. Run Bedrock Model Evaluation with adversarial/red-team datasets. 2. Use FMEval library for automated robustness testing. 3. Schedule periodic re-evaluation after model updates.

Reference

Medium Failed
111122223333 us-west-2 FS-15
No Bedrock Evaluation Jobs Found
Details and remediation
Details

No Bedrock Model Evaluation jobs found. Models have not been evaluated for adversarial robustness. FinServ model-risk management (SR 11-7) expects documented model validation/evaluation.

Resolution

1. Run Bedrock Model Evaluation with adversarial/red-team datasets. 2. Use FMEval library for automated robustness testing. 3. Schedule periodic re-evaluation after model updates.

Reference

Medium Failed
111122223333 us-east-1 FS-16
ECR Repositories Without Image Scanning
Details and remediation
Details

4 ECR repo(s) without scan-on-push: mlexplorationrepo, cdk-hnb659fds-container-assets-111122223333-us-east-1, bedrock-agentcore-customer_support_agent, bedrock-agentcore-origami_expeditions.

Resolution

Enable scan-on-push for all ECR repositories containing model containers. Consider enabling Enhanced Scanning (Inspector) for CVE detection.

Reference

High Failed
111122223333 us-east-2 FS-16
ECR Repositories Without Image Scanning
Details and remediation
Details

4 ECR repo(s) without scan-on-push: mlexplorationrepo, cdk-hnb659fds-container-assets-111122223333-us-east-1, bedrock-agentcore-customer_support_agent, bedrock-agentcore-origami_expeditions.

Resolution

Enable scan-on-push for all ECR repositories containing model containers. Consider enabling Enhanced Scanning (Inspector) for CVE detection.

Reference

High Failed
111122223333 us-west-2 FS-16
ECR Repositories Without Image Scanning
Details and remediation
Details

4 ECR repo(s) without scan-on-push: mlexplorationrepo, cdk-hnb659fds-container-assets-111122223333-us-east-1, bedrock-agentcore-customer_support_agent, bedrock-agentcore-origami_expeditions.

Resolution

Enable scan-on-push for all ECR repositories containing model containers. Consider enabling Enhanced Scanning (Inspector) for CVE detection.

Reference

High Failed
111122223333 us-east-1 FS-20
No SageMaker Feature Groups Found
Details and remediation
Details

No SageMaker Feature Store groups found.

Resolution

No action required.

Reference

Informational N/A
111122223333 us-east-2 FS-20
No SageMaker Feature Groups Found
Details and remediation
Details

No SageMaker Feature Store groups found.

Resolution

No action required.

Reference

Informational N/A
111122223333 us-west-2 FS-20
No SageMaker Feature Groups Found
Details and remediation
Details

No SageMaker Feature Store groups found.

Resolution

No action required.

Reference

Informational N/A
111122223333 us-east-1 FS-21
Training Data Buckets Without Versioning
Details and remediation
Details

13 training data bucket(s) without versioning: ancbedrocklogging, bedrock-agentcore-codebuild-sources-111122223333-us-east-1, bedrock-bda-us-east-1-dda43109-6557-48bb-993d-3f97126b64b4, bedrock-bda-us-east-1-logging-00719114-debd-4487-85d1-09cbc3fc8, bedrock-kb-bucket-f736570b, bedrock-video-generation-us-east-1-h5ltpm, fsi-genai-workshop-bedrock-datasources-111122223333-us-west-2, knowledgebase-bedrock-agent-agasthik, llmevaluationpromptfoo-bedrockkb-cozhbzbrcmd2, sagemaker-studio-111122223333-huo1mvme4t.

Resolution

Enable S3 versioning on all training data buckets. Consider enabling MFA Delete for additional protection against poisoning.

Reference

High Failed
111122223333 us-east-2 FS-21
Training Data Buckets Without Versioning
Details and remediation
Details

13 training data bucket(s) without versioning: ancbedrocklogging, bedrock-agentcore-codebuild-sources-111122223333-us-east-1, bedrock-bda-us-east-1-dda43109-6557-48bb-993d-3f97126b64b4, bedrock-bda-us-east-1-logging-00719114-debd-4487-85d1-09cbc3fc8, bedrock-kb-bucket-f736570b, bedrock-video-generation-us-east-1-h5ltpm, fsi-genai-workshop-bedrock-datasources-111122223333-us-west-2, knowledgebase-bedrock-agent-agasthik, llmevaluationpromptfoo-bedrockkb-cozhbzbrcmd2, sagemaker-studio-111122223333-huo1mvme4t.

Resolution

Enable S3 versioning on all training data buckets. Consider enabling MFA Delete for additional protection against poisoning.

Reference

High Failed
111122223333 us-west-2 FS-21
Training Data Buckets Without Versioning
Details and remediation
Details

13 training data bucket(s) without versioning: ancbedrocklogging, bedrock-agentcore-codebuild-sources-111122223333-us-east-1, bedrock-bda-us-east-1-dda43109-6557-48bb-993d-3f97126b64b4, bedrock-bda-us-east-1-logging-00719114-debd-4487-85d1-09cbc3fc8, bedrock-kb-bucket-f736570b, bedrock-video-generation-us-east-1-h5ltpm, fsi-genai-workshop-bedrock-datasources-111122223333-us-west-2, knowledgebase-bedrock-agent-agasthik, llmevaluationpromptfoo-bedrockkb-cozhbzbrcmd2, sagemaker-studio-111122223333-huo1mvme4t.

Resolution

Enable S3 versioning on all training data buckets. Consider enabling MFA Delete for additional protection against poisoning.

Reference

High Failed
111122223333 us-east-1 FS-22
Overly Permissive Knowledge Base IAM Roles
Details and remediation
Details

829 role(s) with wildcard KB permissions: - Role '111122223333-us-east-1-kb-setup-function-role' allows 'bedrock:CreateKnowledgeBase' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role '111122223333-us-east-1-kb-setup-function-role' allows 'bedrock:CreateDataSource' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'Admin' allows '*' - Role 'agentcore-wildrydes_gateway_role_ab3991f6-role' allows 'bedrock:*' - Role 'AgentCoreEvalsSDK-us-east-1-d04ba7b68b' allows 'bedrock:InvokeModel' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'AgentCoreEvalsSDK-us-east-1-d04ba7b68b' allows 'bedrock:InvokeModelWithResponseStream' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'Agentic-AI-MCP-Strands-SDK-Works-VSCodeInstanceRole-NCTUnlnRBFO6' allows '*' - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:ListGuardrails' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:GetGuardrail' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:ListModelInvocationJobs' on Resource '*' (no ARN scoping to specific Knowledge Bases)

Resolution

Replace wildcard bedrock:* with specific actions such as bedrock:Retrieve, bedrock:RetrieveAndGenerate. Scope resources to specific Knowledge Base ARNs.

Reference

High Failed
111122223333 us-east-2 FS-22
Overly Permissive Knowledge Base IAM Roles
Details and remediation
Details

829 role(s) with wildcard KB permissions: - Role '111122223333-us-east-1-kb-setup-function-role' allows 'bedrock:CreateKnowledgeBase' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role '111122223333-us-east-1-kb-setup-function-role' allows 'bedrock:CreateDataSource' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'Admin' allows '*' - Role 'agentcore-wildrydes_gateway_role_ab3991f6-role' allows 'bedrock:*' - Role 'AgentCoreEvalsSDK-us-east-1-d04ba7b68b' allows 'bedrock:InvokeModel' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'AgentCoreEvalsSDK-us-east-1-d04ba7b68b' allows 'bedrock:InvokeModelWithResponseStream' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'Agentic-AI-MCP-Strands-SDK-Works-VSCodeInstanceRole-NCTUnlnRBFO6' allows '*' - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:ListGuardrails' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:GetGuardrail' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:ListModelInvocationJobs' on Resource '*' (no ARN scoping to specific Knowledge Bases)

Resolution

Replace wildcard bedrock:* with specific actions such as bedrock:Retrieve, bedrock:RetrieveAndGenerate. Scope resources to specific Knowledge Base ARNs.

Reference

High Failed
111122223333 us-west-2 FS-22
Overly Permissive Knowledge Base IAM Roles
Details and remediation
Details

829 role(s) with wildcard KB permissions: - Role '111122223333-us-east-1-kb-setup-function-role' allows 'bedrock:CreateKnowledgeBase' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role '111122223333-us-east-1-kb-setup-function-role' allows 'bedrock:CreateDataSource' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'Admin' allows '*' - Role 'agentcore-wildrydes_gateway_role_ab3991f6-role' allows 'bedrock:*' - Role 'AgentCoreEvalsSDK-us-east-1-d04ba7b68b' allows 'bedrock:InvokeModel' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'AgentCoreEvalsSDK-us-east-1-d04ba7b68b' allows 'bedrock:InvokeModelWithResponseStream' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'Agentic-AI-MCP-Strands-SDK-Works-VSCodeInstanceRole-NCTUnlnRBFO6' allows '*' - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:ListGuardrails' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:GetGuardrail' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:ListModelInvocationJobs' on Resource '*' (no ARN scoping to specific Knowledge Bases)

Resolution

Replace wildcard bedrock:* with specific actions such as bedrock:Retrieve, bedrock:RetrieveAndGenerate. Scope resources to specific Knowledge Base ARNs.

Reference

High Failed
111122223333 us-east-1 FS-24
ADVISORY: Knowledge Base Metadata Filtering — Manual Review Required
Details and remediation
Details

Found 3 Knowledge Base(s). Tenant-isolation metadata filtering is a design pattern that cannot be verified via API — manual review required. Verify that metadata attributes (e.g., tenantId, classification) are indexed and that Retrieve calls include RetrievalFilter conditions for tenant isolation.

Resolution

1. Add metadata fields (tenantId, dataClassification) to KB data sources. 2. Pass RetrievalFilter in all Retrieve/RetrieveAndGenerate calls. 3. Validate filters in integration tests to prevent cross-tenant data leakage.

Reference

Informational N/A
111122223333 us-east-2 FS-24
ADVISORY: Knowledge Base Metadata Filtering — Manual Review Required
Details and remediation
Details

Found 3 Knowledge Base(s). Tenant-isolation metadata filtering is a design pattern that cannot be verified via API — manual review required. Verify that metadata attributes (e.g., tenantId, classification) are indexed and that Retrieve calls include RetrievalFilter conditions for tenant isolation.

Resolution

1. Add metadata fields (tenantId, dataClassification) to KB data sources. 2. Pass RetrievalFilter in all Retrieve/RetrieveAndGenerate calls. 3. Validate filters in integration tests to prevent cross-tenant data leakage.

Reference

Informational N/A
111122223333 us-west-2 FS-24
ADVISORY: Knowledge Base Metadata Filtering — Manual Review Required
Details and remediation
Details

Found 3 Knowledge Base(s). Tenant-isolation metadata filtering is a design pattern that cannot be verified via API — manual review required. Verify that metadata attributes (e.g., tenantId, classification) are indexed and that Retrieve calls include RetrievalFilter conditions for tenant isolation.

Resolution

1. Add metadata fields (tenantId, dataClassification) to KB data sources. 2. Pass RetrievalFilter in all Retrieve/RetrieveAndGenerate calls. 3. Validate filters in integration tests to prevent cross-tenant data leakage.

Reference

Informational N/A
111122223333 us-east-1 FS-25
OpenSearch Serverless Encryption Policies Present
Details and remediation
Details

Found 5 encryption policy(ies); 5 use a customer-managed KMS key.

Resolution

Verify all vector store collections use customer-managed KMS keys.

Reference

High Passed
111122223333 us-east-2 FS-25
OpenSearch Serverless Encryption Policies Present
Details and remediation
Details

Found 5 encryption policy(ies); 5 use a customer-managed KMS key.

Resolution

Verify all vector store collections use customer-managed KMS keys.

Reference

High Passed
111122223333 us-west-2 FS-25
OpenSearch Serverless Encryption Policies Present
Details and remediation
Details

Found 5 encryption policy(ies); 5 use a customer-managed KMS key.

Resolution

Verify all vector store collections use customer-managed KMS keys.

Reference

High Passed
111122223333 us-east-1 FS-26
OpenSearch Serverless Collections Not VPC-Restricted
Details and remediation
Details

Found 5 network policy(ies) but none restrict to VPC. Vector stores may be accessible from the public internet.

Resolution

Update network policies to allow access only from VPC endpoints. Create an OpenSearch Serverless VPC endpoint in your VPC.

Reference

High Failed
111122223333 us-east-2 FS-26
OpenSearch Serverless Collections Not VPC-Restricted
Details and remediation
Details

Found 5 network policy(ies) but none restrict to VPC. Vector stores may be accessible from the public internet.

Resolution

Update network policies to allow access only from VPC endpoints. Create an OpenSearch Serverless VPC endpoint in your VPC.

Reference

High Failed
111122223333 us-west-2 FS-26
OpenSearch Serverless Collections Not VPC-Restricted
Details and remediation
Details

Found 5 network policy(ies) but none restrict to VPC. Vector stores may be accessible from the public internet.

Resolution

Update network policies to allow access only from VPC endpoints. Create an OpenSearch Serverless VPC endpoint in your VPC.

Reference

High Failed
111122223333 us-east-1 FS-27
Contextual Grounding Enabled on Guardrails
Details and remediation
Details

Guardrails with contextual grounding: nist-ai-rmf-guardrail.

Resolution

No action required for contextual grounding. Also consider enabling Automated Reasoning checks for formal policy verification.

Reference

High Passed
111122223333 us-east-2 FS-27
Contextual Grounding Enabled on Guardrails
Details and remediation
Details

Guardrails with contextual grounding: nist-ai-rmf-guardrail.

Resolution

No action required for contextual grounding. Also consider enabling Automated Reasoning checks for formal policy verification.

Reference

High Passed
111122223333 us-west-2 FS-27
Contextual Grounding Enabled on Guardrails
Details and remediation
Details

Guardrails with contextual grounding: nist-ai-rmf-guardrail.

Resolution

No action required for contextual grounding. Also consider enabling Automated Reasoning checks for formal policy verification.

Reference

High Passed
111122223333 us-east-1 FS-27
No Automated Reasoning Policies Found
Details and remediation
Details

No Bedrock Automated Reasoning policies have been created. ARC (GA August 2025) uses formal verification to guarantee that GenAI outputs comply with authored business rules — e.g., loan criteria, regulatory thresholds, policy constraints. Without ARC policies, factual accuracy of outputs is not formally verified, only heuristically filtered by contextual grounding thresholds.

Resolution

1. In the Amazon Bedrock console → Guardrails → Automated Reasoning, create a policy document encoding your FinServ business rules (e.g., eligibility criteria, rate limits, regulatory thresholds). 2. Associate the ARC policy with your guardrail (automatedReasoningPolicy.policies field in CreateGuardrail/UpdateGuardrail). 3. Set confidenceThreshold on the policy to control strictness. 4. ARC requires cross-Region inference — ensure your guardrail has a guardrailProfileArn configured (crossRegionDetails in GetGuardrail response). 5. Reference: AWS Announcement — Automated Reasoning checks GA (August 2025).

Reference

Medium Failed
111122223333 us-east-2 FS-27
No Automated Reasoning Policies Found
Details and remediation
Details

No Bedrock Automated Reasoning policies have been created. ARC (GA August 2025) uses formal verification to guarantee that GenAI outputs comply with authored business rules — e.g., loan criteria, regulatory thresholds, policy constraints. Without ARC policies, factual accuracy of outputs is not formally verified, only heuristically filtered by contextual grounding thresholds.

Resolution

1. In the Amazon Bedrock console → Guardrails → Automated Reasoning, create a policy document encoding your FinServ business rules (e.g., eligibility criteria, rate limits, regulatory thresholds). 2. Associate the ARC policy with your guardrail (automatedReasoningPolicy.policies field in CreateGuardrail/UpdateGuardrail). 3. Set confidenceThreshold on the policy to control strictness. 4. ARC requires cross-Region inference — ensure your guardrail has a guardrailProfileArn configured (crossRegionDetails in GetGuardrail response). 5. Reference: AWS Announcement — Automated Reasoning checks GA (August 2025).

Reference

Medium Failed
111122223333 us-west-2 FS-27
No Automated Reasoning Policies Found
Details and remediation
Details

No Bedrock Automated Reasoning policies have been created. ARC (GA August 2025) uses formal verification to guarantee that GenAI outputs comply with authored business rules — e.g., loan criteria, regulatory thresholds, policy constraints. Without ARC policies, factual accuracy of outputs is not formally verified, only heuristically filtered by contextual grounding thresholds.

Resolution

1. In the Amazon Bedrock console → Guardrails → Automated Reasoning, create a policy document encoding your FinServ business rules (e.g., eligibility criteria, rate limits, regulatory thresholds). 2. Associate the ARC policy with your guardrail (automatedReasoningPolicy.policies field in CreateGuardrail/UpdateGuardrail). 3. Set confidenceThreshold on the policy to control strictness. 4. ARC requires cross-Region inference — ensure your guardrail has a guardrailProfileArn configured (crossRegionDetails in GetGuardrail response). 5. Reference: AWS Announcement — Automated Reasoning checks GA (August 2025).

Reference

Medium Failed
111122223333 us-east-1 FS-28
Denied Topics Configured on CLASSIC Tier
Details and remediation
Details

Guardrails with topic policies: nist-ai-rmf-guardrail. The following use the CLASSIC tier: nist-ai-rmf-guardrail. CLASSIC tier supports English, French, and Spanish only. The STANDARD tier (GA June 2025) provides broader language support and improved detection for denied topics.

Resolution

Verify topics cover regulated financial advice categories. For multilingual FinServ deployments, consider upgrading denied topics to the STANDARD tier (set topicsTierConfig.tierName=STANDARD via UpdateGuardrail; requires a cross-region inference profile on the guardrail). When authoring denied-topic policies, use existing compliance materials as the source: employee policies, training materials, procedure documents, and incident reports (PDF §1.2.1 Practical guidance).

Reference

High Passed
111122223333 us-east-2 FS-28
Denied Topics Configured on CLASSIC Tier
Details and remediation
Details

Guardrails with topic policies: nist-ai-rmf-guardrail. The following use the CLASSIC tier: nist-ai-rmf-guardrail. CLASSIC tier supports English, French, and Spanish only. The STANDARD tier (GA June 2025) provides broader language support and improved detection for denied topics.

Resolution

Verify topics cover regulated financial advice categories. For multilingual FinServ deployments, consider upgrading denied topics to the STANDARD tier (set topicsTierConfig.tierName=STANDARD via UpdateGuardrail; requires a cross-region inference profile on the guardrail). When authoring denied-topic policies, use existing compliance materials as the source: employee policies, training materials, procedure documents, and incident reports (PDF §1.2.1 Practical guidance).

Reference

High Passed
111122223333 us-west-2 FS-28
Denied Topics Configured on CLASSIC Tier
Details and remediation
Details

Guardrails with topic policies: nist-ai-rmf-guardrail. The following use the CLASSIC tier: nist-ai-rmf-guardrail. CLASSIC tier supports English, French, and Spanish only. The STANDARD tier (GA June 2025) provides broader language support and improved detection for denied topics.

Resolution

Verify topics cover regulated financial advice categories. For multilingual FinServ deployments, consider upgrading denied topics to the STANDARD tier (set topicsTierConfig.tierName=STANDARD via UpdateGuardrail; requires a cross-region inference profile on the guardrail). When authoring denied-topic policies, use existing compliance materials as the source: employee policies, training materials, procedure documents, and incident reports (PDF §1.2.1 Practical guidance).

Reference

High Passed
111122223333 us-east-1 FS-29
ADVISORY: Compliance Disclaimer — Manual Review Required
Details and remediation
Details

Application-level compliance disclaimers cannot be verified via AWS APIs. Manual review required to confirm GenAI outputs include required regulatory disclosures.

Resolution

1. Implement post-processing to append required disclaimers to GenAI outputs. 2. Use Bedrock Guardrails word filters to block outputs that omit required disclosures. 3. Document disclaimer requirements in the AI use case register. 4. Test disclaimer presence in QA/UAT before production deployment.

Reference

Informational N/A
111122223333 us-east-2 FS-29
ADVISORY: Compliance Disclaimer — Manual Review Required
Details and remediation
Details

Application-level compliance disclaimers cannot be verified via AWS APIs. Manual review required to confirm GenAI outputs include required regulatory disclosures.

Resolution

1. Implement post-processing to append required disclaimers to GenAI outputs. 2. Use Bedrock Guardrails word filters to block outputs that omit required disclosures. 3. Document disclaimer requirements in the AI use case register. 4. Test disclaimer presence in QA/UAT before production deployment.

Reference

Informational N/A
111122223333 us-west-2 FS-29
ADVISORY: Compliance Disclaimer — Manual Review Required
Details and remediation
Details

Application-level compliance disclaimers cannot be verified via AWS APIs. Manual review required to confirm GenAI outputs include required regulatory disclosures.

Resolution

1. Implement post-processing to append required disclaimers to GenAI outputs. 2. Use Bedrock Guardrails word filters to block outputs that omit required disclosures. 3. Document disclaimer requirements in the AI use case register. 4. Test disclaimer presence in QA/UAT before production deployment.

Reference

Informational N/A
111122223333 us-east-1 FS-30
ADVISORY: Compliance Dataset Coverage — Manual Review Required
Details and remediation
Details

Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation jobs include compliance-specific datasets (fair lending/ECOA, Fair Housing Act, UDAP/UDAAP, AML/KYC edge cases). Whether any evaluation jobs exist at all is assessed by FS-15.

Resolution

Run Bedrock Model Evaluation with compliance-specific datasets: - Fair lending test cases (ECOA, Fair Housing Act) - UDAP/UDAAP unfair/deceptive practice scenarios - AML/KYC edge cases

Reference

Informational N/A
111122223333 us-east-2 FS-30
ADVISORY: Compliance Dataset Coverage — Manual Review Required
Details and remediation
Details

Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation jobs include compliance-specific datasets (fair lending/ECOA, Fair Housing Act, UDAP/UDAAP, AML/KYC edge cases). Whether any evaluation jobs exist at all is assessed by FS-15.

Resolution

Run Bedrock Model Evaluation with compliance-specific datasets: - Fair lending test cases (ECOA, Fair Housing Act) - UDAP/UDAAP unfair/deceptive practice scenarios - AML/KYC edge cases

Reference

Informational N/A
111122223333 us-west-2 FS-30
ADVISORY: Compliance Dataset Coverage — Manual Review Required
Details and remediation
Details

Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation jobs include compliance-specific datasets (fair lending/ECOA, Fair Housing Act, UDAP/UDAAP, AML/KYC edge cases). Whether any evaluation jobs exist at all is assessed by FS-15.

Resolution

Run Bedrock Model Evaluation with compliance-specific datasets: - Fair lending test cases (ECOA, Fair Housing Act) - UDAP/UDAAP unfair/deceptive practice scenarios - AML/KYC edge cases

Reference

Informational N/A
111122223333 us-east-1 FS-31
Knowledge Base Data Sources Past Review Threshold
Details and remediation
Details

2 data source(s) not synced in >7 days (a configurable review threshold, NOT an AWS-mandated limit): - KB 'knowledge-base-semiconductors' source 'knowledge-base-quick-start-qpvuv-data-source' last synced 731 days ago - KB '111122223333-us-east-1-kb' source '111122223333-us-east-1-kb-datasource' last synced 209 days ago Confirm this age is acceptable for each data source's currency requirement — slow-changing reference data may legitimately sync infrequently.

Resolution

1. Define the maximum acceptable data age per use case (e.g., intraday for market data, daily for product terms, weekly/monthly for regulatory guidance) and adjust the review threshold to match. 2. Configure automated sync (EventBridge Scheduler → StartIngestionJob) at that cadence — see FS-61. 3. Set CloudWatch alarms on sync job failures.

Reference

Medium Failed
111122223333 us-east-2 FS-31
Knowledge Base Data Sources Past Review Threshold
Details and remediation
Details

2 data source(s) not synced in >7 days (a configurable review threshold, NOT an AWS-mandated limit): - KB 'knowledge-base-semiconductors' source 'knowledge-base-quick-start-qpvuv-data-source' last synced 731 days ago - KB '111122223333-us-east-1-kb' source '111122223333-us-east-1-kb-datasource' last synced 209 days ago Confirm this age is acceptable for each data source's currency requirement — slow-changing reference data may legitimately sync infrequently.

Resolution

1. Define the maximum acceptable data age per use case (e.g., intraday for market data, daily for product terms, weekly/monthly for regulatory guidance) and adjust the review threshold to match. 2. Configure automated sync (EventBridge Scheduler → StartIngestionJob) at that cadence — see FS-61. 3. Set CloudWatch alarms on sync job failures.

Reference

Medium Failed
111122223333 us-west-2 FS-31
Knowledge Base Data Sources Past Review Threshold
Details and remediation
Details

2 data source(s) not synced in >7 days (a configurable review threshold, NOT an AWS-mandated limit): - KB 'knowledge-base-semiconductors' source 'knowledge-base-quick-start-qpvuv-data-source' last synced 731 days ago - KB '111122223333-us-east-1-kb' source '111122223333-us-east-1-kb-datasource' last synced 209 days ago Confirm this age is acceptable for each data source's currency requirement — slow-changing reference data may legitimately sync infrequently.

Resolution

1. Define the maximum acceptable data age per use case (e.g., intraday for market data, daily for product terms, weekly/monthly for regulatory guidance) and adjust the review threshold to match. 2. Configure automated sync (EventBridge Scheduler → StartIngestionJob) at that cadence — see FS-61. 3. Set CloudWatch alarms on sync job failures.

Reference

Medium Failed
111122223333 us-east-1 FS-32
ADVISORY: Source Attribution — Manual Review Required
Details and remediation
Details

Source attribution in GenAI responses cannot be verified via AWS APIs. Manual review required to confirm responses include citations.

Resolution

1. Use Bedrock RetrieveAndGenerate with citations enabled. 2. Include source document references in response post-processing. 3. Test citation accuracy in QA before production deployment. 4. Consider Bedrock Guardrails grounding checks to validate response accuracy.

Reference

Informational N/A
111122223333 us-east-2 FS-32
ADVISORY: Source Attribution — Manual Review Required
Details and remediation
Details

Source attribution in GenAI responses cannot be verified via AWS APIs. Manual review required to confirm responses include citations.

Resolution

1. Use Bedrock RetrieveAndGenerate with citations enabled. 2. Include source document references in response post-processing. 3. Test citation accuracy in QA before production deployment. 4. Consider Bedrock Guardrails grounding checks to validate response accuracy.

Reference

Informational N/A
111122223333 us-west-2 FS-32
ADVISORY: Source Attribution — Manual Review Required
Details and remediation
Details

Source attribution in GenAI responses cannot be verified via AWS APIs. Manual review required to confirm responses include citations.

Resolution

1. Use Bedrock RetrieveAndGenerate with citations enabled. 2. Include source document references in response post-processing. 3. Test citation accuracy in QA before production deployment. 4. Consider Bedrock Guardrails grounding checks to validate response accuracy.

Reference

Informational N/A
111122223333 us-east-1 FS-33
KB Data Source Buckets Without Versioning
Details and remediation
Details

KB data source S3 buckets without versioning: 111122223333-us-east-1-kb-data-bucket.

Resolution

Enable S3 versioning on all KB data source buckets. Enable S3 Object Integrity (checksum) for tamper detection.

Reference

Medium Failed
111122223333 us-east-2 FS-33
KB Data Source Buckets Without Versioning
Details and remediation
Details

KB data source S3 buckets without versioning: 111122223333-us-east-1-kb-data-bucket.

Resolution

Enable S3 versioning on all KB data source buckets. Enable S3 Object Integrity (checksum) for tamper detection.

Reference

Medium Failed
111122223333 us-west-2 FS-33
KB Data Source Buckets Without Versioning
Details and remediation
Details

KB data source S3 buckets without versioning: 111122223333-us-east-1-kb-data-bucket.

Resolution

Enable S3 versioning on all KB data source buckets. Enable S3 Object Integrity (checksum) for tamper detection.

Reference

Medium Failed
111122223333 us-east-1 FS-34
Legacy Foundation Models Available in Region
Details and remediation
Details

Legacy/deprecated foundation models are available in this account/region: anthropic.claude-sonnet-4-20250514-v1:0, twelvelabs.marengo-embed-2-7-v1:0, anthropic.claude-opus-4-1-20250805-v1:0, amazon.nova-premier-v1:0:8k, amazon.nova-premier-v1:0:20k, amazon.nova-premier-v1:0:1000k, amazon.nova-premier-v1:0:mm, amazon.nova-premier-v1:0, amazon.nova-canvas-v1:0, amazon.nova-reel-v1:0. This API reports model *availability*, not actual usage — it cannot determine which models your applications invoke. Legacy models have older training-data cutoffs and may produce outdated information if used. Review whether any are in active use.

Resolution

1. Identify which (if any) of these legacy models your applications invoke (e.g., via CloudTrail InvokeModel events or application config). 2. Migrate active usage to current model versions. 3. Document training-data cutoff dates for all models in use. 4. Add data-currency disclaimers to outputs from models with old cutoffs.

Reference

Informational N/A
111122223333 us-east-2 FS-34
Legacy Foundation Models Available in Region
Details and remediation
Details

Legacy/deprecated foundation models are available in this account/region: anthropic.claude-sonnet-4-20250514-v1:0, twelvelabs.marengo-embed-2-7-v1:0, anthropic.claude-opus-4-1-20250805-v1:0, amazon.nova-premier-v1:0:8k, amazon.nova-premier-v1:0:20k, amazon.nova-premier-v1:0:1000k, amazon.nova-premier-v1:0:mm, amazon.nova-premier-v1:0, amazon.nova-canvas-v1:0, amazon.nova-reel-v1:0. This API reports model *availability*, not actual usage — it cannot determine which models your applications invoke. Legacy models have older training-data cutoffs and may produce outdated information if used. Review whether any are in active use.

Resolution

1. Identify which (if any) of these legacy models your applications invoke (e.g., via CloudTrail InvokeModel events or application config). 2. Migrate active usage to current model versions. 3. Document training-data cutoff dates for all models in use. 4. Add data-currency disclaimers to outputs from models with old cutoffs.

Reference

Informational N/A
111122223333 us-west-2 FS-34
Legacy Foundation Models Available in Region
Details and remediation
Details

Legacy/deprecated foundation models are available in this account/region: anthropic.claude-sonnet-4-20250514-v1:0, twelvelabs.marengo-embed-2-7-v1:0, anthropic.claude-opus-4-1-20250805-v1:0, amazon.nova-premier-v1:0:8k, amazon.nova-premier-v1:0:20k, amazon.nova-premier-v1:0:1000k, amazon.nova-premier-v1:0:mm, amazon.nova-premier-v1:0, amazon.nova-canvas-v1:0, amazon.nova-reel-v1:0. This API reports model *availability*, not actual usage — it cannot determine which models your applications invoke. Legacy models have older training-data cutoffs and may produce outdated information if used. Review whether any are in active use.

Resolution

1. Identify which (if any) of these legacy models your applications invoke (e.g., via CloudTrail InvokeModel events or application config). 2. Migrate active usage to current model versions. 3. Document training-data cutoff dates for all models in use. 4. Add data-currency disclaimers to outputs from models with old cutoffs.

Reference

Informational N/A
111122223333 us-east-1 FS-35
ADVISORY: Harmful-Content Test Coverage — Manual Review Required
Details and remediation
Details

Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation/FMEval jobs include harmful-content datasets (toxicity, hate speech, violence/self-harm). Whether any evaluation jobs exist at all is assessed by FS-15.

Resolution

Run Bedrock Model Evaluation or FMEval with harmful content datasets: - Toxicity detection - Hate speech classification - Violence/self-harm content

Reference

Informational N/A
111122223333 us-east-2 FS-35
ADVISORY: Harmful-Content Test Coverage — Manual Review Required
Details and remediation
Details

Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation/FMEval jobs include harmful-content datasets (toxicity, hate speech, violence/self-harm). Whether any evaluation jobs exist at all is assessed by FS-15.

Resolution

Run Bedrock Model Evaluation or FMEval with harmful content datasets: - Toxicity detection - Hate speech classification - Violence/self-harm content

Reference

Informational N/A
111122223333 us-west-2 FS-35
ADVISORY: Harmful-Content Test Coverage — Manual Review Required
Details and remediation
Details

Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation/FMEval jobs include harmful-content datasets (toxicity, hate speech, violence/self-harm). Whether any evaluation jobs exist at all is assessed by FS-15.

Resolution

Run Bedrock Model Evaluation or FMEval with harmful content datasets: - Toxicity detection - Hate speech classification - Violence/self-harm content

Reference

Informational N/A
111122223333 us-east-1 FS-36
Guardrail Content Filters on CLASSIC Tier
Details and remediation
Details

Guardrails with content filters: nist-ai-rmf-guardrail. The following use the CLASSIC tier: nist-ai-rmf-guardrail. CLASSIC tier supports English, French, and Spanish only. The STANDARD tier (GA June 2025) provides improved contextual understanding, typographical error detection, 60+ language support, and better prompt-attack classification (distinguishes jailbreaks from prompt injection).

Resolution

Consider upgrading to STANDARD tier content filters for FinServ workloads that handle multiple languages or require higher detection accuracy. STANDARD tier requires cross-region inference (crossRegionDetails.guardrailProfileArn on the guardrail). To upgrade: update the guardrail's contentPolicy.filtersConfig.contentFiltersTierConfig with tierName=STANDARD and configure a guardrail cross-region profile.

Reference

High Passed
111122223333 us-east-2 FS-36
Guardrail Content Filters on CLASSIC Tier
Details and remediation
Details

Guardrails with content filters: nist-ai-rmf-guardrail. The following use the CLASSIC tier: nist-ai-rmf-guardrail. CLASSIC tier supports English, French, and Spanish only. The STANDARD tier (GA June 2025) provides improved contextual understanding, typographical error detection, 60+ language support, and better prompt-attack classification (distinguishes jailbreaks from prompt injection).

Resolution

Consider upgrading to STANDARD tier content filters for FinServ workloads that handle multiple languages or require higher detection accuracy. STANDARD tier requires cross-region inference (crossRegionDetails.guardrailProfileArn on the guardrail). To upgrade: update the guardrail's contentPolicy.filtersConfig.contentFiltersTierConfig with tierName=STANDARD and configure a guardrail cross-region profile.

Reference

High Passed
111122223333 us-west-2 FS-36
Guardrail Content Filters on CLASSIC Tier
Details and remediation
Details

Guardrails with content filters: nist-ai-rmf-guardrail. The following use the CLASSIC tier: nist-ai-rmf-guardrail. CLASSIC tier supports English, French, and Spanish only. The STANDARD tier (GA June 2025) provides improved contextual understanding, typographical error detection, 60+ language support, and better prompt-attack classification (distinguishes jailbreaks from prompt injection).

Resolution

Consider upgrading to STANDARD tier content filters for FinServ workloads that handle multiple languages or require higher detection accuracy. STANDARD tier requires cross-region inference (crossRegionDetails.guardrailProfileArn on the guardrail). To upgrade: update the guardrail's contentPolicy.filtersConfig.contentFiltersTierConfig with tierName=STANDARD and configure a guardrail cross-region profile.

Reference

High Passed
111122223333 us-east-1 FS-37
ADVISORY: User Feedback Mechanism — Manual Review Required
Details and remediation
Details

User feedback mechanisms for harmful outputs cannot be verified via AWS APIs. Manual review required.

Resolution

1. Implement thumbs-up/down or flag-for-review UI in GenAI applications. 2. Route flagged outputs to human reviewers via SQS/SNS. 3. Log feedback to DynamoDB/S3 for model improvement. 4. Define SLAs for reviewing flagged content.

Reference

Informational N/A
111122223333 us-east-2 FS-37
ADVISORY: User Feedback Mechanism — Manual Review Required
Details and remediation
Details

User feedback mechanisms for harmful outputs cannot be verified via AWS APIs. Manual review required.

Resolution

1. Implement thumbs-up/down or flag-for-review UI in GenAI applications. 2. Route flagged outputs to human reviewers via SQS/SNS. 3. Log feedback to DynamoDB/S3 for model improvement. 4. Define SLAs for reviewing flagged content.

Reference

Informational N/A
111122223333 us-west-2 FS-37
ADVISORY: User Feedback Mechanism — Manual Review Required
Details and remediation
Details

User feedback mechanisms for harmful outputs cannot be verified via AWS APIs. Manual review required.

Resolution

1. Implement thumbs-up/down or flag-for-review UI in GenAI applications. 2. Route flagged outputs to human reviewers via SQS/SNS. 3. Log feedback to DynamoDB/S3 for model improvement. 4. Define SLAs for reviewing flagged content.

Reference

Informational N/A
111122223333 us-east-1 FS-38
No Guardrails With Word Filters
Details and remediation
Details

Found 1 guardrail(s) but none have word/phrase filters. Profanity and prohibited financial terms may appear in outputs.

Resolution

Add word filters to guardrails: - Enable AWS managed profanity list - Add custom denylist for prohibited financial terms - Add allowlist for required regulatory language

Reference

Medium Failed
111122223333 us-east-2 FS-38
No Guardrails With Word Filters
Details and remediation
Details

Found 1 guardrail(s) but none have word/phrase filters. Profanity and prohibited financial terms may appear in outputs.

Resolution

Add word filters to guardrails: - Enable AWS managed profanity list - Add custom denylist for prohibited financial terms - Add allowlist for required regulatory language

Reference

Medium Failed
111122223333 us-west-2 FS-38
No Guardrails With Word Filters
Details and remediation
Details

Found 1 guardrail(s) but none have word/phrase filters. Profanity and prohibited financial terms may appear in outputs.

Resolution

Add word filters to guardrails: - Enable AWS managed profanity list - Add custom denylist for prohibited financial terms - Add allowlist for required regulatory language

Reference

Medium Failed
111122223333 us-east-1 FS-39
No SageMaker Clarify Bias Monitoring
Details and remediation
Details

No SageMaker Clarify model bias monitoring schedules found. Models making financial decisions (credit, insurance) may exhibit discriminatory bias without detection.

Resolution

1. Configure SageMaker Clarify bias detection for all models making credit, insurance, or employment decisions. 2. Define protected attributes (age, gender, race proxies). 3. Set bias metric thresholds and alert on violations. 4. Document bias testing results for regulatory examination.

Reference

High Failed
111122223333 us-east-2 FS-39
No SageMaker Clarify Bias Monitoring
Details and remediation
Details

No SageMaker Clarify model bias monitoring schedules found. Models making financial decisions (credit, insurance) may exhibit discriminatory bias without detection.

Resolution

1. Configure SageMaker Clarify bias detection for all models making credit, insurance, or employment decisions. 2. Define protected attributes (age, gender, race proxies). 3. Set bias metric thresholds and alert on violations. 4. Document bias testing results for regulatory examination.

Reference

High Failed
111122223333 us-west-2 FS-39
No SageMaker Clarify Bias Monitoring
Details and remediation
Details

No SageMaker Clarify model bias monitoring schedules found. Models making financial decisions (credit, insurance) may exhibit discriminatory bias without detection.

Resolution

1. Configure SageMaker Clarify bias detection for all models making credit, insurance, or employment decisions. 2. Define protected attributes (age, gender, race proxies). 3. Set bias metric thresholds and alert on violations. 4. Document bias testing results for regulatory examination.

Reference

High Failed
111122223333 us-east-1 FS-40
ADVISORY: Bias Dataset Coverage — Manual Review Required
Details and remediation
Details

Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation jobs include bias/fairness datasets (demographic parity, equal-opportunity, counterfactual fairness) for any GenAI models used in financial decisions (ECOA/Fair Housing). Whether any evaluation jobs exist at all is assessed by FS-15.

Resolution

Run Bedrock Model Evaluation with bias test datasets: - Demographic parity test cases - Equal opportunity scenarios - Counterfactual fairness tests

Reference

Informational N/A
111122223333 us-east-2 FS-40
ADVISORY: Bias Dataset Coverage — Manual Review Required
Details and remediation
Details

Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation jobs include bias/fairness datasets (demographic parity, equal-opportunity, counterfactual fairness) for any GenAI models used in financial decisions (ECOA/Fair Housing). Whether any evaluation jobs exist at all is assessed by FS-15.

Resolution

Run Bedrock Model Evaluation with bias test datasets: - Demographic parity test cases - Equal opportunity scenarios - Counterfactual fairness tests

Reference

Informational N/A
111122223333 us-west-2 FS-40
ADVISORY: Bias Dataset Coverage — Manual Review Required
Details and remediation
Details

Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation jobs include bias/fairness datasets (demographic parity, equal-opportunity, counterfactual fairness) for any GenAI models used in financial decisions (ECOA/Fair Housing). Whether any evaluation jobs exist at all is assessed by FS-15.

Resolution

Run Bedrock Model Evaluation with bias test datasets: - Demographic parity test cases - Equal opportunity scenarios - Counterfactual fairness tests

Reference

Informational N/A
111122223333 us-east-1 FS-41
No SageMaker Clarify Explainability Monitoring
Details and remediation
Details

No SageMaker Clarify explainability monitoring found. Models making adverse financial decisions may not provide required explanations (ECOA adverse action notices).

Resolution

1. Configure SageMaker Clarify explainability for credit/lending models. 2. Generate SHAP values for feature importance. 3. Map top features to human-readable adverse action reason codes. 4. Store explanations for regulatory examination.

Reference

High Failed
111122223333 us-east-2 FS-41
No SageMaker Clarify Explainability Monitoring
Details and remediation
Details

No SageMaker Clarify explainability monitoring found. Models making adverse financial decisions may not provide required explanations (ECOA adverse action notices).

Resolution

1. Configure SageMaker Clarify explainability for credit/lending models. 2. Generate SHAP values for feature importance. 3. Map top features to human-readable adverse action reason codes. 4. Store explanations for regulatory examination.

Reference

High Failed
111122223333 us-west-2 FS-41
No SageMaker Clarify Explainability Monitoring
Details and remediation
Details

No SageMaker Clarify explainability monitoring found. Models making adverse financial decisions may not provide required explanations (ECOA adverse action notices).

Resolution

1. Configure SageMaker Clarify explainability for credit/lending models. 2. Generate SHAP values for feature importance. 3. Map top features to human-readable adverse action reason codes. 4. Store explanations for regulatory examination.

Reference

High Failed
111122223333 us-east-1 FS-42
No SageMaker Model Cards Found
Details and remediation
Details

No SageMaker Model Cards found. Production AI models lack documented intended use, limitations, and bias evaluations.

Resolution

1. Create SageMaker Model Cards for all production models. 2. Document: intended use, out-of-scope uses, training data, bias evaluations. 3. Include regulatory compliance attestations. 4. Review and update cards at each model version release.

Reference

Medium Failed
111122223333 us-east-2 FS-42
No SageMaker Model Cards Found
Details and remediation
Details

No SageMaker Model Cards found. Production AI models lack documented intended use, limitations, and bias evaluations.

Resolution

1. Create SageMaker Model Cards for all production models. 2. Document: intended use, out-of-scope uses, training data, bias evaluations. 3. Include regulatory compliance attestations. 4. Review and update cards at each model version release.

Reference

Medium Failed
111122223333 us-west-2 FS-42
No SageMaker Model Cards Found
Details and remediation
Details

No SageMaker Model Cards found. Production AI models lack documented intended use, limitations, and bias evaluations.

Resolution

1. Create SageMaker Model Cards for all production models. 2. Document: intended use, out-of-scope uses, training data, bias evaluations. 3. Include regulatory compliance attestations. 4. Review and update cards at each model version release.

Reference

Medium Failed
111122223333 us-east-1 FS-43
No CloudWatch Logs Data Protection Policies
Details and remediation
Details

No CloudWatch Logs data protection policies found. PII (SSN, account numbers, credit card numbers) in Bedrock invocation logs may be stored in plaintext.

Resolution

1. Create CloudWatch Logs data protection policies to mask PII. 2. Enable masking for: SSN, credit card numbers, bank account numbers, email. 3. Apply policies to Bedrock invocation log groups. 4. Test masking with synthetic PII before production deployment.

Reference

High Failed
111122223333 us-east-2 FS-43
No CloudWatch Logs Data Protection Policies
Details and remediation
Details

No CloudWatch Logs data protection policies found. PII (SSN, account numbers, credit card numbers) in Bedrock invocation logs may be stored in plaintext.

Resolution

1. Create CloudWatch Logs data protection policies to mask PII. 2. Enable masking for: SSN, credit card numbers, bank account numbers, email. 3. Apply policies to Bedrock invocation log groups. 4. Test masking with synthetic PII before production deployment.

Reference

High Failed
111122223333 us-west-2 FS-43
No CloudWatch Logs Data Protection Policies
Details and remediation
Details

No CloudWatch Logs data protection policies found. PII (SSN, account numbers, credit card numbers) in Bedrock invocation logs may be stored in plaintext.

Resolution

1. Create CloudWatch Logs data protection policies to mask PII. 2. Enable masking for: SSN, credit card numbers, bank account numbers, email. 3. Apply policies to Bedrock invocation log groups. 4. Test masking with synthetic PII before production deployment.

Reference

High Failed
111122223333 us-east-1 FS-44
Amazon Macie Enabled
Details and remediation
Details

Amazon Macie is enabled and scanning S3 buckets.

Resolution

Verify Macie jobs cover training data and KB data source buckets.

Reference

High Passed
111122223333 us-east-2 FS-44
Amazon Macie Enabled
Details and remediation
Details

Amazon Macie is enabled and scanning S3 buckets.

Resolution

Verify Macie jobs cover training data and KB data source buckets.

Reference

High Passed
111122223333 us-west-2 FS-44
Amazon Macie Enabled
Details and remediation
Details

Amazon Macie is enabled and scanning S3 buckets.

Resolution

Verify Macie jobs cover training data and KB data source buckets.

Reference

High Passed
111122223333 us-east-1 FS-45
Guardrail PII Filters Configured
Details and remediation
Details

Guardrails with PII filters: nist-ai-rmf-guardrail.

Resolution

No action required.

Reference

High Passed
111122223333 us-east-2 FS-45
Guardrail PII Filters Configured
Details and remediation
Details

Guardrails with PII filters: nist-ai-rmf-guardrail.

Resolution

No action required.

Reference

High Passed
111122223333 us-west-2 FS-45
Guardrail PII Filters Configured
Details and remediation
Details

Guardrails with PII filters: nist-ai-rmf-guardrail.

Resolution

No action required.

Reference

High Passed
111122223333 us-east-1 FS-46
AI/ML Buckets Without Data Classification Tags
Details and remediation
Details

18 AI/ML bucket(s) without data-classification tags: 111122223333-us-east-1-kb-data-bucket, ancbedrocklogging, ancknowledgebase, aws-streaming-data-solut-outputaccesslogsbucket8b-1o7m0kb4bafm4, bedrock-agentcore-codebuild-sources-111122223333-us-east-1, bedrock-bda-us-east-1-dda43109-6557-48bb-993d-3f97126b64b4, bedrock-bda-us-east-1-logging-00719114-debd-4487-85d1-09cbc3fc8, bedrock-kb-bucket-f736570b, bedrock-video-generation-us-east-1-h5ltpm, create-customer-resources-kb-bucket-111122223333.

Resolution

Tag all AI/ML data buckets with 'data-classification' key. Values: Public, Internal, Confidential, Restricted. Enforce via SCP or AWS Config rule.

Reference

Medium Failed
111122223333 us-east-2 FS-46
AI/ML Buckets Without Data Classification Tags
Details and remediation
Details

18 AI/ML bucket(s) without data-classification tags: 111122223333-us-east-1-kb-data-bucket, ancbedrocklogging, ancknowledgebase, aws-streaming-data-solut-outputaccesslogsbucket8b-1o7m0kb4bafm4, bedrock-agentcore-codebuild-sources-111122223333-us-east-1, bedrock-bda-us-east-1-dda43109-6557-48bb-993d-3f97126b64b4, bedrock-bda-us-east-1-logging-00719114-debd-4487-85d1-09cbc3fc8, bedrock-kb-bucket-f736570b, bedrock-video-generation-us-east-1-h5ltpm, create-customer-resources-kb-bucket-111122223333.

Resolution

Tag all AI/ML data buckets with 'data-classification' key. Values: Public, Internal, Confidential, Restricted. Enforce via SCP or AWS Config rule.

Reference

Medium Failed
111122223333 us-west-2 FS-46
AI/ML Buckets Without Data Classification Tags
Details and remediation
Details

18 AI/ML bucket(s) without data-classification tags: 111122223333-us-east-1-kb-data-bucket, ancbedrocklogging, ancknowledgebase, aws-streaming-data-solut-outputaccesslogsbucket8b-1o7m0kb4bafm4, bedrock-agentcore-codebuild-sources-111122223333-us-east-1, bedrock-bda-us-east-1-dda43109-6557-48bb-993d-3f97126b64b4, bedrock-bda-us-east-1-logging-00719114-debd-4487-85d1-09cbc3fc8, bedrock-kb-bucket-f736570b, bedrock-video-generation-us-east-1-h5ltpm, create-customer-resources-kb-bucket-111122223333.

Resolution

Tag all AI/ML data buckets with 'data-classification' key. Values: Public, Internal, Confidential, Restricted. Enforce via SCP or AWS Config rule.

Reference

Medium Failed
111122223333 us-east-1 FS-47
Guardrail Grounding Thresholds Appropriate
Details and remediation
Details

All 1 guardrail(s) with a GROUNDING filter have thresholds ≥0.7.

Resolution

No action required.

Reference

High Passed
111122223333 us-east-2 FS-47
Guardrail Grounding Thresholds Appropriate
Details and remediation
Details

All 1 guardrail(s) with a GROUNDING filter have thresholds ≥0.7.

Resolution

No action required.

Reference

High Passed
111122223333 us-west-2 FS-47
Guardrail Grounding Thresholds Appropriate
Details and remediation
Details

All 1 guardrail(s) with a GROUNDING filter have thresholds ≥0.7.

Resolution

No action required.

Reference

High Passed
111122223333 us-east-1 FS-48
Active Knowledge Bases for RAG Present
Details and remediation
Details

Found 3 active Knowledge Base(s) for RAG grounding.

Resolution

No action required.

Reference

Medium Passed
111122223333 us-east-2 FS-48
Active Knowledge Bases for RAG Present
Details and remediation
Details

Found 3 active Knowledge Base(s) for RAG grounding.

Resolution

No action required.

Reference

Medium Passed
111122223333 us-west-2 FS-48
Active Knowledge Bases for RAG Present
Details and remediation
Details

Found 3 active Knowledge Base(s) for RAG grounding.

Resolution

No action required.

Reference

Medium Passed
111122223333 us-east-1 FS-49
ADVISORY: Hallucination Disclaimer — Manual Review Required
Details and remediation
Details

Application-level hallucination disclaimers cannot be verified via AWS APIs. Manual review required.

Resolution

1. Add disclaimers to GenAI outputs: 'AI-generated content may contain errors. Verify with authoritative sources before acting.' 2. Implement post-processing to append disclaimers. 3. Test disclaimer presence in QA before production.

Reference

Informational N/A
111122223333 us-east-2 FS-49
ADVISORY: Hallucination Disclaimer — Manual Review Required
Details and remediation
Details

Application-level hallucination disclaimers cannot be verified via AWS APIs. Manual review required.

Resolution

1. Add disclaimers to GenAI outputs: 'AI-generated content may contain errors. Verify with authoritative sources before acting.' 2. Implement post-processing to append disclaimers. 3. Test disclaimer presence in QA before production.

Reference

Informational N/A
111122223333 us-west-2 FS-49
ADVISORY: Hallucination Disclaimer — Manual Review Required
Details and remediation
Details

Application-level hallucination disclaimers cannot be verified via AWS APIs. Manual review required.

Resolution

1. Add disclaimers to GenAI outputs: 'AI-generated content may contain errors. Verify with authoritative sources before acting.' 2. Implement post-processing to append disclaimers. 3. Test disclaimer presence in QA before production.

Reference

Informational N/A
111122223333 us-east-1 FS-50
Relevance Grounding Filters Present
Details and remediation
Details

Guardrails with RELEVANCE grounding filters: nist-ai-rmf-guardrail.

Resolution

No action required.

Reference

Medium Passed
111122223333 us-east-2 FS-50
Relevance Grounding Filters Present
Details and remediation
Details

Guardrails with RELEVANCE grounding filters: nist-ai-rmf-guardrail.

Resolution

No action required.

Reference

Medium Passed
111122223333 us-west-2 FS-50
Relevance Grounding Filters Present
Details and remediation
Details

Guardrails with RELEVANCE grounding filters: nist-ai-rmf-guardrail.

Resolution

No action required.

Reference

Medium Passed
111122223333 us-east-1 FS-51
No Guardrails With Prompt Attack Filters
Details and remediation
Details

Found 1 guardrail(s) but none have PROMPT_ATTACK filters. Prompt injection attacks may bypass system prompts and access controls.

Resolution

1. Enable PROMPT_ATTACK content filter in Bedrock Guardrails. 2. Set input filter strength to HIGH. 3. Use input tags (<amazon-bedrock-guardrails-guardContent_xyz>) to differentiate user inputs from developer-provided prompts — required for PROMPT_ATTACK filters to work correctly with InvokeModel/InvokeModelWithResponseStream. 4. Consider STANDARD tier (GA June 2025) for better jailbreak vs. injection classification and broader language support. 5. Implement application-level input sanitization as defense-in-depth.

Reference

High Failed
111122223333 us-east-2 FS-51
No Guardrails With Prompt Attack Filters
Details and remediation
Details

Found 1 guardrail(s) but none have PROMPT_ATTACK filters. Prompt injection attacks may bypass system prompts and access controls.

Resolution

1. Enable PROMPT_ATTACK content filter in Bedrock Guardrails. 2. Set input filter strength to HIGH. 3. Use input tags (<amazon-bedrock-guardrails-guardContent_xyz>) to differentiate user inputs from developer-provided prompts — required for PROMPT_ATTACK filters to work correctly with InvokeModel/InvokeModelWithResponseStream. 4. Consider STANDARD tier (GA June 2025) for better jailbreak vs. injection classification and broader language support. 5. Implement application-level input sanitization as defense-in-depth.

Reference

High Failed
111122223333 us-west-2 FS-51
No Guardrails With Prompt Attack Filters
Details and remediation
Details

Found 1 guardrail(s) but none have PROMPT_ATTACK filters. Prompt injection attacks may bypass system prompts and access controls.

Resolution

1. Enable PROMPT_ATTACK content filter in Bedrock Guardrails. 2. Set input filter strength to HIGH. 3. Use input tags (<amazon-bedrock-guardrails-guardContent_xyz>) to differentiate user inputs from developer-provided prompts — required for PROMPT_ATTACK filters to work correctly with InvokeModel/InvokeModelWithResponseStream. 4. Consider STANDARD tier (GA June 2025) for better jailbreak vs. injection classification and broader language support. 5. Implement application-level input sanitization as defense-in-depth.

Reference

High Failed
111122223333 us-east-1 FS-52
Bedrock Lambda Functions on Deprecated Runtimes
Details and remediation
Details

Functions on deprecated runtimes: e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk, e2ebedrockrag-OSSInfraSta-OSSIndexCreationProvider-g56en9UzRjII. Deprecated runtimes may use outdated boto3/SDK versions lacking security patches.

Resolution

1. Upgrade Lambda functions to a supported runtime — Python 3.12+, Node.js 22.x or 24.x, Java 21+, or .NET 8+. 2. Update boto3 to the latest version in Lambda layers (pin the version in requirements.txt and redeploy). 3. Enable Lambda runtime management controls for automatic minor-version updates (runtimeManagementConfig.updateRuntimeOn = 'Auto'). 4. Refer to https://docs.aws.amazon.com/lambda/latest/dg/lambda-runtimes.html for the authoritative list of supported and deprecated runtimes.

Reference

Medium Failed
111122223333 us-east-2 FS-52
Bedrock Lambda Functions on Deprecated Runtimes
Details and remediation
Details

Functions on deprecated runtimes: e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk, e2ebedrockrag-OSSInfraSta-OSSIndexCreationProvider-g56en9UzRjII. Deprecated runtimes may use outdated boto3/SDK versions lacking security patches.

Resolution

1. Upgrade Lambda functions to a supported runtime — Python 3.12+, Node.js 22.x or 24.x, Java 21+, or .NET 8+. 2. Update boto3 to the latest version in Lambda layers (pin the version in requirements.txt and redeploy). 3. Enable Lambda runtime management controls for automatic minor-version updates (runtimeManagementConfig.updateRuntimeOn = 'Auto'). 4. Refer to https://docs.aws.amazon.com/lambda/latest/dg/lambda-runtimes.html for the authoritative list of supported and deprecated runtimes.

Reference

Medium Failed
111122223333 us-west-2 FS-52
Bedrock Lambda Functions on Deprecated Runtimes
Details and remediation
Details

Functions on deprecated runtimes: e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk, e2ebedrockrag-OSSInfraSta-OSSIndexCreationProvider-g56en9UzRjII. Deprecated runtimes may use outdated boto3/SDK versions lacking security patches.

Resolution

1. Upgrade Lambda functions to a supported runtime — Python 3.12+, Node.js 22.x or 24.x, Java 21+, or .NET 8+. 2. Update boto3 to the latest version in Lambda layers (pin the version in requirements.txt and redeploy). 3. Enable Lambda runtime management controls for automatic minor-version updates (runtimeManagementConfig.updateRuntimeOn = 'Auto'). 4. Refer to https://docs.aws.amazon.com/lambda/latest/dg/lambda-runtimes.html for the authoritative list of supported and deprecated runtimes.

Reference

Medium Failed
111122223333 us-east-1 FS-53
No WAF Web ACLs — Injection Rules Not Applicable
Details and remediation
Details

No regional WAF Web ACLs found.

Resolution

Create WAF Web ACLs with injection protection rules (see FS-01).

Reference

Informational N/A
111122223333 us-east-2 FS-53
No WAF Web ACLs — Injection Rules Not Applicable
Details and remediation
Details

No regional WAF Web ACLs found.

Resolution

Create WAF Web ACLs with injection protection rules (see FS-01).

Reference

Informational N/A
111122223333 us-west-2 FS-53
No WAF Web ACLs — Injection Rules Not Applicable
Details and remediation
Details

No regional WAF Web ACLs found.

Resolution

Create WAF Web ACLs with injection protection rules (see FS-01).

Reference

Informational N/A
111122223333 us-east-1 FS-54
ADVISORY: Penetration Testing — Manual Review Required
Details and remediation
Details

Penetration testing evidence cannot be verified via AWS APIs. Manual review required to confirm GenAI applications have been tested.

Resolution

1. Conduct penetration testing of GenAI applications at least annually and before major releases. 2. Include AI-specific test cases: prompt injection, jailbreak, indirect (cross-domain) injection, system-prompt leakage, and data-extraction attempts. 3. Consider AWS Security Agent for on-demand, AI-driven penetration testing (GA March 2026; available in US East N. Virginia, US West Oregon, Europe Ireland, Europe Frankfurt, Asia Pacific Sydney, Asia Pacific Tokyo, with cross-account shared-VPC testing via AWS RAM). Open-source tools such as Garak or PyRIT and manual red-teaming are complementary options. Verify current regional availability on the AWS Security Agent page before relying on it. 4. Document findings and remediation for regulatory examination, and tag tested resources with a last-pentest-date for audit trail. 5. For DORA compliance, include GenAI in TLPT (Threat-Led Penetration Testing) scope.

Reference

Informational N/A
111122223333 us-east-2 FS-54
ADVISORY: Penetration Testing — Manual Review Required
Details and remediation
Details

Penetration testing evidence cannot be verified via AWS APIs. Manual review required to confirm GenAI applications have been tested.

Resolution

1. Conduct penetration testing of GenAI applications at least annually and before major releases. 2. Include AI-specific test cases: prompt injection, jailbreak, indirect (cross-domain) injection, system-prompt leakage, and data-extraction attempts. 3. Consider AWS Security Agent for on-demand, AI-driven penetration testing (GA March 2026; available in US East N. Virginia, US West Oregon, Europe Ireland, Europe Frankfurt, Asia Pacific Sydney, Asia Pacific Tokyo, with cross-account shared-VPC testing via AWS RAM). Open-source tools such as Garak or PyRIT and manual red-teaming are complementary options. Verify current regional availability on the AWS Security Agent page before relying on it. 4. Document findings and remediation for regulatory examination, and tag tested resources with a last-pentest-date for audit trail. 5. For DORA compliance, include GenAI in TLPT (Threat-Led Penetration Testing) scope.

Reference

Informational N/A
111122223333 us-west-2 FS-54
ADVISORY: Penetration Testing — Manual Review Required
Details and remediation
Details

Penetration testing evidence cannot be verified via AWS APIs. Manual review required to confirm GenAI applications have been tested.

Resolution

1. Conduct penetration testing of GenAI applications at least annually and before major releases. 2. Include AI-specific test cases: prompt injection, jailbreak, indirect (cross-domain) injection, system-prompt leakage, and data-extraction attempts. 3. Consider AWS Security Agent for on-demand, AI-driven penetration testing (GA March 2026; available in US East N. Virginia, US West Oregon, Europe Ireland, Europe Frankfurt, Asia Pacific Sydney, Asia Pacific Tokyo, with cross-account shared-VPC testing via AWS RAM). Open-source tools such as Garak or PyRIT and manual red-teaming are complementary options. Verify current regional availability on the AWS Security Agent page before relying on it. 4. Document findings and remediation for regulatory examination, and tag tested resources with a last-pentest-date for audit trail. 5. For DORA compliance, include GenAI in TLPT (Threat-Led Penetration Testing) scope.

Reference

Informational N/A
111122223333 us-east-1 FS-55
No Output Validation Functions Found
Details and remediation
Details

No Lambda functions with output validation/sanitization naming found. GenAI outputs may be passed directly to downstream systems without validation.

Resolution

1. Implement output validation Lambda functions in GenAI pipelines. 2. Validate output schema, length, and content before downstream use. 3. Sanitize outputs before rendering in web UIs (XSS prevention). 4. Encode outputs appropriately for the target context (HTML, SQL, JSON).

Reference

Medium Failed
111122223333 us-east-2 FS-55
No Output Validation Functions Found
Details and remediation
Details

No Lambda functions with output validation/sanitization naming found. GenAI outputs may be passed directly to downstream systems without validation.

Resolution

1. Implement output validation Lambda functions in GenAI pipelines. 2. Validate output schema, length, and content before downstream use. 3. Sanitize outputs before rendering in web UIs (XSS prevention). 4. Encode outputs appropriately for the target context (HTML, SQL, JSON).

Reference

Medium Failed
111122223333 us-west-2 FS-55
No Output Validation Functions Found
Details and remediation
Details

No Lambda functions with output validation/sanitization naming found. GenAI outputs may be passed directly to downstream systems without validation.

Resolution

1. Implement output validation Lambda functions in GenAI pipelines. 2. Validate output schema, length, and content before downstream use. 3. Sanitize outputs before rendering in web UIs (XSS prevention). 4. Encode outputs appropriately for the target context (HTML, SQL, JSON).

Reference

Medium Failed
111122223333 us-east-1 FS-56
No WAF ACLs — XSS Prevention Not Applicable
Details and remediation
Details

No regional WAF Web ACLs found.

Resolution

Create WAF ACLs with XSS prevention rules.

Reference

Informational N/A
111122223333 us-east-2 FS-56
No WAF ACLs — XSS Prevention Not Applicable
Details and remediation
Details

No regional WAF Web ACLs found.

Resolution

Create WAF ACLs with XSS prevention rules.

Reference

Informational N/A
111122223333 us-west-2 FS-56
No WAF ACLs — XSS Prevention Not Applicable
Details and remediation
Details

No regional WAF Web ACLs found.

Resolution

Create WAF ACLs with XSS prevention rules.

Reference

Informational N/A
111122223333 us-east-1 FS-57
ADVISORY: Output Encoding — Manual Review Required
Details and remediation
Details

Output encoding practices cannot be verified via AWS APIs. Manual code review required.

Resolution

1. HTML-encode GenAI outputs before rendering in web UIs. 2. Use parameterized queries when GenAI output is used in database operations. 3. JSON-encode outputs before embedding in JavaScript contexts. 4. Validate output length and format before passing to downstream APIs.

Reference

Informational N/A
111122223333 us-east-2 FS-57
ADVISORY: Output Encoding — Manual Review Required
Details and remediation
Details

Output encoding practices cannot be verified via AWS APIs. Manual code review required.

Resolution

1. HTML-encode GenAI outputs before rendering in web UIs. 2. Use parameterized queries when GenAI output is used in database operations. 3. JSON-encode outputs before embedding in JavaScript contexts. 4. Validate output length and format before passing to downstream APIs.

Reference

Informational N/A
111122223333 us-west-2 FS-57
ADVISORY: Output Encoding — Manual Review Required
Details and remediation
Details

Output encoding practices cannot be verified via AWS APIs. Manual code review required.

Resolution

1. HTML-encode GenAI outputs before rendering in web UIs. 2. Use parameterized queries when GenAI output is used in database operations. 3. JSON-encode outputs before embedding in JavaScript contexts. 4. Validate output length and format before passing to downstream APIs.

Reference

Informational N/A
111122223333 us-east-1 FS-58
ADVISORY: Output Schema Validation — Manual Review Required
Details and remediation
Details

Found 0 Lambda function(s) whose names suggest schema/validation handling. Structured-output / JSON-schema validation of GenAI responses is an application-layer control that cannot be verified automatically — manual review required.

Resolution

1. Use Bedrock structured output (response schemas) where supported. 2. Implement JSON schema validation on Lambda output processors. 3. Reject malformed outputs and return safe error responses. 4. Log schema validation failures to CloudWatch for monitoring.

Reference

Informational N/A
111122223333 us-east-2 FS-58
ADVISORY: Output Schema Validation — Manual Review Required
Details and remediation
Details

Found 0 Lambda function(s) whose names suggest schema/validation handling. Structured-output / JSON-schema validation of GenAI responses is an application-layer control that cannot be verified automatically — manual review required.

Resolution

1. Use Bedrock structured output (response schemas) where supported. 2. Implement JSON schema validation on Lambda output processors. 3. Reject malformed outputs and return safe error responses. 4. Log schema validation failures to CloudWatch for monitoring.

Reference

Informational N/A
111122223333 us-west-2 FS-58
ADVISORY: Output Schema Validation — Manual Review Required
Details and remediation
Details

Found 0 Lambda function(s) whose names suggest schema/validation handling. Structured-output / JSON-schema validation of GenAI responses is an application-layer control that cannot be verified automatically — manual review required.

Resolution

1. Use Bedrock structured output (response schemas) where supported. 2. Implement JSON schema validation on Lambda output processors. 3. Reject malformed outputs and return safe error responses. 4. Log schema validation failures to CloudWatch for monitoring.

Reference

Informational N/A
111122223333 us-east-1 FS-59
Topic Restrictions Configured on CLASSIC Tier
Details and remediation
Details

Guardrails with topic policies: nist-ai-rmf-guardrail. The following use the CLASSIC tier: nist-ai-rmf-guardrail. CLASSIC tier supports English, French, and Spanish only; the STANDARD tier (GA June 2025) adds broader language support for off-topic detection.

Resolution

For multilingual FinServ deployments, consider upgrading denied topics to the STANDARD tier (topicsTierConfig.tierName=STANDARD via UpdateGuardrail; requires a cross-region inference profile).

Reference

Medium Passed
111122223333 us-east-2 FS-59
Topic Restrictions Configured on CLASSIC Tier
Details and remediation
Details

Guardrails with topic policies: nist-ai-rmf-guardrail. The following use the CLASSIC tier: nist-ai-rmf-guardrail. CLASSIC tier supports English, French, and Spanish only; the STANDARD tier (GA June 2025) adds broader language support for off-topic detection.

Resolution

For multilingual FinServ deployments, consider upgrading denied topics to the STANDARD tier (topicsTierConfig.tierName=STANDARD via UpdateGuardrail; requires a cross-region inference profile).

Reference

Medium Passed
111122223333 us-west-2 FS-59
Topic Restrictions Configured on CLASSIC Tier
Details and remediation
Details

Guardrails with topic policies: nist-ai-rmf-guardrail. The following use the CLASSIC tier: nist-ai-rmf-guardrail. CLASSIC tier supports English, French, and Spanish only; the STANDARD tier (GA June 2025) adds broader language support for off-topic detection.

Resolution

For multilingual FinServ deployments, consider upgrading denied topics to the STANDARD tier (topicsTierConfig.tierName=STANDARD via UpdateGuardrail; requires a cross-region inference profile).

Reference

Medium Passed
111122223333 us-east-1 FS-60
ADVISORY: Contextual Grounding for Off-Topic Prevention
Details and remediation
Details

Contextual grounding for off-topic prevention is covered by guardrail grounding checks (FS-47) and RAG configuration (FS-48). Additionally verify system prompts explicitly scope the assistant's role.

Resolution

1. Include explicit scope instructions in system prompts. 2. Use Bedrock Guardrails relevance grounding filter. 3. Test with off-topic prompts in QA to verify rejection behavior.

Reference

Informational N/A
111122223333 us-east-2 FS-60
ADVISORY: Contextual Grounding for Off-Topic Prevention
Details and remediation
Details

Contextual grounding for off-topic prevention is covered by guardrail grounding checks (FS-47) and RAG configuration (FS-48). Additionally verify system prompts explicitly scope the assistant's role.

Resolution

1. Include explicit scope instructions in system prompts. 2. Use Bedrock Guardrails relevance grounding filter. 3. Test with off-topic prompts in QA to verify rejection behavior.

Reference

Informational N/A
111122223333 us-west-2 FS-60
ADVISORY: Contextual Grounding for Off-Topic Prevention
Details and remediation
Details

Contextual grounding for off-topic prevention is covered by guardrail grounding checks (FS-47) and RAG configuration (FS-48). Additionally verify system prompts explicitly scope the assistant's role.

Resolution

1. Include explicit scope instructions in system prompts. 2. Use Bedrock Guardrails relevance grounding filter. 3. Test with off-topic prompts in QA to verify rejection behavior.

Reference

Informational N/A
111122223333 us-east-1 FS-61
No Automated KB Sync Schedules Detected
Details and remediation
Details

Found 3 Knowledge Base(s) but no EventBridge Scheduler schedules or EventBridge rules with 'bedrock'/'knowledge' naming were found. Note: this check uses a name/target heuristic — sync automation with other naming conventions, AWS Step Functions-based orchestration, or native Bedrock API-triggered syncs (StartIngestionJob called directly) will not be detected. Verify sync automation manually if applicable.

Resolution

1. Use EventBridge Scheduler (the AWS-recommended approach) to create a recurring schedule (e.g., rate(1 day) or a cron expression) that triggers a Lambda function calling the Bedrock StartIngestionJob API for each data source. Classic EventBridge scheduled rules also work but are a legacy feature. 2. As of December 2024, Bedrock Knowledge Bases supports custom connectors and streaming data ingestion — use direct document ingestion (KnowledgeBaseDocuments API) for real-time updates without a full S3 sync. 3. Set sync frequency based on data currency requirements (e.g., hourly for market data, daily for regulatory guidance). 4. Configure CloudWatch alarms or SNS notifications on IngestionJob FAILED status for sync failure alerting.

Reference

Medium Failed
111122223333 us-east-2 FS-61
No Automated KB Sync Schedules Detected
Details and remediation
Details

Found 3 Knowledge Base(s) but no EventBridge Scheduler schedules or EventBridge rules with 'bedrock'/'knowledge' naming were found. Note: this check uses a name/target heuristic — sync automation with other naming conventions, AWS Step Functions-based orchestration, or native Bedrock API-triggered syncs (StartIngestionJob called directly) will not be detected. Verify sync automation manually if applicable.

Resolution

1. Use EventBridge Scheduler (the AWS-recommended approach) to create a recurring schedule (e.g., rate(1 day) or a cron expression) that triggers a Lambda function calling the Bedrock StartIngestionJob API for each data source. Classic EventBridge scheduled rules also work but are a legacy feature. 2. As of December 2024, Bedrock Knowledge Bases supports custom connectors and streaming data ingestion — use direct document ingestion (KnowledgeBaseDocuments API) for real-time updates without a full S3 sync. 3. Set sync frequency based on data currency requirements (e.g., hourly for market data, daily for regulatory guidance). 4. Configure CloudWatch alarms or SNS notifications on IngestionJob FAILED status for sync failure alerting.

Reference

Medium Failed
111122223333 us-west-2 FS-61
No Automated KB Sync Schedules Detected
Details and remediation
Details

Found 3 Knowledge Base(s) but no EventBridge Scheduler schedules or EventBridge rules with 'bedrock'/'knowledge' naming were found. Note: this check uses a name/target heuristic — sync automation with other naming conventions, AWS Step Functions-based orchestration, or native Bedrock API-triggered syncs (StartIngestionJob called directly) will not be detected. Verify sync automation manually if applicable.

Resolution

1. Use EventBridge Scheduler (the AWS-recommended approach) to create a recurring schedule (e.g., rate(1 day) or a cron expression) that triggers a Lambda function calling the Bedrock StartIngestionJob API for each data source. Classic EventBridge scheduled rules also work but are a legacy feature. 2. As of December 2024, Bedrock Knowledge Bases supports custom connectors and streaming data ingestion — use direct document ingestion (KnowledgeBaseDocuments API) for real-time updates without a full S3 sync. 3. Set sync frequency based on data currency requirements (e.g., hourly for market data, daily for regulatory guidance). 4. Configure CloudWatch alarms or SNS notifications on IngestionJob FAILED status for sync failure alerting.

Reference

Medium Failed
111122223333 us-east-1 FS-62
ADVISORY: Data Currency Disclaimer — Manual Review Required
Details and remediation
Details

Data currency disclaimers cannot be verified via AWS APIs. Manual review required.

Resolution

1. Add data currency disclaimers to GenAI outputs: 'Information based on data current as of [KB last sync date].' 2. Expose KB last sync timestamp in application responses. 3. Alert users when KB data is older than defined threshold.

Reference

Informational N/A
111122223333 us-east-2 FS-62
ADVISORY: Data Currency Disclaimer — Manual Review Required
Details and remediation
Details

Data currency disclaimers cannot be verified via AWS APIs. Manual review required.

Resolution

1. Add data currency disclaimers to GenAI outputs: 'Information based on data current as of [KB last sync date].' 2. Expose KB last sync timestamp in application responses. 3. Alert users when KB data is older than defined threshold.

Reference

Informational N/A
111122223333 us-west-2 FS-62
ADVISORY: Data Currency Disclaimer — Manual Review Required
Details and remediation
Details

Data currency disclaimers cannot be verified via AWS APIs. Manual review required.

Resolution

1. Add data currency disclaimers to GenAI outputs: 'Information based on data current as of [KB last sync date].' 2. Expose KB last sync timestamp in application responses. 3. Alert users when KB data is older than defined threshold.

Reference

Informational N/A
111122223333 us-east-1 FS-63
Foundation Model Lifecycle Management
Details and remediation
Details

No legacy models detected. 10 lifecycle-related Config rule(s) found.

Resolution

No action required.

Reference

Medium Passed
111122223333 us-east-2 FS-63
Foundation Model Lifecycle Management
Details and remediation
Details

No legacy models detected. 10 lifecycle-related Config rule(s) found.

Resolution

No action required.

Reference

Medium Passed
111122223333 us-west-2 FS-63
Foundation Model Lifecycle Management
Details and remediation
Details

No legacy models detected. 10 lifecycle-related Config rule(s) found.

Resolution

No action required.

Reference

Medium Passed
111122223333 us-east-1 FS-65
KB Data Source Buckets Missing S3 Event Notifications
Details and remediation
Details

The following KB data-source S3 buckets have no event notifications configured. Unauthorized document modifications will not be detected in real time: - semiconductor-demo-9999 - 111122223333-us-east-1-kb-data-bucket

Resolution

1. Enable Amazon EventBridge notifications on each KB data-source S3 bucket. 2. Create an EventBridge rule to route s3:ObjectCreated, s3:ObjectRemoved, and s3:ObjectModified events to an SNS topic or Lambda for alerting. 3. Integrate alerts into your security incident response workflow.

Reference

Medium Failed
111122223333 us-east-2 FS-65
KB Data Source Buckets Missing S3 Event Notifications
Details and remediation
Details

The following KB data-source S3 buckets have no event notifications configured. Unauthorized document modifications will not be detected in real time: - semiconductor-demo-9999 - 111122223333-us-east-1-kb-data-bucket

Resolution

1. Enable Amazon EventBridge notifications on each KB data-source S3 bucket. 2. Create an EventBridge rule to route s3:ObjectCreated, s3:ObjectRemoved, and s3:ObjectModified events to an SNS topic or Lambda for alerting. 3. Integrate alerts into your security incident response workflow.

Reference

Medium Failed
111122223333 us-west-2 FS-65
KB Data Source Buckets Missing S3 Event Notifications
Details and remediation
Details

The following KB data-source S3 buckets have no event notifications configured. Unauthorized document modifications will not be detected in real time: - semiconductor-demo-9999 - 111122223333-us-east-1-kb-data-bucket

Resolution

1. Enable Amazon EventBridge notifications on each KB data-source S3 bucket. 2. Create an EventBridge rule to route s3:ObjectCreated, s3:ObjectRemoved, and s3:ObjectModified events to an SNS topic or Lambda for alerting. 3. Integrate alerts into your security incident response workflow.

Reference

Medium Failed
111122223333 us-east-1 FS-66
AgentCore Runtimes Missing End-User Identity Propagation
Details and remediation
Details

The following runtimes have no JWT or IAM authorizer configured for end-user identity propagation. Tool calls are authorized only by the agent execution role, not the originating user: - origami_expeditions - neoCyan_Agent - customer_support_agent - cdk_agent_core - awsapimcpserver

Resolution

1. Configure a custom JWT authorizer or IAM authorizer on each AgentCore runtime. 2. Propagate the end-user's identity token to downstream tool services. 3. Ensure tool services validate the propagated identity before executing actions. 4. Do not expose propagated identity tokens to unauthorized third parties.

Reference

High Failed
111122223333 us-east-2 FS-66
AgentCore Runtimes Missing End-User Identity Propagation
Details and remediation
Details

The following runtimes have no JWT or IAM authorizer configured for end-user identity propagation. Tool calls are authorized only by the agent execution role, not the originating user: - origami_expeditions - neoCyan_Agent - customer_support_agent - cdk_agent_core - awsapimcpserver

Resolution

1. Configure a custom JWT authorizer or IAM authorizer on each AgentCore runtime. 2. Propagate the end-user's identity token to downstream tool services. 3. Ensure tool services validate the propagated identity before executing actions. 4. Do not expose propagated identity tokens to unauthorized third parties.

Reference

High Failed
111122223333 us-west-2 FS-66
AgentCore Runtimes Missing End-User Identity Propagation
Details and remediation
Details

The following runtimes have no JWT or IAM authorizer configured for end-user identity propagation. Tool calls are authorized only by the agent execution role, not the originating user: - origami_expeditions - neoCyan_Agent - customer_support_agent - cdk_agent_core - awsapimcpserver

Resolution

1. Configure a custom JWT authorizer or IAM authorizer on each AgentCore runtime. 2. Propagate the end-user's identity token to downstream tool services. 3. Ensure tool services validate the propagated identity before executing actions. 4. Do not expose propagated identity tokens to unauthorized third parties.

Reference

High Failed
111122223333 us-east-1 FS-67
Agent Action-Group Lambdas May Lack Transaction Thresholds
Details and remediation
Details

The following agent action-group Lambda functions have no environment variables whose names suggest transaction-value threshold configuration (this is a best-effort heuristic — a threshold enforced in code or in an AgentCore Policy Engine rule would not be detected here, so treat this as a prompt for manual verification rather than a definitive gap). Without explicit limits, agents could initiate unbounded financial transactions: - aiml-security-aiml-security-111122223333-FinServAssessment - aiml-security-aiml-security-111122223333-BedrockAssessment - resco-aiml-BedrockAssessment - aiml-security-aiml-security-111122223333-AgentCoreAssessment - e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk - e2ebedrockrag-OSSInfraSta-OSSIndexCreationProvider-g56en9UzRjII - resco-aiml-AgentCoreAssessment

Resolution

1. Add transaction-value threshold environment variables (e.g., MAX_TRANSACTION_AMOUNT) to each agent action-group Lambda. 2. Implement threshold enforcement logic in the Lambda handler. 3. Configure AgentCore Policy Engine rules to cap financial transaction amounts. 4. Route transactions exceeding thresholds to a human-in-the-loop approval step.

Reference

High Failed
111122223333 us-east-2 FS-67
Agent Action-Group Lambdas May Lack Transaction Thresholds
Details and remediation
Details

The following agent action-group Lambda functions have no environment variables whose names suggest transaction-value threshold configuration (this is a best-effort heuristic — a threshold enforced in code or in an AgentCore Policy Engine rule would not be detected here, so treat this as a prompt for manual verification rather than a definitive gap). Without explicit limits, agents could initiate unbounded financial transactions: - aiml-security-aiml-security-111122223333-FinServAssessment - aiml-security-aiml-security-111122223333-BedrockAssessment - resco-aiml-BedrockAssessment - aiml-security-aiml-security-111122223333-AgentCoreAssessment - e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk - e2ebedrockrag-OSSInfraSta-OSSIndexCreationProvider-g56en9UzRjII - resco-aiml-AgentCoreAssessment

Resolution

1. Add transaction-value threshold environment variables (e.g., MAX_TRANSACTION_AMOUNT) to each agent action-group Lambda. 2. Implement threshold enforcement logic in the Lambda handler. 3. Configure AgentCore Policy Engine rules to cap financial transaction amounts. 4. Route transactions exceeding thresholds to a human-in-the-loop approval step.

Reference

High Failed
111122223333 us-west-2 FS-67
Agent Action-Group Lambdas May Lack Transaction Thresholds
Details and remediation
Details

The following agent action-group Lambda functions have no environment variables whose names suggest transaction-value threshold configuration (this is a best-effort heuristic — a threshold enforced in code or in an AgentCore Policy Engine rule would not be detected here, so treat this as a prompt for manual verification rather than a definitive gap). Without explicit limits, agents could initiate unbounded financial transactions: - aiml-security-aiml-security-111122223333-FinServAssessment - aiml-security-aiml-security-111122223333-BedrockAssessment - resco-aiml-BedrockAssessment - aiml-security-aiml-security-111122223333-AgentCoreAssessment - e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk - e2ebedrockrag-OSSInfraSta-OSSIndexCreationProvider-g56en9UzRjII - resco-aiml-AgentCoreAssessment

Resolution

1. Add transaction-value threshold environment variables (e.g., MAX_TRANSACTION_AMOUNT) to each agent action-group Lambda. 2. Implement threshold enforcement logic in the Lambda handler. 3. Configure AgentCore Policy Engine rules to cap financial transaction amounts. 4. Route transactions exceeding thresholds to a human-in-the-loop approval step.

Reference

High Failed
111122223333 us-east-1 FS-68
API Gateway Request Body Size Limits Not Enforced
Details and remediation
Details

Found 3 REST API(s) and 0 regional WAF Web ACL(s), but none enforce a maximum request-body size. Note: an API Gateway request validator does NOT cap body size (it validates the schema and required params; the REST limit is a fixed 10 MB), and a WAF body SizeConstraint only inspects the first ~16 KB of the body by default. Oversized prompts can exhaust Bedrock token quotas and inflate costs.

Resolution

1. Add a maxLength (or maxItems/maxProperties) bound to the request-body JSON-Schema model used by your request validator, so oversized prompts are rejected with a 400. 2. Add a WAF SizeConstraintStatement on the request Body sized within WAF's body-inspection window (default 16 KB; raise via the web ACL AssociationConfig, or set OversizeHandling=MATCH to block bodies beyond the window), and associate the ACL with the API stage. 3. Set the max_tokens parameter in Bedrock API calls to cap output length. 4. Implement client-side token counting before submitting requests.

Reference

Medium Failed
111122223333 us-east-2 FS-68
API Gateway Request Body Size Limits Not Enforced
Details and remediation
Details

Found 3 REST API(s) and 0 regional WAF Web ACL(s), but none enforce a maximum request-body size. Note: an API Gateway request validator does NOT cap body size (it validates the schema and required params; the REST limit is a fixed 10 MB), and a WAF body SizeConstraint only inspects the first ~16 KB of the body by default. Oversized prompts can exhaust Bedrock token quotas and inflate costs.

Resolution

1. Add a maxLength (or maxItems/maxProperties) bound to the request-body JSON-Schema model used by your request validator, so oversized prompts are rejected with a 400. 2. Add a WAF SizeConstraintStatement on the request Body sized within WAF's body-inspection window (default 16 KB; raise via the web ACL AssociationConfig, or set OversizeHandling=MATCH to block bodies beyond the window), and associate the ACL with the API stage. 3. Set the max_tokens parameter in Bedrock API calls to cap output length. 4. Implement client-side token counting before submitting requests.

Reference

Medium Failed
111122223333 us-west-2 FS-68
API Gateway Request Body Size Limits Not Enforced
Details and remediation
Details

Found 3 REST API(s) and 0 regional WAF Web ACL(s), but none enforce a maximum request-body size. Note: an API Gateway request validator does NOT cap body size (it validates the schema and required params; the REST limit is a fixed 10 MB), and a WAF body SizeConstraint only inspects the first ~16 KB of the body by default. Oversized prompts can exhaust Bedrock token quotas and inflate costs.

Resolution

1. Add a maxLength (or maxItems/maxProperties) bound to the request-body JSON-Schema model used by your request validator, so oversized prompts are rejected with a 400. 2. Add a WAF SizeConstraintStatement on the request Body sized within WAF's body-inspection window (default 16 KB; raise via the web ACL AssociationConfig, or set OversizeHandling=MATCH to block bodies beyond the window), and associate the ACL with the API stage. 3. Set the max_tokens parameter in Bedrock API calls to cap output length. 4. Implement client-side token counting before submitting requests.

Reference

Medium Failed
111122223333 us-east-1 FS-69
Prompt Input Validation Functions Present
Details and remediation
Details

Found 3 Lambda function(s) with input validation/sanitization naming patterns: resco-aiml-CleanupBucket, visa-bulletin-tracker-prod-cleanup, aiml-security-aiml-security-111122223333-CleanupBucket.

Resolution

Review these functions to confirm they cover: special-character stripping, format validation, size limits, and injection-sequence detection.

Reference

Medium Passed
111122223333 us-east-2 FS-69
Prompt Input Validation Functions Present
Details and remediation
Details

Found 3 Lambda function(s) with input validation/sanitization naming patterns: resco-aiml-CleanupBucket, visa-bulletin-tracker-prod-cleanup, aiml-security-aiml-security-111122223333-CleanupBucket.

Resolution

Review these functions to confirm they cover: special-character stripping, format validation, size limits, and injection-sequence detection.

Reference

Medium Passed
111122223333 us-west-2 FS-69
Prompt Input Validation Functions Present
Details and remediation
Details

Found 3 Lambda function(s) with input validation/sanitization naming patterns: resco-aiml-CleanupBucket, visa-bulletin-tracker-prod-cleanup, aiml-security-aiml-security-111122223333-CleanupBucket.

Resolution

Review these functions to confirm they cover: special-character stripping, format validation, size limits, and injection-sequence detection.

Reference

Medium Passed
111122223333 eu-west-1 FS-00
FinServ Regional Scope Not Applicable
Details and remediation
Details

No regional Bedrock, AgentCore, or SageMaker resources were found in eu-west-1; FinServ GenAI risk checks were not applied to this region.

Resolution

No action required unless GenAI workloads are expected in this region.

Reference

Informational N/A
111122223333 us-east-2 AC-01
AgentCore VPC Configuration Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 AC-04
AgentCore Observability Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 AC-05
AgentCore Encryption Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 AC-06
AgentCore Browser Tool Recording Check
Details and remediation
Details

No AgentCore Runtimes found to check browser tool configuration

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 AC-07
AgentCore Memory Configuration Check
Details and remediation
Details

No Memory resources found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 AC-13
AgentCore Gateway Configuration Check
Details and remediation
Details

No Gateway resources found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 AC-08
AgentCore VPC Endpoints Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 AC-10
AgentCore Resource-Based Policies Check
Details and remediation
Details

No AgentCore resources found to check for resource-based policies

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 AC-11
AgentCore Policy Engine Encryption Check
Details and remediation
Details

No Policy Engines found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 AC-12
AgentCore Gateway Encryption Check
Details and remediation
Details

No Gateways found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 AG-24
Agentic AI Gateway Inbound Authorization
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 AG-25
Agentic AI Gateway Tool Policy Enforcement
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 AG-26
Agentic AI Gateway Error Detail Exposure
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 AG-27
Agentic AI Gateway WAF Protection
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 AG-15
Agentic AI Runtime Network Boundary
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found

Resolution

Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services.

Reference

Informational N/A
111122223333 us-east-2 AG-18
Agentic AI AgentCore Observability
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found

Resolution

Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported.

Reference

Informational N/A
111122223333 us-east-2 AG-19
Agentic AI Memory Data Protection
Details and remediation
Details

Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found

Resolution

Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions.

Reference

Informational N/A
111122223333 us-east-2 AG-20
Agentic AI Private AgentCore Connectivity
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found

Resolution

Create required VPC endpoints for AgentCore services and validate endpoint availability.

Reference

Informational N/A
111122223333 us-east-2 AG-21
Agentic AI Resource Policy Boundary
Details and remediation
Details

Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies

Resolution

Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources.

Reference

Informational N/A
111122223333 us-east-2 AG-22
Agentic AI Policy Engine Data Protection
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found

Resolution

Configure policy engines with customer-managed KMS keys where enhanced key control is required.

Reference

Informational N/A
111122223333 us-east-2 AG-23
Agentic AI Gateway Data Protection
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found

Resolution

Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required.

Reference

Informational N/A
111122223333 us-west-2 AC-01
AgentCore VPC Configuration Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
111122223333 us-west-2 AC-04
AgentCore Observability Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
111122223333 us-west-2 AC-05
AgentCore Encryption Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
111122223333 us-west-2 AC-06
AgentCore Browser Tool Recording Check
Details and remediation
Details

No AgentCore Runtimes found to check browser tool configuration

Resolution

No action required

Reference

Informational N/A
111122223333 us-west-2 AC-07
AgentCore Memory Configuration Check
Details and remediation
Details

No Memory resources found

Resolution

No action required

Reference

Informational N/A
111122223333 us-west-2 AC-13
AgentCore Gateway Configuration Check
Details and remediation
Details

Found 1 Gateway resources

Resolution

No action required

Reference

Medium Passed
111122223333 us-west-2 AC-08
AgentCore VPC Endpoints Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
111122223333 us-west-2 AC-10
AgentCore Resource-Based Policies Missing
Details and remediation
Details

The following AgentCore resources do not have resource-based policies: Gateway 'aws-news-mcp'. Without RBPs, access control relies solely on identity-based policies.

Resolution

Attach resource-based policies to AgentCore resources to: 1. Implement defense-in-depth access control 2. Enable cross-account access control 3. Restrict access based on source VPC or IP 4. Implement hierarchical authorization for Agent Runtimes

Reference

High Failed
111122223333 us-west-2 AC-11
AgentCore Policy Engine Encryption Check
Details and remediation
Details

No Policy Engines found

Resolution

No action required

Reference

Informational N/A
111122223333 us-west-2 AC-12
AgentCore Gateway Encryption Missing
Details and remediation
Details

The following Gateways do not use customer-managed KMS encryption: 'aws-news-mcp'. Gateway configuration data uses AWS-managed keys.

Resolution

1. Create gateways with customer-managed KMS keys for additional control 2. AWS-managed keys are single-tenant and region-specific 3. Consider CMK for enhanced audit capabilities and key rotation control

Reference

Low Failed
111122223333 us-west-2 AG-24
Agentic AI Gateway Inbound Authorization
Details and remediation
Details

Gateway 'aws-news-mcp' (aws-news-mcp-vx9kxwqv9p) uses authorizerType CUSTOM_JWT.

Resolution

No action required

Reference

High Passed
111122223333 us-west-2 AG-25
Agentic AI Gateway Tool Policy Enforcement Missing
Details and remediation
Details

Gateway 'aws-news-mcp' (aws-news-mcp-vx9kxwqv9p) does not have a policy engine configuration. Tool calls are not evaluated by AgentCore policy enforcement.

Resolution

Attach an AgentCore policy engine to the gateway and use ENFORCE mode for production tool authorization.

Reference

High Failed
111122223333 us-west-2 AG-26
Agentic AI Gateway Error Detail Exposure
Details and remediation
Details

Gateway 'aws-news-mcp' (aws-news-mcp-vx9kxwqv9p) does not expose DEBUG-level exception detail.

Resolution

No action required

Reference

Medium Passed
111122223333 us-west-2 AG-27
Agentic AI Gateway WAF Protection Missing
Details and remediation
Details

Gateway 'aws-news-mcp' (aws-news-mcp-vx9kxwqv9p) is not associated with an AWS WAF web ACL.

Resolution

Associate an AWS WAF web ACL with internet-facing AgentCore gateways to add request filtering and abuse protection.

Reference

Low Failed
111122223333 us-west-2 AG-15
Agentic AI Runtime Network Boundary
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found

Resolution

Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services.

Reference

Informational N/A
111122223333 us-west-2 AG-18
Agentic AI AgentCore Observability
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found

Resolution

Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported.

Reference

Informational N/A
111122223333 us-west-2 AG-19
Agentic AI Memory Data Protection
Details and remediation
Details

Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found

Resolution

Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions.

Reference

Informational N/A
111122223333 us-west-2 AG-20
Agentic AI Private AgentCore Connectivity
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found

Resolution

Create required VPC endpoints for AgentCore services and validate endpoint availability.

Reference

Informational N/A
111122223333 us-west-2 AG-21
Agentic AI Resource Policy Boundary
Details and remediation
Details

Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: The following AgentCore resources do not have resource-based policies: Gateway 'aws-news-mcp'. Without RBPs, access control relies solely on identity-based policies.

Resolution

Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources.

Reference

High Failed
111122223333 us-west-2 AG-22
Agentic AI Policy Engine Data Protection
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found

Resolution

Configure policy engines with customer-managed KMS keys where enhanced key control is required.

Reference

Informational N/A
111122223333 us-west-2 AG-23
Agentic AI Gateway Data Protection
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: The following Gateways do not use customer-managed KMS encryption: 'aws-news-mcp'. Gateway configuration data uses AWS-managed keys.

Resolution

Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required.

Reference

Low Failed
111122223333 us-east-2 OW-01
OWASP LLM01: Model Invocation Logging
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging

Resolution

Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis.

Reference

Informational N/A
111122223333 us-east-2 OW-07
OWASP LLM07: Model Invocation Logging
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging

Resolution

Enable Bedrock model invocation logging so prompt-extraction attempts against the system prompt are auditable after the fact.

Reference

Informational N/A
111122223333 us-east-2 OW-07
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses.

Resolution

Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident.

Reference

Informational N/A
111122223333 us-east-2 OW-07
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-16: No Bedrock guardrails configured in this region

Resolution

Set guardrail contentPolicy.tier.tierName to STANDARD; Standard tier additionally detects prompt-leakage attacks.

Reference

Informational N/A
111122223333 us-east-2 OW-09
OWASP LLM09: Model Evaluation Jobs
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs

Resolution

Run Bedrock model evaluation jobs that include correctness and safety datasets.

Reference

Informational N/A
111122223333 us-east-2 OW-08
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: No Bedrock knowledge bases found in this region

Resolution

Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption.

Reference

Informational N/A
111122223333 us-east-2 OW-06
OWASP LLM06: Agent Action-Group Least Privilege
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-21: No Bedrock agents configured in this region

Resolution

Restrict agent action-group Lambda roles to only the specific actions and resources needed for each tool.

Reference

Informational N/A
111122223333 us-east-2 OW-10
OWASP LLM10: Service Quota Throttling Limits
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas

Resolution

Customise Bedrock TPM / RPM service quotas above the account default to establish an explicit consumption ceiling.

Reference

Informational N/A
111122223333 us-east-2 OW-01
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: No Bedrock guardrails configured in this region

Resolution

Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier.

Reference

Informational N/A
111122223333 us-east-2 OW-04
OWASP LLM04: RAG Evaluation Coverage
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: No Bedrock knowledge bases found in this region

Resolution

Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context.

Reference

Informational N/A
111122223333 us-east-2 OW-09
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-25: No Bedrock knowledge bases found in this region

Resolution

Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates.

Reference

Informational N/A
111122223333 us-east-2 OW-02
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check BR-26: No Bedrock guardrails configured in this region

Resolution

Configure guardrail sensitiveInformationPolicy with PII entities and regex patterns; set outputAction=ANONYMIZE or BLOCK.

Reference

Informational N/A
111122223333 us-east-2 OW-01
OWASP LLM01: Contextual Grounding Guardrail
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Enable Bedrock guardrail contextual grounding checks to reduce the surface for indirect prompt injection through retrieved context.

Reference

Informational N/A
111122223333 us-east-2 OW-04
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Enable contextual grounding guardrail filters so retrieved context that diverges from ground truth is filtered before reaching the model.

Reference

Informational N/A
111122223333 us-east-2 OW-09
OWASP LLM09: Contextual Grounding for Faithfulness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Set the contextual grounding filter threshold to at least 0.70 to reduce hallucinated responses.

Reference

Informational N/A
111122223333 us-east-2 OW-06
OWASP LLM06: Bedrock Agent Guardrail Association
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-28: No Bedrock agents configured in this region

Resolution

Attach an approved Bedrock guardrail to every Bedrock agent so autonomous actions are filtered consistently.

Reference

Informational N/A
111122223333 us-east-2 OW-06
OWASP LLM06: Agent Idle Session TTL
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-29: No Bedrock agents configured in this region

Resolution

Set idleSessionTTLInSeconds to a conservative value (e.g., <= 3600) so long-lived agent sessions cannot be reused.

Reference

Informational N/A
111122223333 us-east-2 OW-03
OWASP LLM03: Imported-Model KMS Provenance
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check BR-30: No imported custom Bedrock models found in this region

Resolution

Encrypt imported Bedrock models with a customer-managed KMS key to preserve provenance and access control across model artefacts.

Reference

Informational N/A
111122223333 us-east-2 OW-10
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms

Resolution

Create CloudWatch alarms on Bedrock InvocationThrottles, InputTokenCount, OutputTokenCount, and EstimatedTPMQuotaUsage.

Reference

Informational N/A
111122223333 us-east-2 OW-03
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check BR-33: No Lambda functions with Bedrock indicators were found in us-east-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads.

Resolution

Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain.

Reference

Informational N/A
111122223333 us-east-2 OW-03
OWASP LLM03: SageMaker Internet Exposure
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-01: No SageMaker notebook instances or domains found to check

Resolution

Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths.

Reference

Informational N/A
111122223333 us-east-2 OW-02
OWASP LLM02: SageMaker Data Encryption
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: Training Job 'xgboost-2021-12-19-01-07-45-798' - No output encryption configured

Resolution

Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data.

Reference

High Failed
111122223333 us-east-2 OW-02
OWASP LLM02: SageMaker Data Encryption
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: Training Job 'xgboost-2021-12-19-01-07-45-798' - Inter-container traffic encryption not enabled

Resolution

Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data.

Reference

Medium Failed
111122223333 us-east-2 OW-09
OWASP LLM09: SageMaker Clarify Evaluation
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-06: No SageMaker Clarify jobs found

Resolution

Use SageMaker Clarify to evaluate bias and explainability for models whose generated outputs can influence user decisions.

Reference

Informational N/A
111122223333 us-east-2 OW-04
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-07: No Model Monitor schedules found

Resolution

Configure active SageMaker Model Monitor schedules so data-quality and model-quality regressions caused by poisoned inputs or drift are detected.

Reference

Informational N/A
111122223333 us-east-2 OW-09
OWASP LLM09: SageMaker Model Monitor Coverage
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-07: No Model Monitor schedules found

Resolution

Configure SageMaker Model Monitor schedules for production models so quality regressions that can produce incorrect outputs are detected.

Reference

Informational N/A
111122223333 us-east-2 OW-03
OWASP LLM03: SageMaker Notebook VPC Deployment
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-10: No notebook instances found

Resolution

Deploy SageMaker notebook instances inside a VPC so package, data, and model artifact access can be controlled through private network paths.

Reference

Informational N/A
111122223333 us-east-2 OW-03
OWASP LLM03: SageMaker Model Network Isolation
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-11: Model 'xgboost-2021-12-19-01-25-44-527' does not have network isolation enabled. Model containers can make outbound network calls, potentially exfiltrating data.

Resolution

Enable network isolation on SageMaker models so inference containers cannot make unmanaged outbound calls that alter dependencies or exfiltrate model artifacts.

Reference

High Failed
111122223333 us-east-2 OW-10
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check SM-11: Model 'xgboost-2021-12-19-01-25-44-527' does not have network isolation enabled. Model containers can make outbound network calls, potentially exfiltrating data.

Resolution

Enable SageMaker model network isolation to prevent deployed model containers from making uncontrolled outbound calls that can amplify consumption or abuse downstream services.

Reference

High Failed
111122223333 us-east-2 OW-03
OWASP LLM03: SageMaker Container Repository Access
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-14: Model 'xgboost-2021-12-19-01-25-44-527' uses Platform repository access mode. Container images are pulled from public/external registries, exposing supply chain risks.

Resolution

Configure SageMaker models to pull container images from private ECR repositories through VPC repository access instead of platform or public registry paths.

Reference

Medium Failed
111122223333 us-east-2 OW-02
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-15: No feature groups with offline stores found

Resolution

Encrypt SageMaker Feature Store offline stores with customer-managed KMS keys so sensitive feature data is protected at rest.

Reference

Informational N/A
111122223333 us-east-2 OW-03
OWASP LLM03: SageMaker AutoML Network Isolation
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-21: No AutoML jobs found

Resolution

Enable network isolation on AutoML jobs so generated training containers cannot fetch unapproved dependencies or send data over unmanaged network paths.

Reference

Informational N/A
111122223333 us-east-2 OW-04
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance.

Resolution

Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically.

Reference

Informational N/A
111122223333 us-east-2 OW-09
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance.

Resolution

Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release.

Reference

Informational N/A
111122223333 us-east-2 OW-04
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-23: No InService endpoints found to monitor.

Resolution

Enable SageMaker Model Monitor drift detection for production endpoints so poisoning, data drift, and model-quality degradation are identified.

Reference

Medium Passed
111122223333 us-east-2 OW-09
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-23: No InService endpoints found to monitor.

Resolution

Configure data-quality and model-quality monitoring for SageMaker endpoints so degraded model behavior that can produce misinformation is detected.

Reference

Medium Passed
111122223333 us-east-2 OW-03
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain.

Reference

Informational N/A
111122223333 us-east-2 OW-04
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated.

Reference

Informational N/A
111122223333 us-east-2 OW-06
OWASP LLM06: AgentCore Resource-Based Policies
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check AC-10: No AgentCore resources found to check for resource-based policies

Resolution

Attach resource-based policies to AgentCore runtimes and gateways so caller identities are constrained.

Reference

Informational N/A
111122223333 us-east-2 OW-11
OWASP LLM07: System Prompt Embedded in Lambda Env Var
Details and remediation
Details

No Lambda function env vars in us-east-2 match the embedded-system-prompt heuristic (>= 200 chars containing prompt-shaped tokens).

Resolution

No action required.

Reference

Medium Passed
111122223333 us-east-2 OW-12
OWASP LLM07: System-Prompt-Disclosure Denied Topic
Details and remediation
Details

No Bedrock guardrails configured in us-east-2; nothing to inspect.

Resolution

No action required.

Reference

Informational N/A
111122223333 us-west-2 OW-01
OWASP LLM01: Model Invocation Logging
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: Model invocation logging is not enabled. This limits your ability to track and audit model usage.

Resolution

Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis.

Reference

Medium Failed
111122223333 us-west-2 OW-07
OWASP LLM07: Model Invocation Logging
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-04: Model invocation logging is not enabled. This limits your ability to track and audit model usage.

Resolution

Enable Bedrock model invocation logging so prompt-extraction attempts against the system prompt are auditable after the fact.

Reference

Medium Failed
111122223333 us-west-2 OW-07
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses.

Resolution

Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident.

Reference

Informational N/A
111122223333 us-west-2 OW-07
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-16: Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) is using the 'CLASSIC' content-filter tier instead of 'STANDARD'. The STANDARD tier provides more robust content filtering and broader language support than the CLASSIC tier.

Resolution

Set guardrail contentPolicy.tier.tierName to STANDARD; Standard tier additionally detects prompt-leakage attacks.

Reference

Medium Failed
111122223333 us-west-2 OW-09
OWASP LLM09: Model Evaluation Jobs
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-18: No Bedrock model evaluation jobs found. Model evaluation helps assess toxicity, accuracy, semantic robustness, and other safety metrics before production deployment.

Resolution

Run Bedrock model evaluation jobs that include correctness and safety datasets.

Reference

Medium Failed
111122223333 us-west-2 OW-08
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: Knowledge base 'knowledge-base-bedrock-agent' (ID: XSPYLN4FQL) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store.

Resolution

Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption.

Reference

Informational N/A
111122223333 us-west-2 OW-08
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: Knowledge base 'IDP-DOCUMENTBEDROCKKB-CY8N0Q7N4YDT' (ID: SUGAG7RGYD) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store.

Resolution

Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption.

Reference

Informational N/A
111122223333 us-west-2 OW-08
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: Knowledge base 'promptfoo-rag-workshop-111122223333-kb' (ID: N74ZIKTUFL) uses 'RDS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store.

Resolution

Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption.

Reference

Informational N/A
111122223333 us-west-2 OW-08
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: Knowledge base 'InvestmentResearchKB' (ID: M1GMUG3BP0) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store.

Resolution

Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption.

Reference

Informational N/A
111122223333 us-west-2 OW-08
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: Knowledge base 'knowledge-base-quick-start-xtwwd' (ID: ENFHSBBLMV) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store.

Resolution

Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption.

Reference

Informational N/A
111122223333 us-west-2 OW-08
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: Knowledge base 'kb-s3-vector-store' (ID: 116IXQU5VP) uses 'S3_VECTORS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store.

Resolution

Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption.

Reference

Informational N/A
111122223333 us-west-2 OW-06
OWASP LLM06: Agent Action-Group Least Privilege
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-21: No Bedrock agents configured in this region

Resolution

Restrict agent action-group Lambda roles to only the specific actions and resources needed for each tool.

Reference

Informational N/A
111122223333 us-west-2 OW-10
OWASP LLM10: Service Quota Throttling Limits
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-22: 7 custom throttling quotas are configured. Regular quota review helps maintain appropriate rate limits.

Resolution

Customise Bedrock TPM / RPM service quotas above the account default to establish an explicit consumption ceiling.

Reference

Low Passed
111122223333 us-west-2 OW-01
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) is missing content filters: INSULTS, HATE, SEXUAL, VIOLENCE. Complete content filter coverage is essential for comprehensive content safety.

Resolution

Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier.

Reference

High Failed
111122223333 us-west-2 OW-04
OWASP LLM04: RAG Evaluation Coverage
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: Knowledge base 'knowledge-base-bedrock-agent' (ID: XSPYLN4FQL) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations.

Resolution

Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context.

Reference

Low Failed
111122223333 us-west-2 OW-09
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-25: Knowledge base 'knowledge-base-bedrock-agent' (ID: XSPYLN4FQL) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations.

Resolution

Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates.

Reference

Low Failed
111122223333 us-west-2 OW-04
OWASP LLM04: RAG Evaluation Coverage
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: Knowledge base 'IDP-DOCUMENTBEDROCKKB-CY8N0Q7N4YDT' (ID: SUGAG7RGYD) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations.

Resolution

Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context.

Reference

Low Failed
111122223333 us-west-2 OW-09
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-25: Knowledge base 'IDP-DOCUMENTBEDROCKKB-CY8N0Q7N4YDT' (ID: SUGAG7RGYD) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations.

Resolution

Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates.

Reference

Low Failed
111122223333 us-west-2 OW-04
OWASP LLM04: RAG Evaluation Coverage
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: Knowledge base 'promptfoo-rag-workshop-111122223333-kb' (ID: N74ZIKTUFL) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations.

Resolution

Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context.

Reference

Low Failed
111122223333 us-west-2 OW-09
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-25: Knowledge base 'promptfoo-rag-workshop-111122223333-kb' (ID: N74ZIKTUFL) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations.

Resolution

Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates.

Reference

Low Failed
111122223333 us-west-2 OW-04
OWASP LLM04: RAG Evaluation Coverage
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: Knowledge base 'InvestmentResearchKB' (ID: M1GMUG3BP0) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations.

Resolution

Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context.

Reference

Low Failed
111122223333 us-west-2 OW-09
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-25: Knowledge base 'InvestmentResearchKB' (ID: M1GMUG3BP0) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations.

Resolution

Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates.

Reference

Low Failed
111122223333 us-west-2 OW-04
OWASP LLM04: RAG Evaluation Coverage
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: Knowledge base 'knowledge-base-quick-start-xtwwd' (ID: ENFHSBBLMV) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations.

Resolution

Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context.

Reference

Low Failed
111122223333 us-west-2 OW-09
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-25: Knowledge base 'knowledge-base-quick-start-xtwwd' (ID: ENFHSBBLMV) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations.

Resolution

Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates.

Reference

Low Failed
111122223333 us-west-2 OW-04
OWASP LLM04: RAG Evaluation Coverage
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: Knowledge base 'kb-s3-vector-store' (ID: 116IXQU5VP) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations.

Resolution

Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context.

Reference

Low Failed
111122223333 us-west-2 OW-09
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-25: Knowledge base 'kb-s3-vector-store' (ID: 116IXQU5VP) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations.

Resolution

Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates.

Reference

Low Failed
111122223333 us-west-2 OW-02
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check BR-26: Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) has no sensitive-information filters configured (no PII entities or regex patterns). Prompts and model responses are not screened for sensitive data such as PII.

Resolution

Configure guardrail sensitiveInformationPolicy with PII entities and regex patterns; set outputAction=ANONYMIZE or BLOCK.

Reference

High Failed
111122223333 us-west-2 OW-01
OWASP LLM01: Contextual Grounding Guardrail
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-27: Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) does not have contextual grounding checks enabled. Without grounding and relevance checks, the guardrail cannot detect hallucinated (ungrounded) or off-topic model responses.

Resolution

Enable Bedrock guardrail contextual grounding checks to reduce the surface for indirect prompt injection through retrieved context.

Reference

Medium Failed
111122223333 us-west-2 OW-04
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-27: Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) does not have contextual grounding checks enabled. Without grounding and relevance checks, the guardrail cannot detect hallucinated (ungrounded) or off-topic model responses.

Resolution

Enable contextual grounding guardrail filters so retrieved context that diverges from ground truth is filtered before reaching the model.

Reference

Medium Failed
111122223333 us-west-2 OW-09
OWASP LLM09: Contextual Grounding for Faithfulness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-27: Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) does not have contextual grounding checks enabled. Without grounding and relevance checks, the guardrail cannot detect hallucinated (ungrounded) or off-topic model responses.

Resolution

Set the contextual grounding filter threshold to at least 0.70 to reduce hallucinated responses.

Reference

Medium Failed
111122223333 us-west-2 OW-06
OWASP LLM06: Bedrock Agent Guardrail Association
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-28: No Bedrock agents configured in this region

Resolution

Attach an approved Bedrock guardrail to every Bedrock agent so autonomous actions are filtered consistently.

Reference

Informational N/A
111122223333 us-west-2 OW-06
OWASP LLM06: Agent Idle Session TTL
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-29: No Bedrock agents configured in this region

Resolution

Set idleSessionTTLInSeconds to a conservative value (e.g., <= 3600) so long-lived agent sessions cannot be reused.

Reference

Informational N/A
111122223333 us-west-2 OW-03
OWASP LLM03: Imported-Model KMS Provenance
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check BR-30: No imported custom Bedrock models found in this region

Resolution

Encrypt imported Bedrock models with a customer-managed KMS key to preserve provenance and access control across model artefacts.

Reference

Informational N/A
111122223333 us-west-2 OW-10
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-32: No CloudWatch alarms are configured on Amazon Bedrock runtime metrics (AWS/Bedrock namespace). Without alarms, abuse, denial-of-wallet, sustained throttling, and content-filter spikes can go undetected.

Resolution

Create CloudWatch alarms on Bedrock InvocationThrottles, InputTokenCount, OutputTokenCount, and EstimatedTPMQuotaUsage.

Reference

Medium Failed
111122223333 us-west-2 OW-03
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check BR-33: Amazon Inspector Lambda scanning is not fully enabled in us-west-2. Lambda standard scan status: DISABLED. Lambda code scan status: DISABLED. Detected 6 Lambda function(s) with Bedrock indicators: IDP-DOCUMENTBEDROCKKB-CY8-GetAdjustedStackNameFunc-MFYZSG0nWqdj, IDP-DOCUMENTBEDROCKKB-CY8-StartIngestionJobFunctio-QGtm6KrDTRYu, IDP-DOCUMENTBEDROCKKB-CY8N0Q7N-GetSeedUrlsFunction-vCBSeTw4AdDV, IDP-PATTERN1STACK-TNHNKPKJY-ProcessResultsFunction-xLOdarbvGDm7, IDP-QueryKnowledgeBaseResolverFunction-tkmkVZ4lgxf8 (and 1 more). Without both scan types enabled, vulnerable dependencies and hardcoded secrets in these in-scope functions will not be detected.

Resolution

Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain.

Reference

Medium Failed
111122223333 us-west-2 OW-03
OWASP LLM03: SageMaker Internet Exposure
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-01: SageMaker domain 'd-krxh4fmtaxjl' (PromptEvaluationDomain) is not configured for VPC-only access

Resolution

Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths.

Reference

High Failed
111122223333 us-west-2 OW-02
OWASP LLM02: SageMaker Data Encryption
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: Domain 'PromptEvaluationDomain' - No KMS key configured

Resolution

Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data.

Reference

High Failed
111122223333 us-west-2 OW-09
OWASP LLM09: SageMaker Clarify Evaluation
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-06: No SageMaker Clarify jobs found

Resolution

Use SageMaker Clarify to evaluate bias and explainability for models whose generated outputs can influence user decisions.

Reference

Informational N/A
111122223333 us-west-2 OW-04
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-07: No Model Monitor schedules found

Resolution

Configure active SageMaker Model Monitor schedules so data-quality and model-quality regressions caused by poisoned inputs or drift are detected.

Reference

Informational N/A
111122223333 us-west-2 OW-09
OWASP LLM09: SageMaker Model Monitor Coverage
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-07: No Model Monitor schedules found

Resolution

Configure SageMaker Model Monitor schedules for production models so quality regressions that can produce incorrect outputs are detected.

Reference

Informational N/A
111122223333 us-west-2 OW-03
OWASP LLM03: SageMaker Notebook VPC Deployment
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-10: No notebook instances found

Resolution

Deploy SageMaker notebook instances inside a VPC so package, data, and model artifact access can be controlled through private network paths.

Reference

Informational N/A
111122223333 us-west-2 OW-03
OWASP LLM03: SageMaker Model Network Isolation
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-11: No models found

Resolution

Enable network isolation on SageMaker models so inference containers cannot make unmanaged outbound calls that alter dependencies or exfiltrate model artifacts.

Reference

Informational N/A
111122223333 us-west-2 OW-10
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check SM-11: No models found

Resolution

Enable SageMaker model network isolation to prevent deployed model containers from making uncontrolled outbound calls that can amplify consumption or abuse downstream services.

Reference

Informational N/A
111122223333 us-west-2 OW-03
OWASP LLM03: SageMaker Container Repository Access
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-14: No models found or all use default Platform access

Resolution

Configure SageMaker models to pull container images from private ECR repositories through VPC repository access instead of platform or public registry paths.

Reference

Informational N/A
111122223333 us-west-2 OW-02
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-15: No feature groups with offline stores found

Resolution

Encrypt SageMaker Feature Store offline stores with customer-managed KMS keys so sensitive feature data is protected at rest.

Reference

Informational N/A
111122223333 us-west-2 OW-03
OWASP LLM03: SageMaker AutoML Network Isolation
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-21: No AutoML jobs found

Resolution

Enable network isolation on AutoML jobs so generated training containers cannot fetch unapproved dependencies or send data over unmanaged network paths.

Reference

Informational N/A
111122223333 us-west-2 OW-04
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance.

Resolution

Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically.

Reference

Informational N/A
111122223333 us-west-2 OW-09
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance.

Resolution

Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release.

Reference

Informational N/A
111122223333 us-west-2 OW-04
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-23: No InService endpoints found to monitor.

Resolution

Enable SageMaker Model Monitor drift detection for production endpoints so poisoning, data drift, and model-quality degradation are identified.

Reference

Medium Passed
111122223333 us-west-2 OW-09
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-23: No InService endpoints found to monitor.

Resolution

Configure data-quality and model-quality monitoring for SageMaker endpoints so degraded model behavior that can produce misinformation is detected.

Reference

Medium Passed
111122223333 us-west-2 OW-03
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain.

Reference

Informational N/A
111122223333 us-west-2 OW-04
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated.

Reference

Informational N/A
111122223333 us-west-2 OW-06
OWASP LLM06: AgentCore Resource-Based Policies
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check AC-10: The following AgentCore resources do not have resource-based policies: Gateway 'aws-news-mcp'. Without RBPs, access control relies solely on identity-based policies.

Resolution

Attach resource-based policies to AgentCore runtimes and gateways so caller identities are constrained.

Reference

High Failed
111122223333 us-west-2 OW-11
OWASP LLM07: System Prompt Embedded in Lambda Env Var
Details and remediation
Details

No Lambda function env vars in us-west-2 match the embedded-system-prompt heuristic (>= 200 chars containing prompt-shaped tokens).

Resolution

No action required.

Reference

Medium Passed
111122223333 us-west-2 OW-12
OWASP LLM07: System-Prompt-Disclosure Denied Topic
Details and remediation
Details

No Bedrock guardrail in us-west-2 has a DENY topic covering system-prompt disclosure. Attackers can craft prompts that ask the agent to reveal its system prompt or instructions.

Resolution

Add a DENY topic to at least one guardrail. Suggested topic name: 'SystemPromptDisclosure'. Suggested definition: 'Requests to reveal, describe, or summarise the system prompt, instructions, or internal role definition given to the assistant.'

Reference

Medium Failed
111122223333 us-west-2 BR-02
Amazon Bedrock private connectivity not used
Details and remediation
Details

No Bedrock service VPC endpoints found in VPCs: vpc-0f85a6754ab37efb7, vpc-5c3b6524, vpc-03bcafcb58a3029fc

Resolution

Create a VPC endpoint in your VPC with any of the following Bedrock service endpoints that your application may be using: - com.amazonaws.region.bedrock - com.amazonaws.region.bedrock-runtime - com.amazonaws.region.bedrock-agent - com.amazonaws.region.bedrock-agent-runtime

Reference

Medium Failed
111122223333 us-west-2 BR-04
Bedrock Model Invocation Logging Check
Details and remediation
Details

Model invocation logging is not enabled. This limits your ability to track and audit model usage.

Resolution

Enable model invocation logging to collect invocation logs, model input data, and model output data. Configure logging to deliver to Amazon S3, CloudWatch Logs, or both for comprehensive monitoring.

Reference

Medium Failed
111122223333 us-west-2 BR-05
Bedrock Guardrails Check
Details and remediation
Details

Amazon Bedrock Guardrails are properly configured with 1 guardrails

Resolution

No action required. Continue monitoring and updating guardrails as needed.

Reference

High Passed
111122223333 us-west-2 BR-06
Bedrock CloudTrail Logging Check
Details and remediation
Details

CloudTrail is properly configured to log Bedrock API activity in trails: IsengardTrail-DO-NOT-DELETE

Resolution

No action required. Continue monitoring CloudTrail logs for Bedrock activity.

Reference

Medium Passed
111122223333 us-west-2 BR-07
Bedrock Prompt Management Check
Details and remediation
Details

Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses.

Resolution

Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates

Reference

Informational N/A
111122223333 us-west-2 BR-08
Bedrock Agent IAM Roles Check
Details and remediation
Details

No Bedrock agents found in the account

Resolution

No action required

Reference

Informational N/A
111122223333 us-west-2 BR-09
Bedrock Knowledge Base Encryption Review
Details and remediation
Details

Knowledge Base 'knowledge-base-bedrock-agent' (XSPYLN4FQL) uses 'OPENSEARCH_SERVERLESS' storage. Encryption is managed at the storage layer and cannot be validated from the KB API. Verify encryption configuration on the underlying storage resource.

Resolution

1. For OpenSearch Serverless: Verify encryption with CMK at collection level 2. For S3 data sources: Verify CMK-encrypted S3 buckets 3. For RDS: Verify KMS encryption on the database 4. Consider using CMK for transient data during ingestion

Reference

Informational N/A
111122223333 us-west-2 BR-09
Bedrock Knowledge Base Encryption Review
Details and remediation
Details

Knowledge Base 'IDP-DOCUMENTBEDROCKKB-CY8N0Q7N4YDT' (SUGAG7RGYD) uses 'OPENSEARCH_SERVERLESS' storage. Encryption is managed at the storage layer and cannot be validated from the KB API. Verify encryption configuration on the underlying storage resource.

Resolution

1. For OpenSearch Serverless: Verify encryption with CMK at collection level 2. For S3 data sources: Verify CMK-encrypted S3 buckets 3. For RDS: Verify KMS encryption on the database 4. Consider using CMK for transient data during ingestion

Reference

Informational N/A
111122223333 us-west-2 BR-09
Bedrock Knowledge Base Encryption Review
Details and remediation
Details

Knowledge Base 'promptfoo-rag-workshop-111122223333-kb' (N74ZIKTUFL) uses 'RDS' storage. Encryption is managed at the storage layer and cannot be validated from the KB API. Verify encryption configuration on the underlying storage resource.

Resolution

1. For OpenSearch Serverless: Verify encryption with CMK at collection level 2. For S3 data sources: Verify CMK-encrypted S3 buckets 3. For RDS: Verify KMS encryption on the database 4. Consider using CMK for transient data during ingestion

Reference

Informational N/A
111122223333 us-west-2 BR-09
Bedrock Knowledge Base Encryption Review
Details and remediation
Details

Knowledge Base 'InvestmentResearchKB' (M1GMUG3BP0) uses 'OPENSEARCH_SERVERLESS' storage. Encryption is managed at the storage layer and cannot be validated from the KB API. Verify encryption configuration on the underlying storage resource.

Resolution

1. For OpenSearch Serverless: Verify encryption with CMK at collection level 2. For S3 data sources: Verify CMK-encrypted S3 buckets 3. For RDS: Verify KMS encryption on the database 4. Consider using CMK for transient data during ingestion

Reference

Informational N/A
111122223333 us-west-2 BR-09
Bedrock Knowledge Base Encryption Review
Details and remediation
Details

Knowledge Base 'knowledge-base-quick-start-xtwwd' (ENFHSBBLMV) uses 'OPENSEARCH_SERVERLESS' storage. Encryption is managed at the storage layer and cannot be validated from the KB API. Verify encryption configuration on the underlying storage resource.

Resolution

1. For OpenSearch Serverless: Verify encryption with CMK at collection level 2. For S3 data sources: Verify CMK-encrypted S3 buckets 3. For RDS: Verify KMS encryption on the database 4. Consider using CMK for transient data during ingestion

Reference

Informational N/A
111122223333 us-west-2 BR-09
Bedrock Knowledge Base Encryption Review
Details and remediation
Details

Knowledge Base 'kb-s3-vector-store' (116IXQU5VP) uses 'S3_VECTORS' storage. Encryption is managed at the storage layer and cannot be validated from the KB API. Verify encryption configuration on the underlying storage resource.

Resolution

1. For OpenSearch Serverless: Verify encryption with CMK at collection level 2. For S3 data sources: Verify CMK-encrypted S3 buckets 3. For RDS: Verify KMS encryption on the database 4. Consider using CMK for transient data during ingestion

Reference

Informational N/A
111122223333 us-west-2 BR-10
Bedrock Guardrail IAM Enforcement Missing
Details and remediation
Details

The following roles can invoke Bedrock models without enforced guardrails: 111122223333-us-east-1-kb-bedrock-service-role, agentcore-wildrydes_gateway_role_ab3991f6-role, AgentCoreEvalsSDK-us-east-1-d04ba7b68b, AmazonBedrockAgentCoreSDKRuntime-us-east-1-a6ddf3fc76, AmazonBedrockAgentCoreSDKRuntime-us-east-1-ed660add8b, AmazonBedrockExecutionRoleForAgents_S0T9VNPP9D, AmazonBedrockExecutionRoleForAgents_WNCOPE29NZ, AmazonBedrockExecutionRoleForKnowledgeBase_072pr, AmazonBedrockExecutionRoleForKnowledgeBase_byjin, AmazonBedrockExecutionRoleForKnowledgeBase_h9718...

Resolution

Add IAM policy conditions to enforce guardrail usage: 1. Use 'bedrock:GuardrailIdentifier' condition key 2. Specify required guardrail ARN or ID 3. Example: "Condition": {"StringEquals": {"bedrock:GuardrailIdentifier": "arn:aws:bedrock:region:account:guardrail/guardrail-id"}}

Reference

High Failed
111122223333 us-west-2 BR-11
Bedrock Custom Model Encryption Check
Details and remediation
Details

No custom/fine-tuned models found in the account

Resolution

No action required

Reference

Informational N/A
111122223333 us-west-2 BR-12
Bedrock Invocation Log Encryption Check
Details and remediation
Details

Model invocation logging to S3 is not configured

Resolution

If logging is enabled to CloudWatch only, ensure CloudWatch log group uses CMK encryption

Reference

Informational N/A
111122223333 us-west-2 BR-13
Bedrock Flows Guardrails Check
Details and remediation
Details

No Bedrock Flows found in the account

Resolution

No action required

Reference

Informational N/A
111122223333 us-west-2 BR-16
Guardrail Tier Validation Check
Details and remediation
Details

Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) is using the 'CLASSIC' content-filter tier instead of 'STANDARD'. The STANDARD tier provides more robust content filtering and broader language support than the CLASSIC tier.

Resolution

Update the guardrail to use the STANDARD content-filter tier for improved contextual understanding, better prompt attack filtering (distinguishing jailbreaks from prompt injection), and broader language support. The STANDARD tier requires cross-Region inference. Review pricing implications before upgrading.

Reference

Medium Failed
111122223333 us-west-2 BR-17
Custom Model Customer-Managed KMS Encryption Check
Details and remediation
Details

No custom (fine-tuned) Bedrock models found in this region

Resolution

When creating custom models, specify a customer-managed KMS key for encryption to maintain control over encryption keys

Reference

High N/A
111122223333 us-west-2 BR-18
Model Evaluation Implementation Check
Details and remediation
Details

No Bedrock model evaluation jobs found. Model evaluation helps assess toxicity, accuracy, semantic robustness, and other safety metrics before production deployment.

Resolution

Create model evaluation jobs using Amazon Bedrock Evaluations to assess foundation model performance against safety and quality metrics. Use built-in datasets or custom test sets. Enable LLM-as-a-judge evaluation for comprehensive assessment.

Reference

Medium Failed
111122223333 us-west-2 BR-19
Prompt Flow Validation Check
Details and remediation
Details

No Bedrock prompt flows configured in this region

Resolution

When creating prompt flows, use the ValidateFlowDefinition API to validate flow definitions before deployment

Reference

Medium N/A
111122223333 us-west-2 BR-20
Knowledge Base Customer-Managed KMS Encryption Review
Details and remediation
Details

Knowledge base 'knowledge-base-bedrock-agent' (ID: XSPYLN4FQL) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store.

Resolution

1. For OpenSearch Serverless: verify the collection uses a customer-managed KMS key 2. For Amazon RDS/Aurora: verify KMS encryption on the database 3. For third-party stores (Pinecone, Redis, MongoDB): verify the provider's encryption configuration 4. Verify the customer-managed KMS key used for transient data during ingestion

Reference

Informational N/A
111122223333 us-west-2 BR-20
Knowledge Base Customer-Managed KMS Encryption Review
Details and remediation
Details

Knowledge base 'IDP-DOCUMENTBEDROCKKB-CY8N0Q7N4YDT' (ID: SUGAG7RGYD) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store.

Resolution

1. For OpenSearch Serverless: verify the collection uses a customer-managed KMS key 2. For Amazon RDS/Aurora: verify KMS encryption on the database 3. For third-party stores (Pinecone, Redis, MongoDB): verify the provider's encryption configuration 4. Verify the customer-managed KMS key used for transient data during ingestion

Reference

Informational N/A
111122223333 us-west-2 BR-20
Knowledge Base Customer-Managed KMS Encryption Review
Details and remediation
Details

Knowledge base 'promptfoo-rag-workshop-111122223333-kb' (ID: N74ZIKTUFL) uses 'RDS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store.

Resolution

1. For OpenSearch Serverless: verify the collection uses a customer-managed KMS key 2. For Amazon RDS/Aurora: verify KMS encryption on the database 3. For third-party stores (Pinecone, Redis, MongoDB): verify the provider's encryption configuration 4. Verify the customer-managed KMS key used for transient data during ingestion

Reference

Informational N/A
111122223333 us-west-2 BR-20
Knowledge Base Customer-Managed KMS Encryption Review
Details and remediation
Details

Knowledge base 'InvestmentResearchKB' (ID: M1GMUG3BP0) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store.

Resolution

1. For OpenSearch Serverless: verify the collection uses a customer-managed KMS key 2. For Amazon RDS/Aurora: verify KMS encryption on the database 3. For third-party stores (Pinecone, Redis, MongoDB): verify the provider's encryption configuration 4. Verify the customer-managed KMS key used for transient data during ingestion

Reference

Informational N/A
111122223333 us-west-2 BR-20
Knowledge Base Customer-Managed KMS Encryption Review
Details and remediation
Details

Knowledge base 'knowledge-base-quick-start-xtwwd' (ID: ENFHSBBLMV) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store.

Resolution

1. For OpenSearch Serverless: verify the collection uses a customer-managed KMS key 2. For Amazon RDS/Aurora: verify KMS encryption on the database 3. For third-party stores (Pinecone, Redis, MongoDB): verify the provider's encryption configuration 4. Verify the customer-managed KMS key used for transient data during ingestion

Reference

Informational N/A
111122223333 us-west-2 BR-20
Knowledge Base Customer-Managed KMS Encryption Review
Details and remediation
Details

Knowledge base 'kb-s3-vector-store' (ID: 116IXQU5VP) uses 'S3_VECTORS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store.

Resolution

1. For OpenSearch Serverless: verify the collection uses a customer-managed KMS key 2. For Amazon RDS/Aurora: verify KMS encryption on the database 3. For third-party stores (Pinecone, Redis, MongoDB): verify the provider's encryption configuration 4. Verify the customer-managed KMS key used for transient data during ingestion

Reference

Informational N/A
111122223333 us-west-2 BR-21
Agent Action Group IAM Least Privilege Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents with action groups, ensure Lambda execution roles follow least privilege principles

Reference

High N/A
111122223333 us-west-2 BR-22
Model Invocation Throttling Limits Check
Details and remediation
Details

7 custom throttling quotas are configured. Regular quota review helps maintain appropriate rate limits.

Resolution

Continue monitoring quota utilization. Review and adjust quotas as application requirements change.

Reference

Low Passed
111122223333 us-west-2 BR-23
Guardrail Content Filter Coverage Check
Details and remediation
Details

Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) is missing content filters: INSULTS, HATE, SEXUAL, VIOLENCE. Complete content filter coverage is essential for comprehensive content safety.

Resolution

Update guardrail to enable all content filters (HATE, INSULTS, SEXUAL, VIOLENCE). Configure appropriate threshold levels (LOW, MEDIUM, HIGH) for both input and output filtering based on your use case. Review AWS documentation for threshold guidance.

Reference

High Failed
111122223333 us-west-2 BR-24
Automated Reasoning Policy Implementation Check
Details and remediation
Details

Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) does not have an Automated Reasoning policy configured. Automated Reasoning provides formal verification of model responses against defined policies.

Resolution

Configure Automated Reasoning policies on guardrails to mathematically verify model responses. Define policies that specify allowed and disallowed behaviors. Use for high-assurance use cases where formal verification is required.

Reference

Medium Failed
111122223333 us-west-2 BR-25
RAG Evaluation Jobs Check
Details and remediation
Details

Knowledge base 'knowledge-base-bedrock-agent' (ID: XSPYLN4FQL) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations.

Resolution

Create RAG evaluation jobs for knowledge bases using Amazon Bedrock Model Evaluation. Configure evaluations to test context relevance, answer correctness, and faithfulness metrics. Run evaluations regularly (monthly or after significant KB updates) to maintain quality.

Reference

Low Failed
111122223333 us-west-2 BR-25
RAG Evaluation Jobs Check
Details and remediation
Details

Knowledge base 'IDP-DOCUMENTBEDROCKKB-CY8N0Q7N4YDT' (ID: SUGAG7RGYD) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations.

Resolution

Create RAG evaluation jobs for knowledge bases using Amazon Bedrock Model Evaluation. Configure evaluations to test context relevance, answer correctness, and faithfulness metrics. Run evaluations regularly (monthly or after significant KB updates) to maintain quality.

Reference

Low Failed
111122223333 us-west-2 BR-25
RAG Evaluation Jobs Check
Details and remediation
Details

Knowledge base 'promptfoo-rag-workshop-111122223333-kb' (ID: N74ZIKTUFL) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations.

Resolution

Create RAG evaluation jobs for knowledge bases using Amazon Bedrock Model Evaluation. Configure evaluations to test context relevance, answer correctness, and faithfulness metrics. Run evaluations regularly (monthly or after significant KB updates) to maintain quality.

Reference

Low Failed
111122223333 us-west-2 BR-25
RAG Evaluation Jobs Check
Details and remediation
Details

Knowledge base 'InvestmentResearchKB' (ID: M1GMUG3BP0) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations.

Resolution

Create RAG evaluation jobs for knowledge bases using Amazon Bedrock Model Evaluation. Configure evaluations to test context relevance, answer correctness, and faithfulness metrics. Run evaluations regularly (monthly or after significant KB updates) to maintain quality.

Reference

Low Failed
111122223333 us-west-2 BR-25
RAG Evaluation Jobs Check
Details and remediation
Details

Knowledge base 'knowledge-base-quick-start-xtwwd' (ID: ENFHSBBLMV) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations.

Resolution

Create RAG evaluation jobs for knowledge bases using Amazon Bedrock Model Evaluation. Configure evaluations to test context relevance, answer correctness, and faithfulness metrics. Run evaluations regularly (monthly or after significant KB updates) to maintain quality.

Reference

Low Failed
111122223333 us-west-2 BR-25
RAG Evaluation Jobs Check
Details and remediation
Details

Knowledge base 'kb-s3-vector-store' (ID: 116IXQU5VP) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations.

Resolution

Create RAG evaluation jobs for knowledge bases using Amazon Bedrock Model Evaluation. Configure evaluations to test context relevance, answer correctness, and faithfulness metrics. Run evaluations regularly (monthly or after significant KB updates) to maintain quality.

Reference

Low Failed
111122223333 us-west-2 BR-26
Guardrail Sensitive Information Filter Check
Details and remediation
Details

Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) has no sensitive-information filters configured (no PII entities or regex patterns). Prompts and model responses are not screened for sensitive data such as PII.

Resolution

Configure sensitive-information filters on the guardrail: add PII entity types (e.g. NAME, EMAIL, SSN, CREDIT_DEBIT_CARD_NUMBER) and/or custom regex patterns, and set the appropriate BLOCK or ANONYMIZE action for input and output.

Reference

High Failed
111122223333 us-west-2 BR-27
Guardrail Contextual Grounding Check
Details and remediation
Details

Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) does not have contextual grounding checks enabled. Without grounding and relevance checks, the guardrail cannot detect hallucinated (ungrounded) or off-topic model responses.

Resolution

Enable contextual grounding checks (GROUNDING and RELEVANCE filter types) on the guardrail with appropriate thresholds. This is especially important for RAG applications to ensure responses are grounded in the retrieved source material.

Reference

Medium Failed
111122223333 us-west-2 BR-28
Agent Guardrail Association Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents, associate a Bedrock guardrail so agent inputs and responses are filtered for harmful content, PII, and denied topics

Reference

High N/A
111122223333 us-west-2 BR-29
Agent Idle Session TTL Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents, set a conservative idleSessionTTLInSeconds to limit how long an idle session remains resumable

Reference

Low N/A
111122223333 us-west-2 BR-30
Imported Model Customer-Managed KMS Encryption Check
Details and remediation
Details

No imported custom Bedrock models found in this region

Resolution

When importing models, specify a customer-managed KMS key for encryption to maintain control over encryption keys

Reference

High N/A
111122223333 us-west-2 BR-31
Batch Inference Output Encryption Check
Details and remediation
Details

No Bedrock batch inference (model invocation) jobs found in this region

Resolution

When creating batch inference jobs, set outputDataConfig.s3OutputDataConfig.s3EncryptionKeyId to a customer-managed KMS key to encrypt the job output

Reference

Medium N/A
111122223333 us-west-2 BR-32
Bedrock CloudWatch Alarm Check
Details and remediation
Details

No CloudWatch alarms are configured on Amazon Bedrock runtime metrics (AWS/Bedrock namespace). Without alarms, abuse, denial-of-wallet, sustained throttling, and content-filter spikes can go undetected.

Resolution

Create CloudWatch alarms on AWS/Bedrock runtime metrics such as Invocations, InvocationThrottles, InputTokenCount, OutputTokenCount, and ContentFilteredCount, and route them to an Amazon SNS topic for notification.

Reference

Medium Failed
111122223333 us-west-2 BR-33
Amazon Inspector Lambda Code Scanning Check
Details and remediation
Details

Amazon Inspector Lambda scanning is not fully enabled in us-west-2. Lambda standard scan status: DISABLED. Lambda code scan status: DISABLED. Detected 6 Lambda function(s) with Bedrock indicators: IDP-DOCUMENTBEDROCKKB-CY8-GetAdjustedStackNameFunc-MFYZSG0nWqdj, IDP-DOCUMENTBEDROCKKB-CY8-StartIngestionJobFunctio-QGtm6KrDTRYu, IDP-DOCUMENTBEDROCKKB-CY8N0Q7N-GetSeedUrlsFunction-vCBSeTw4AdDV, IDP-PATTERN1STACK-TNHNKPKJY-ProcessResultsFunction-xLOdarbvGDm7, IDP-QueryKnowledgeBaseResolverFunction-tkmkVZ4lgxf8 (and 1 more). Without both scan types enabled, vulnerable dependencies and hardcoded secrets in these in-scope functions will not be detected.

Resolution

Enable both Lambda standard scanning and Lambda code scanning in Amazon Inspector for this account and region. Console: Inspector -> Account management -> Activate for Lambda functions and Lambda code.

Reference

Medium Failed
111122223333 us-west-2 AG-07
Agentic AI Model Invocation Logging
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: Model invocation logging is not enabled. This limits your ability to track and audit model usage.

Resolution

Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements.

Reference

Medium Failed
111122223333 us-west-2 AG-08
Agentic AI API Audit Trail
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: CloudTrail is properly configured to log Bedrock API activity in trails: IsengardTrail-DO-NOT-DELETE

Resolution

Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured.

Reference

Medium Passed
111122223333 us-west-2 AG-10
Agentic AI Adversarial Evaluation Coverage
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No Bedrock model evaluation jobs found. Model evaluation helps assess toxicity, accuracy, semantic robustness, and other safety metrics before production deployment.

Resolution

Configure model or application evaluations that include adversarial, safety, and security-relevant test cases.

Reference

Medium Failed
111122223333 us-west-2 AG-11
Agentic AI Prompt Flow Validation
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region

Resolution

Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions.

Reference

Informational N/A
111122223333 us-west-2 AG-06
Agentic AI Tool Execution Least Privilege
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region

Resolution

Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required.

Reference

Informational N/A
111122223333 us-west-2 AG-12
Agentic AI Invocation Abuse Controls
Details and remediation
Details

Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: 7 custom throttling quotas are configured. Regular quota review helps maintain appropriate rate limits.

Resolution

Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns.

Reference

Low Passed
111122223333 us-west-2 AG-02
Agentic AI Harmful Content Guardrail Coverage
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) is missing content filters: INSULTS, HATE, SEXUAL, VIOLENCE. Complete content filter coverage is essential for comprehensive content safety.

Resolution

Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads.

Reference

High Failed
111122223333 us-west-2 AG-04
Agentic AI Automated Reasoning Guardrails
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) does not have an Automated Reasoning policy configured. Automated Reasoning provides formal verification of model responses against defined policies.

Resolution

Configure automated reasoning policies on guardrails where formal response validation is required.

Reference

Medium Failed
111122223333 us-west-2 AG-03
Agentic AI Sensitive Information Protection
Details and remediation
Details

Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) has no sensitive-information filters configured (no PII entities or regex patterns). Prompts and model responses are not screened for sensitive data such as PII.

Resolution

Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns.

Reference

High Failed
111122223333 us-west-2 AG-05
Agentic AI Grounding Controls
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: Guardrail 'Sample-Guardrail' (ID: mmi5rrre65gv) does not have contextual grounding checks enabled. Without grounding and relevance checks, the guardrail cannot detect hallucinated (ungrounded) or off-topic model responses.

Resolution

Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows.

Reference

Medium Failed
111122223333 us-west-2 AG-01
Agentic AI Agent Guardrail Association
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region

Resolution

Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating.

Reference

Informational N/A
111122223333 us-west-2 AG-13
Agentic AI Session Boundary
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region

Resolution

Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements.

Reference

Informational N/A
111122223333 us-west-2 AG-14
Agentic AI Operational Abuse Alarms
Details and remediation
Details

Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No CloudWatch alarms are configured on Amazon Bedrock runtime metrics (AWS/Bedrock namespace). Without alarms, abuse, denial-of-wallet, sustained throttling, and content-filter spikes can go undetected.

Resolution

Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available.

Reference

Medium Failed
111122223333 us-east-1 OW-01
OWASP LLM01: Model Invocation Logging
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: Model invocation logging is properly configured with delivery to: Amazon S3, CloudWatch Logs

Resolution

Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis.

Reference

Medium Passed
111122223333 us-east-1 OW-07
OWASP LLM07: Model Invocation Logging
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-04: Model invocation logging is properly configured with delivery to: Amazon S3, CloudWatch Logs

Resolution

Enable Bedrock model invocation logging so prompt-extraction attempts against the system prompt are auditable after the fact.

Reference

Medium Passed
111122223333 us-east-1 OW-07
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses.

Resolution

Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident.

Reference

Informational N/A
111122223333 us-east-1 OW-07
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-16: Guardrail 'nist-ai-rmf-guardrail' (ID: do7xkmhadx7k) is using the 'CLASSIC' content-filter tier instead of 'STANDARD'. The STANDARD tier provides more robust content filtering and broader language support than the CLASSIC tier.

Resolution

Set guardrail contentPolicy.tier.tierName to STANDARD; Standard tier additionally detects prompt-leakage attacks.

Reference

Medium Failed
111122223333 us-east-1 OW-09
OWASP LLM09: Model Evaluation Jobs
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-18: No Bedrock model evaluation jobs found. Model evaluation helps assess toxicity, accuracy, semantic robustness, and other safety metrics before production deployment.

Resolution

Run Bedrock model evaluation jobs that include correctness and safety datasets.

Reference

Medium Failed
111122223333 us-east-1 OW-08
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: Knowledge base 'knowledge-base-semiconductors' (ID: RQYFDSE1LT) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store.

Resolution

Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption.

Reference

Informational N/A
111122223333 us-east-1 OW-08
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: Knowledge base '111122223333-us-east-1-kb' (ID: PAJOKBSIMQ) uses 'S3_VECTORS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store.

Resolution

Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption.

Reference

Informational N/A
111122223333 us-east-1 OW-08
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: Knowledge base 'e2e-rag-knowledgebase' (ID: ESIYAYSYTJ) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store.

Resolution

Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption.

Reference

Informational N/A
111122223333 us-east-1 OW-06
OWASP LLM06: Agent Action-Group Least Privilege
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-21: No Bedrock agents configured in this region

Resolution

Restrict agent action-group Lambda roles to only the specific actions and resources needed for each tool.

Reference

Informational N/A
111122223333 us-east-1 OW-10
OWASP LLM10: Service Quota Throttling Limits
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-22: 11 custom throttling quotas are configured. Regular quota review helps maintain appropriate rate limits.

Resolution

Customise Bedrock TPM / RPM service quotas above the account default to establish an explicit consumption ceiling.

Reference

Low Passed
111122223333 us-east-1 OW-01
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: 1 guardrails have complete content filter coverage (hate, insults, sexual, violence)

Resolution

Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier.

Reference

Low Passed
111122223333 us-east-1 OW-04
OWASP LLM04: RAG Evaluation Coverage
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: Knowledge base 'knowledge-base-semiconductors' (ID: RQYFDSE1LT) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations.

Resolution

Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context.

Reference

Low Failed
111122223333 us-east-1 OW-09
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-25: Knowledge base 'knowledge-base-semiconductors' (ID: RQYFDSE1LT) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations.

Resolution

Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates.

Reference

Low Failed
111122223333 us-east-1 OW-04
OWASP LLM04: RAG Evaluation Coverage
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: Knowledge base '111122223333-us-east-1-kb' (ID: PAJOKBSIMQ) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations.

Resolution

Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context.

Reference

Low Failed
111122223333 us-east-1 OW-09
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-25: Knowledge base '111122223333-us-east-1-kb' (ID: PAJOKBSIMQ) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations.

Resolution

Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates.

Reference

Low Failed
111122223333 us-east-1 OW-04
OWASP LLM04: RAG Evaluation Coverage
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: Knowledge base 'e2e-rag-knowledgebase' (ID: ESIYAYSYTJ) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations.

Resolution

Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context.

Reference

Low Failed
111122223333 us-east-1 OW-09
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-25: Knowledge base 'e2e-rag-knowledgebase' (ID: ESIYAYSYTJ) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations.

Resolution

Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates.

Reference

Low Failed
111122223333 us-east-1 OW-02
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check BR-26: 1 guardrails have sensitive-information (PII) filters configured

Resolution

Configure guardrail sensitiveInformationPolicy with PII entities and regex patterns; set outputAction=ANONYMIZE or BLOCK.

Reference

Low Passed
111122223333 us-east-1 OW-01
OWASP LLM01: Contextual Grounding Guardrail
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-27: 1 guardrails have contextual grounding checks enabled

Resolution

Enable Bedrock guardrail contextual grounding checks to reduce the surface for indirect prompt injection through retrieved context.

Reference

Low Passed
111122223333 us-east-1 OW-04
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-27: 1 guardrails have contextual grounding checks enabled

Resolution

Enable contextual grounding guardrail filters so retrieved context that diverges from ground truth is filtered before reaching the model.

Reference

Low Passed
111122223333 us-east-1 OW-09
OWASP LLM09: Contextual Grounding for Faithfulness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-27: 1 guardrails have contextual grounding checks enabled

Resolution

Set the contextual grounding filter threshold to at least 0.70 to reduce hallucinated responses.

Reference

Low Passed
111122223333 us-east-1 OW-06
OWASP LLM06: Bedrock Agent Guardrail Association
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-28: No Bedrock agents configured in this region

Resolution

Attach an approved Bedrock guardrail to every Bedrock agent so autonomous actions are filtered consistently.

Reference

Informational N/A
111122223333 us-east-1 OW-06
OWASP LLM06: Agent Idle Session TTL
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-29: No Bedrock agents configured in this region

Resolution

Set idleSessionTTLInSeconds to a conservative value (e.g., <= 3600) so long-lived agent sessions cannot be reused.

Reference

Informational N/A
111122223333 us-east-1 OW-03
OWASP LLM03: Imported-Model KMS Provenance
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check BR-30: No imported custom Bedrock models found in this region

Resolution

Encrypt imported Bedrock models with a customer-managed KMS key to preserve provenance and access control across model artefacts.

Reference

Informational N/A
111122223333 us-east-1 OW-10
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-32: No CloudWatch alarms are configured on Amazon Bedrock runtime metrics (AWS/Bedrock namespace). Without alarms, abuse, denial-of-wallet, sustained throttling, and content-filter spikes can go undetected.

Resolution

Create CloudWatch alarms on Bedrock InvocationThrottles, InputTokenCount, OutputTokenCount, and EstimatedTPMQuotaUsage.

Reference

Medium Failed
111122223333 us-east-1 OW-03
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check BR-33: Amazon Inspector Lambda scanning is not fully enabled in us-east-1. Lambda standard scan status: ENABLED. Lambda code scan status: DISABLED. Detected 6 Lambda function(s) with Bedrock indicators: aiml-security-aiml-security-111122223333-BedrockAssessment, e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk, gateway_lambda, myAskMeAnything, resco-aiml-BedrockAssessment (and 1 more). Without both scan types enabled, vulnerable dependencies and hardcoded secrets in these in-scope functions will not be detected.

Resolution

Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain.

Reference

Medium Failed
111122223333 us-east-1 OW-03
OWASP LLM03: SageMaker Internet Exposure
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-01: SageMaker domain 'd-cz8qi7j81si3' (QuickSetupDomain-20250525T153160) is not configured for VPC-only access

Resolution

Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths.

Reference

High Failed
111122223333 us-east-1 OW-02
OWASP LLM02: SageMaker Data Encryption
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: Domain 'QuickSetupDomain-20250525T153160' - No KMS key configured

Resolution

Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data.

Reference

High Failed
111122223333 us-east-1 OW-09
OWASP LLM09: SageMaker Clarify Evaluation
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-06: No SageMaker Clarify jobs found

Resolution

Use SageMaker Clarify to evaluate bias and explainability for models whose generated outputs can influence user decisions.

Reference

Informational N/A
111122223333 us-east-1 OW-04
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-07: No Model Monitor schedules found

Resolution

Configure active SageMaker Model Monitor schedules so data-quality and model-quality regressions caused by poisoned inputs or drift are detected.

Reference

Informational N/A
111122223333 us-east-1 OW-09
OWASP LLM09: SageMaker Model Monitor Coverage
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-07: No Model Monitor schedules found

Resolution

Configure SageMaker Model Monitor schedules for production models so quality regressions that can produce incorrect outputs are detected.

Reference

Informational N/A
111122223333 us-east-1 OW-03
OWASP LLM03: SageMaker Notebook VPC Deployment
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-10: No notebook instances found

Resolution

Deploy SageMaker notebook instances inside a VPC so package, data, and model artifact access can be controlled through private network paths.

Reference

Informational N/A
111122223333 us-east-1 OW-03
OWASP LLM03: SageMaker Model Network Isolation
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-11: No models found

Resolution

Enable network isolation on SageMaker models so inference containers cannot make unmanaged outbound calls that alter dependencies or exfiltrate model artifacts.

Reference

Informational N/A
111122223333 us-east-1 OW-10
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check SM-11: No models found

Resolution

Enable SageMaker model network isolation to prevent deployed model containers from making uncontrolled outbound calls that can amplify consumption or abuse downstream services.

Reference

Informational N/A
111122223333 us-east-1 OW-03
OWASP LLM03: SageMaker Container Repository Access
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-14: No models found or all use default Platform access

Resolution

Configure SageMaker models to pull container images from private ECR repositories through VPC repository access instead of platform or public registry paths.

Reference

Informational N/A
111122223333 us-east-1 OW-02
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-15: No feature groups with offline stores found

Resolution

Encrypt SageMaker Feature Store offline stores with customer-managed KMS keys so sensitive feature data is protected at rest.

Reference

Informational N/A
111122223333 us-east-1 OW-03
OWASP LLM03: SageMaker AutoML Network Isolation
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-21: No AutoML jobs found

Resolution

Enable network isolation on AutoML jobs so generated training containers cannot fetch unapproved dependencies or send data over unmanaged network paths.

Reference

Informational N/A
111122223333 us-east-1 OW-04
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance.

Resolution

Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically.

Reference

Informational N/A
111122223333 us-east-1 OW-09
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance.

Resolution

Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release.

Reference

Informational N/A
111122223333 us-east-1 OW-04
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-23: No InService endpoints found to monitor.

Resolution

Enable SageMaker Model Monitor drift detection for production endpoints so poisoning, data drift, and model-quality degradation are identified.

Reference

Medium Passed
111122223333 us-east-1 OW-09
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-23: No InService endpoints found to monitor.

Resolution

Configure data-quality and model-quality monitoring for SageMaker endpoints so degraded model behavior that can produce misinformation is detected.

Reference

Medium Passed
111122223333 us-east-1 OW-03
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain.

Reference

Informational N/A
111122223333 us-east-1 OW-04
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated.

Reference

Informational N/A
111122223333 Global OW-06
OWASP LLM06: AgentCore IAM Least Privilege
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check AC-02: The following roles have BedrockAgentCoreFullAccess policy: AmazonSageMaker-ExecutionRole-20250525T153161

Resolution

Remove AmazonBedrockAgentCoreFullAccess (or equivalents) from identities that only need read/execute permissions.

Reference

High Failed
111122223333 Global OW-06
OWASP LLM06: AgentCore IAM Least Privilege
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check AC-02: The following roles have wildcard AgentCore permissions on all resources: agentcore-wildrydes_gateway_role_ab3991f6-role

Resolution

Remove AmazonBedrockAgentCoreFullAccess (or equivalents) from identities that only need read/execute permissions.

Reference

High Failed
111122223333 us-east-1 OW-06
OWASP LLM06: AgentCore Resource-Based Policies
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check AC-10: The following AgentCore resources do not have resource-based policies: Runtime 'origami_expeditions', Runtime 'neoCyan_Agent', Runtime 'customer_support_agent', Runtime 'cdk_agent_core', Runtime 'awsapimcpserver' and 2 more. Without RBPs, access control relies solely on identity-based policies.

Resolution

Attach resource-based policies to AgentCore runtimes and gateways so caller identities are constrained.

Reference

High Failed
111122223333 us-east-1 OW-10
OWASP LLM10: WAF Rate-Based & Shield Protection
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-01: AWS Shield Advanced is not subscribed. GenAI API endpoints are vulnerable to volumetric DDoS attacks that can exhaust token quotas and inflate costs.

Resolution

Add a WAF RateBasedStatement plus a SizeConstraintStatement on the GenAI ingress and subscribe to AWS Shield Advanced.

Reference

Low Failed
111122223333 us-east-2 OW-10
OWASP LLM10: WAF Rate-Based & Shield Protection
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-01: AWS Shield Advanced is not subscribed. GenAI API endpoints are vulnerable to volumetric DDoS attacks that can exhaust token quotas and inflate costs.

Resolution

Add a WAF RateBasedStatement plus a SizeConstraintStatement on the GenAI ingress and subscribe to AWS Shield Advanced.

Reference

Low Failed
111122223333 us-west-2 OW-10
OWASP LLM10: WAF Rate-Based & Shield Protection
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-01: AWS Shield Advanced is not subscribed. GenAI API endpoints are vulnerable to volumetric DDoS attacks that can exhaust token quotas and inflate costs.

Resolution

Add a WAF RateBasedStatement plus a SizeConstraintStatement on the GenAI ingress and subscribe to AWS Shield Advanced.

Reference

Low Failed
111122223333 us-east-1 OW-10
OWASP LLM10: WAF Rate-Based & Shield Protection
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-01: No AWS WAF regional Web ACLs found. Without WAF, GenAI endpoints lack rate-based rules to block abusive callers.

Resolution

Add a WAF RateBasedStatement plus a SizeConstraintStatement on the GenAI ingress and subscribe to AWS Shield Advanced.

Reference

Medium Failed
111122223333 us-east-2 OW-10
OWASP LLM10: WAF Rate-Based & Shield Protection
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-01: No AWS WAF regional Web ACLs found. Without WAF, GenAI endpoints lack rate-based rules to block abusive callers.

Resolution

Add a WAF RateBasedStatement plus a SizeConstraintStatement on the GenAI ingress and subscribe to AWS Shield Advanced.

Reference

Medium Failed
111122223333 us-west-2 OW-10
OWASP LLM10: WAF Rate-Based & Shield Protection
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-01: No AWS WAF regional Web ACLs found. Without WAF, GenAI endpoints lack rate-based rules to block abusive callers.

Resolution

Add a WAF RateBasedStatement plus a SizeConstraintStatement on the GenAI ingress and subscribe to AWS Shield Advanced.

Reference

Medium Failed
111122223333 us-east-1 OW-10
OWASP LLM10: API Gateway Usage Plans
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-02: Usage plans without throttling: myAskMeAnything-UsagePlan. Unbounded API calls can exhaust Bedrock token quotas and inflate costs.

Resolution

Attach API Gateway Usage Plans with non-zero rateLimit / burstLimit to any REST APIs that proxy Bedrock.

Reference

Medium Failed
111122223333 us-east-2 OW-10
OWASP LLM10: API Gateway Usage Plans
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-02: Usage plans without throttling: myAskMeAnything-UsagePlan. Unbounded API calls can exhaust Bedrock token quotas and inflate costs.

Resolution

Attach API Gateway Usage Plans with non-zero rateLimit / burstLimit to any REST APIs that proxy Bedrock.

Reference

Medium Failed
111122223333 us-west-2 OW-10
OWASP LLM10: API Gateway Usage Plans
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-02: Usage plans without throttling: myAskMeAnything-UsagePlan. Unbounded API calls can exhaust Bedrock token quotas and inflate costs.

Resolution

Attach API Gateway Usage Plans with non-zero rateLimit / burstLimit to any REST APIs that proxy Bedrock.

Reference

Medium Failed
111122223333 us-east-1 OW-10
OWASP LLM10: Bedrock TPM/RPM Quotas Customised
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-03: Found 240 Bedrock token-based quota(s); at least one applied value exceeds the AWS default, indicating quotas have been reviewed and raised.

Resolution

Customise Bedrock service quotas above the account default so consumption is explicitly bounded.

Reference

Medium Passed
111122223333 us-east-2 OW-10
OWASP LLM10: Bedrock TPM/RPM Quotas Customised
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-03: Found 240 Bedrock token-based quota(s); at least one applied value exceeds the AWS default, indicating quotas have been reviewed and raised.

Resolution

Customise Bedrock service quotas above the account default so consumption is explicitly bounded.

Reference

Medium Passed
111122223333 us-west-2 OW-10
OWASP LLM10: Bedrock TPM/RPM Quotas Customised
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-03: Found 240 Bedrock token-based quota(s); at least one applied value exceeds the AWS default, indicating quotas have been reviewed and raised.

Resolution

Customise Bedrock service quotas above the account default so consumption is explicitly bounded.

Reference

Medium Passed
111122223333 us-east-1 OW-10
OWASP LLM10: Cost Anomaly Detection
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-04: No AWS Cost Anomaly Detection monitors found. Unexpected spikes in Bedrock/SageMaker usage (e.g., from prompt injection loops) will go undetected.

Resolution

Configure AWS Cost Anomaly Detection monitors that include Bedrock and SageMaker.

Reference

Medium Failed
111122223333 us-east-2 OW-10
OWASP LLM10: Cost Anomaly Detection
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-04: No AWS Cost Anomaly Detection monitors found. Unexpected spikes in Bedrock/SageMaker usage (e.g., from prompt injection loops) will go undetected.

Resolution

Configure AWS Cost Anomaly Detection monitors that include Bedrock and SageMaker.

Reference

Medium Failed
111122223333 us-west-2 OW-10
OWASP LLM10: Cost Anomaly Detection
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-04: No AWS Cost Anomaly Detection monitors found. Unexpected spikes in Bedrock/SageMaker usage (e.g., from prompt injection loops) will go undetected.

Resolution

Configure AWS Cost Anomaly Detection monitors that include Bedrock and SageMaker.

Reference

Medium Failed
111122223333 us-east-1 OW-10
OWASP LLM10: Token / Throttle Alarms
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-05: No CloudWatch alarms found for Bedrock metrics. Token exhaustion and throttling events will not trigger operational alerts.

Resolution

Create CloudWatch alarms on the Bedrock namespace for InvocationThrottles and token counters.

Reference

Medium Failed
111122223333 us-east-2 OW-10
OWASP LLM10: Token / Throttle Alarms
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-05: No CloudWatch alarms found for Bedrock metrics. Token exhaustion and throttling events will not trigger operational alerts.

Resolution

Create CloudWatch alarms on the Bedrock namespace for InvocationThrottles and token counters.

Reference

Medium Failed
111122223333 us-west-2 OW-10
OWASP LLM10: Token / Throttle Alarms
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-05: No CloudWatch alarms found for Bedrock metrics. Token exhaustion and throttling events will not trigger operational alerts.

Resolution

Create CloudWatch alarms on the Bedrock namespace for InvocationThrottles and token counters.

Reference

Medium Failed
111122223333 us-east-1 OW-10
OWASP LLM10: AWS Budgets with Bedrock Filters
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-06: No AWS Budgets found scoped to Bedrock or SageMaker. Unbounded GenAI spend can go undetected until the monthly bill.

Resolution

Configure AWS Budgets with FilterExpression / CostFilters targeting Bedrock or SageMaker spend, with an alerting SNS action.

Reference

Medium Failed
111122223333 us-east-2 OW-10
OWASP LLM10: AWS Budgets with Bedrock Filters
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-06: No AWS Budgets found scoped to Bedrock or SageMaker. Unbounded GenAI spend can go undetected until the monthly bill.

Resolution

Configure AWS Budgets with FilterExpression / CostFilters targeting Bedrock or SageMaker spend, with an alerting SNS action.

Reference

Medium Failed
111122223333 us-west-2 OW-10
OWASP LLM10: AWS Budgets with Bedrock Filters
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-06: No AWS Budgets found scoped to Bedrock or SageMaker. Unbounded GenAI spend can go undetected until the monthly bill.

Resolution

Configure AWS Budgets with FilterExpression / CostFilters targeting Bedrock or SageMaker spend, with an alerting SNS action.

Reference

Medium Failed
111122223333 us-east-1 OW-06
OWASP LLM06: Agent Execution Role Least Privilege
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check FS-07: No Bedrock agents found.

Resolution

Remove wildcard sensitive actions from Bedrock Agent execution roles.

Reference

Informational N/A
111122223333 us-east-2 OW-06
OWASP LLM06: Agent Execution Role Least Privilege
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check FS-07: No Bedrock agents found.

Resolution

Remove wildcard sensitive actions from Bedrock Agent execution roles.

Reference

Informational N/A
111122223333 us-west-2 OW-06
OWASP LLM06: Agent Execution Role Least Privilege
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check FS-07: No Bedrock agents found.

Resolution

Remove wildcard sensitive actions from Bedrock Agent execution roles.

Reference

Informational N/A
111122223333 us-east-1 OW-06
OWASP LLM06: AgentCore Gateway Policy Engine
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check FS-08: Runtimes without authorizer configuration: origami_expeditions, neoCyan_Agent, customer_support_agent, cdk_agent_core, awsapimcpserver. Without a policy engine, agents can invoke any registered tool without authorization checks.

Resolution

Set AgentCore Gateway policyEngineConfiguration.mode to ENFORCE and require identity propagation on Runtimes.

Reference

High Failed
111122223333 us-east-2 OW-06
OWASP LLM06: AgentCore Gateway Policy Engine
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check FS-08: Runtimes without authorizer configuration: origami_expeditions, neoCyan_Agent, customer_support_agent, cdk_agent_core, awsapimcpserver. Without a policy engine, agents can invoke any registered tool without authorization checks.

Resolution

Set AgentCore Gateway policyEngineConfiguration.mode to ENFORCE and require identity propagation on Runtimes.

Reference

High Failed
111122223333 us-west-2 OW-06
OWASP LLM06: AgentCore Gateway Policy Engine
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check FS-08: Runtimes without authorizer configuration: origami_expeditions, neoCyan_Agent, customer_support_agent, cdk_agent_core, awsapimcpserver. Without a policy engine, agents can invoke any registered tool without authorization checks.

Resolution

Set AgentCore Gateway policyEngineConfiguration.mode to ENFORCE and require identity propagation on Runtimes.

Reference

High Failed
111122223333 us-east-1 OW-06
OWASP LLM06: Agent Tool Concurrency Limits
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check FS-09: Agent-related Lambda functions without reserved concurrency: aiml-security-aiml-security-111122223333-FinServAssessment, resco-aiml-IAMPermissionCaching, aiml-security-aiml-security-111122223333-OWASPAssessment, aiml-security-aiml-security-111122223333-SagemakerAssessment, resco-aiml-CleanupBucket, aiml-security-aiml-security-111122223333-BedrockAssessment, resco-aiml-BedrockAssessment, aiml-security-aiml-security-111122223333-CleanupBucket, aiml-security-aiml-security-111122223333-AgentCoreAssessment, e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk. Unlimited concurrency allows runaway agent loops to exhaust account limits.

Resolution

Set reserved concurrency on agent action-group Lambdas so a runaway agent cannot exhaust downstream capacity.

Reference

Medium Failed
111122223333 us-east-2 OW-06
OWASP LLM06: Agent Tool Concurrency Limits
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check FS-09: Agent-related Lambda functions without reserved concurrency: aiml-security-aiml-security-111122223333-FinServAssessment, resco-aiml-IAMPermissionCaching, aiml-security-aiml-security-111122223333-OWASPAssessment, aiml-security-aiml-security-111122223333-SagemakerAssessment, resco-aiml-CleanupBucket, aiml-security-aiml-security-111122223333-BedrockAssessment, resco-aiml-BedrockAssessment, aiml-security-aiml-security-111122223333-CleanupBucket, aiml-security-aiml-security-111122223333-AgentCoreAssessment, e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk. Unlimited concurrency allows runaway agent loops to exhaust account limits.

Resolution

Set reserved concurrency on agent action-group Lambdas so a runaway agent cannot exhaust downstream capacity.

Reference

Medium Failed
111122223333 us-west-2 OW-06
OWASP LLM06: Agent Tool Concurrency Limits
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check FS-09: Agent-related Lambda functions without reserved concurrency: aiml-security-aiml-security-111122223333-FinServAssessment, resco-aiml-IAMPermissionCaching, aiml-security-aiml-security-111122223333-OWASPAssessment, aiml-security-aiml-security-111122223333-SagemakerAssessment, resco-aiml-CleanupBucket, aiml-security-aiml-security-111122223333-BedrockAssessment, resco-aiml-BedrockAssessment, aiml-security-aiml-security-111122223333-CleanupBucket, aiml-security-aiml-security-111122223333-AgentCoreAssessment, e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk. Unlimited concurrency allows runaway agent loops to exhaust account limits.

Resolution

Set reserved concurrency on agent action-group Lambdas so a runaway agent cannot exhaust downstream capacity.

Reference

Medium Failed
111122223333 us-east-1 OW-06
OWASP LLM06: Human-in-the-Loop Callback States
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check FS-10: No Step Functions state machines with agent/approval naming found. Verify that high-risk agent actions (e.g., fund transfers, account changes) have human approval gates.

Resolution

Insert Step Functions .waitForTaskToken callback states before any high-risk agent-triggered action.

Reference

Informational N/A
111122223333 us-east-2 OW-06
OWASP LLM06: Human-in-the-Loop Callback States
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check FS-10: No Step Functions state machines with agent/approval naming found. Verify that high-risk agent actions (e.g., fund transfers, account changes) have human approval gates.

Resolution

Insert Step Functions .waitForTaskToken callback states before any high-risk agent-triggered action.

Reference

Informational N/A
111122223333 us-west-2 OW-06
OWASP LLM06: Human-in-the-Loop Callback States
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check FS-10: No Step Functions state machines with agent/approval naming found. Verify that high-risk agent actions (e.g., fund transfers, account changes) have human approval gates.

Resolution

Insert Step Functions .waitForTaskToken callback states before any high-risk agent-triggered action.

Reference

Informational N/A
111122223333 us-east-1 OW-03
OWASP LLM03: SCP-Enforced Model Allowlist
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check FS-12: No Service Control Policies reference Bedrock. Without SCPs, any account in the organization can access any Bedrock model, including unapproved third-party models.

Resolution

Attach an Organizations SCP that denies bedrock:InvokeModel* except for allowlisted bedrock:ModelId values.

Reference

High Failed
111122223333 us-east-2 OW-03
OWASP LLM03: SCP-Enforced Model Allowlist
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check FS-12: No Service Control Policies reference Bedrock. Without SCPs, any account in the organization can access any Bedrock model, including unapproved third-party models.

Resolution

Attach an Organizations SCP that denies bedrock:InvokeModel* except for allowlisted bedrock:ModelId values.

Reference

High Failed
111122223333 us-west-2 OW-03
OWASP LLM03: SCP-Enforced Model Allowlist
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check FS-12: No Service Control Policies reference Bedrock. Without SCPs, any account in the organization can access any Bedrock model, including unapproved third-party models.

Resolution

Attach an Organizations SCP that denies bedrock:InvokeModel* except for allowlisted bedrock:ModelId values.

Reference

High Failed
111122223333 us-east-1 OW-03
OWASP LLM03: Custom-Model Provenance Tags
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check FS-13: All reviewed models have required provenance tags.

Resolution

Tag every Bedrock custom model with model-source, model-version, approval-date, and risk-tier so provenance is auditable.

Reference

Medium Passed
111122223333 us-east-2 OW-03
OWASP LLM03: Custom-Model Provenance Tags
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check FS-13: All reviewed models have required provenance tags.

Resolution

Tag every Bedrock custom model with model-source, model-version, approval-date, and risk-tier so provenance is auditable.

Reference

Medium Passed
111122223333 us-west-2 OW-03
OWASP LLM03: Custom-Model Provenance Tags
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check FS-13: All reviewed models have required provenance tags.

Resolution

Tag every Bedrock custom model with model-source, model-version, approval-date, and risk-tier so provenance is auditable.

Reference

Medium Passed
111122223333 us-east-1 OW-03
OWASP LLM03: Config Rules for Model Onboarding
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check FS-14: Found 11 model-related Config rule(s).

Resolution

Deploy AWS Config rules that enforce required tags and configuration on AWS::Bedrock::* resources at creation time.

Reference

Medium Passed
111122223333 us-east-2 OW-03
OWASP LLM03: Config Rules for Model Onboarding
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check FS-14: Found 11 model-related Config rule(s).

Resolution

Deploy AWS Config rules that enforce required tags and configuration on AWS::Bedrock::* resources at creation time.

Reference

Medium Passed
111122223333 us-west-2 OW-03
OWASP LLM03: Config Rules for Model Onboarding
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check FS-14: Found 11 model-related Config rule(s).

Resolution

Deploy AWS Config rules that enforce required tags and configuration on AWS::Bedrock::* resources at creation time.

Reference

Medium Passed
111122223333 us-east-1 OW-03
OWASP LLM03: Adversarial Evaluation Coverage
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check FS-15: No Bedrock Model Evaluation jobs found. Models have not been evaluated for adversarial robustness. FinServ model-risk management (SR 11-7) expects documented model validation/evaluation.

Resolution

Run Bedrock evaluation jobs that include adversarial and safety datasets before promoting a model to production.

Reference

Medium Failed
111122223333 us-east-2 OW-03
OWASP LLM03: Adversarial Evaluation Coverage
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check FS-15: No Bedrock Model Evaluation jobs found. Models have not been evaluated for adversarial robustness. FinServ model-risk management (SR 11-7) expects documented model validation/evaluation.

Resolution

Run Bedrock evaluation jobs that include adversarial and safety datasets before promoting a model to production.

Reference

Medium Failed
111122223333 us-west-2 OW-03
OWASP LLM03: Adversarial Evaluation Coverage
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check FS-15: No Bedrock Model Evaluation jobs found. Models have not been evaluated for adversarial robustness. FinServ model-risk management (SR 11-7) expects documented model validation/evaluation.

Resolution

Run Bedrock evaluation jobs that include adversarial and safety datasets before promoting a model to production.

Reference

Medium Failed
111122223333 us-east-1 OW-03
OWASP LLM03: ECR Image Scanning
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check FS-16: 4 ECR repo(s) without scan-on-push: mlexplorationrepo, cdk-hnb659fds-container-assets-111122223333-us-east-1, bedrock-agentcore-customer_support_agent, bedrock-agentcore-origami_expeditions.

Resolution

Enable Amazon Inspector enhanced scanning or scan-on-push on ECR repositories that hold model / agent container images.

Reference

High Failed
111122223333 us-east-2 OW-03
OWASP LLM03: ECR Image Scanning
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check FS-16: 4 ECR repo(s) without scan-on-push: mlexplorationrepo, cdk-hnb659fds-container-assets-111122223333-us-east-1, bedrock-agentcore-customer_support_agent, bedrock-agentcore-origami_expeditions.

Resolution

Enable Amazon Inspector enhanced scanning or scan-on-push on ECR repositories that hold model / agent container images.

Reference

High Failed
111122223333 us-west-2 OW-03
OWASP LLM03: ECR Image Scanning
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check FS-16: 4 ECR repo(s) without scan-on-push: mlexplorationrepo, cdk-hnb659fds-container-assets-111122223333-us-east-1, bedrock-agentcore-customer_support_agent, bedrock-agentcore-origami_expeditions.

Resolution

Enable Amazon Inspector enhanced scanning or scan-on-push on ECR repositories that hold model / agent container images.

Reference

High Failed
111122223333 us-east-1 OW-04
OWASP LLM04: Feature Store Offline Recovery
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check FS-20: No SageMaker Feature Store groups found.

Resolution

Enable OfflineStoreConfig on SageMaker Feature Groups so features have a durable, point-in-time record for rollback after a poisoning event.

Reference

Informational N/A
111122223333 us-east-2 OW-04
OWASP LLM04: Feature Store Offline Recovery
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check FS-20: No SageMaker Feature Store groups found.

Resolution

Enable OfflineStoreConfig on SageMaker Feature Groups so features have a durable, point-in-time record for rollback after a poisoning event.

Reference

Informational N/A
111122223333 us-west-2 OW-04
OWASP LLM04: Feature Store Offline Recovery
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check FS-20: No SageMaker Feature Store groups found.

Resolution

Enable OfflineStoreConfig on SageMaker Feature Groups so features have a durable, point-in-time record for rollback after a poisoning event.

Reference

Informational N/A
111122223333 us-east-1 OW-04
OWASP LLM04: Training-Data Versioning
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check FS-21: 13 training data bucket(s) without versioning: ancbedrocklogging, bedrock-agentcore-codebuild-sources-111122223333-us-east-1, bedrock-bda-us-east-1-dda43109-6557-48bb-993d-3f97126b64b4, bedrock-bda-us-east-1-logging-00719114-debd-4487-85d1-09cbc3fc8, bedrock-kb-bucket-f736570b, bedrock-video-generation-us-east-1-h5ltpm, fsi-genai-workshop-bedrock-datasources-111122223333-us-west-2, knowledgebase-bedrock-agent-agasthik, llmevaluationpromptfoo-bedrockkb-cozhbzbrcmd2, sagemaker-studio-111122223333-huo1mvme4t.

Resolution

Enable S3 versioning on training-data buckets so poisoned data can be reverted.

Reference

High Failed
111122223333 us-east-2 OW-04
OWASP LLM04: Training-Data Versioning
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check FS-21: 13 training data bucket(s) without versioning: ancbedrocklogging, bedrock-agentcore-codebuild-sources-111122223333-us-east-1, bedrock-bda-us-east-1-dda43109-6557-48bb-993d-3f97126b64b4, bedrock-bda-us-east-1-logging-00719114-debd-4487-85d1-09cbc3fc8, bedrock-kb-bucket-f736570b, bedrock-video-generation-us-east-1-h5ltpm, fsi-genai-workshop-bedrock-datasources-111122223333-us-west-2, knowledgebase-bedrock-agent-agasthik, llmevaluationpromptfoo-bedrockkb-cozhbzbrcmd2, sagemaker-studio-111122223333-huo1mvme4t.

Resolution

Enable S3 versioning on training-data buckets so poisoned data can be reverted.

Reference

High Failed
111122223333 us-west-2 OW-04
OWASP LLM04: Training-Data Versioning
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check FS-21: 13 training data bucket(s) without versioning: ancbedrocklogging, bedrock-agentcore-codebuild-sources-111122223333-us-east-1, bedrock-bda-us-east-1-dda43109-6557-48bb-993d-3f97126b64b4, bedrock-bda-us-east-1-logging-00719114-debd-4487-85d1-09cbc3fc8, bedrock-kb-bucket-f736570b, bedrock-video-generation-us-east-1-h5ltpm, fsi-genai-workshop-bedrock-datasources-111122223333-us-west-2, knowledgebase-bedrock-agent-agasthik, llmevaluationpromptfoo-bedrockkb-cozhbzbrcmd2, sagemaker-studio-111122223333-huo1mvme4t.

Resolution

Enable S3 versioning on training-data buckets so poisoned data can be reverted.

Reference

High Failed
111122223333 us-east-1 OW-08
OWASP LLM08: KB IAM Scope
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-22: 829 role(s) with wildcard KB permissions: - Role '111122223333-us-east-1-kb-setup-function-role' allows 'bedrock:CreateKnowledgeBase' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role '111122223333-us-east-1-kb-setup-function-role' allows 'bedrock:CreateDataSource' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'Admin' allows '*' - Role 'agentcore-wildrydes_gateway_role_ab3991f6-role' allows 'bedrock:*' - Role 'AgentCoreEvalsSDK-us-east-1-d04ba7b68b' allows 'bedrock:InvokeModel' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'AgentCoreEvalsSDK-us-east-1-d04ba7b68b' allows 'bedrock:InvokeModelWithResponseStream' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'Agentic-AI-MCP-Strands-SDK-Works-VSCodeInstanceRole-NCTUnlnRBFO6' allows '*' - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:ListGuardrails' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:GetGuardrail' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:ListModelInvocationJobs' on Resource '*' (no ARN scoping to specific Knowledge Bases)

Resolution

Scope Knowledge Base IAM roles to specific KB ARNs; remove wildcard bedrock:* on KB actions.

Reference

High Failed
111122223333 us-east-2 OW-08
OWASP LLM08: KB IAM Scope
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-22: 829 role(s) with wildcard KB permissions: - Role '111122223333-us-east-1-kb-setup-function-role' allows 'bedrock:CreateKnowledgeBase' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role '111122223333-us-east-1-kb-setup-function-role' allows 'bedrock:CreateDataSource' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'Admin' allows '*' - Role 'agentcore-wildrydes_gateway_role_ab3991f6-role' allows 'bedrock:*' - Role 'AgentCoreEvalsSDK-us-east-1-d04ba7b68b' allows 'bedrock:InvokeModel' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'AgentCoreEvalsSDK-us-east-1-d04ba7b68b' allows 'bedrock:InvokeModelWithResponseStream' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'Agentic-AI-MCP-Strands-SDK-Works-VSCodeInstanceRole-NCTUnlnRBFO6' allows '*' - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:ListGuardrails' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:GetGuardrail' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:ListModelInvocationJobs' on Resource '*' (no ARN scoping to specific Knowledge Bases)

Resolution

Scope Knowledge Base IAM roles to specific KB ARNs; remove wildcard bedrock:* on KB actions.

Reference

High Failed
111122223333 us-west-2 OW-08
OWASP LLM08: KB IAM Scope
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-22: 829 role(s) with wildcard KB permissions: - Role '111122223333-us-east-1-kb-setup-function-role' allows 'bedrock:CreateKnowledgeBase' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role '111122223333-us-east-1-kb-setup-function-role' allows 'bedrock:CreateDataSource' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'Admin' allows '*' - Role 'agentcore-wildrydes_gateway_role_ab3991f6-role' allows 'bedrock:*' - Role 'AgentCoreEvalsSDK-us-east-1-d04ba7b68b' allows 'bedrock:InvokeModel' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'AgentCoreEvalsSDK-us-east-1-d04ba7b68b' allows 'bedrock:InvokeModelWithResponseStream' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'Agentic-AI-MCP-Strands-SDK-Works-VSCodeInstanceRole-NCTUnlnRBFO6' allows '*' - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:ListGuardrails' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:GetGuardrail' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-19304724716-BedrockSecurityAssessment-vv6H0eGD9ESX' allows 'bedrock:ListModelInvocationJobs' on Resource '*' (no ARN scoping to specific Knowledge Bases)

Resolution

Scope Knowledge Base IAM roles to specific KB ARNs; remove wildcard bedrock:* on KB actions.

Reference

High Failed
111122223333 us-east-1 OW-08
OWASP LLM08: KB Metadata Filtering
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-24: Found 3 Knowledge Base(s). Tenant-isolation metadata filtering is a design pattern that cannot be verified via API — manual review required. Verify that metadata attributes (e.g., tenantId, classification) are indexed and that Retrieve calls include RetrievalFilter conditions for tenant isolation.

Resolution

Define Knowledge Base metadata fields so tenant / document-level filtering can be applied at retrieval time.

Reference

Informational N/A
111122223333 us-east-2 OW-08
OWASP LLM08: KB Metadata Filtering
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-24: Found 3 Knowledge Base(s). Tenant-isolation metadata filtering is a design pattern that cannot be verified via API — manual review required. Verify that metadata attributes (e.g., tenantId, classification) are indexed and that Retrieve calls include RetrievalFilter conditions for tenant isolation.

Resolution

Define Knowledge Base metadata fields so tenant / document-level filtering can be applied at retrieval time.

Reference

Informational N/A
111122223333 us-west-2 OW-08
OWASP LLM08: KB Metadata Filtering
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-24: Found 3 Knowledge Base(s). Tenant-isolation metadata filtering is a design pattern that cannot be verified via API — manual review required. Verify that metadata attributes (e.g., tenantId, classification) are indexed and that Retrieve calls include RetrievalFilter conditions for tenant isolation.

Resolution

Define Knowledge Base metadata fields so tenant / document-level filtering can be applied at retrieval time.

Reference

Informational N/A
111122223333 us-east-1 OW-08
OWASP LLM08: OpenSearch Serverless Encryption
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-25: Found 5 encryption policy(ies); 5 use a customer-managed KMS key.

Resolution

Use a customer-managed KMS key on the OpenSearch Serverless encryption policy for the vector collection.

Reference

High Passed
111122223333 us-east-2 OW-08
OWASP LLM08: OpenSearch Serverless Encryption
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-25: Found 5 encryption policy(ies); 5 use a customer-managed KMS key.

Resolution

Use a customer-managed KMS key on the OpenSearch Serverless encryption policy for the vector collection.

Reference

High Passed
111122223333 us-west-2 OW-08
OWASP LLM08: OpenSearch Serverless Encryption
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-25: Found 5 encryption policy(ies); 5 use a customer-managed KMS key.

Resolution

Use a customer-managed KMS key on the OpenSearch Serverless encryption policy for the vector collection.

Reference

High Passed
111122223333 us-east-1 OW-08
OWASP LLM08: OpenSearch Serverless Network Policy
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-26: Found 5 network policy(ies) but none restrict to VPC. Vector stores may be accessible from the public internet.

Resolution

Set AllowFromPublic=false on the OpenSearch Serverless network policy and restrict access to bedrock.amazonaws.com or a specific VPC endpoint.

Reference

High Failed
111122223333 us-east-2 OW-08
OWASP LLM08: OpenSearch Serverless Network Policy
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-26: Found 5 network policy(ies) but none restrict to VPC. Vector stores may be accessible from the public internet.

Resolution

Set AllowFromPublic=false on the OpenSearch Serverless network policy and restrict access to bedrock.amazonaws.com or a specific VPC endpoint.

Reference

High Failed
111122223333 us-west-2 OW-08
OWASP LLM08: OpenSearch Serverless Network Policy
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-26: Found 5 network policy(ies) but none restrict to VPC. Vector stores may be accessible from the public internet.

Resolution

Set AllowFromPublic=false on the OpenSearch Serverless network policy and restrict access to bedrock.amazonaws.com or a specific VPC endpoint.

Reference

High Failed
111122223333 us-east-1 OW-09
OWASP LLM09: Knowledge-Base Ingestion Freshness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check FS-31: 2 data source(s) not synced in >7 days (a configurable review threshold, NOT an AWS-mandated limit): - KB 'knowledge-base-semiconductors' source 'knowledge-base-quick-start-qpvuv-data-source' last synced 731 days ago - KB '111122223333-us-east-1-kb' source '111122223333-us-east-1-kb-datasource' last synced 209 days ago Confirm this age is acceptable for each data source's currency requirement — slow-changing reference data may legitimately sync infrequently.

Resolution

Sync Knowledge Base data sources on a schedule (weekly at most); stale KB content increases hallucination risk.

Reference

Medium Failed
111122223333 us-east-2 OW-09
OWASP LLM09: Knowledge-Base Ingestion Freshness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check FS-31: 2 data source(s) not synced in >7 days (a configurable review threshold, NOT an AWS-mandated limit): - KB 'knowledge-base-semiconductors' source 'knowledge-base-quick-start-qpvuv-data-source' last synced 731 days ago - KB '111122223333-us-east-1-kb' source '111122223333-us-east-1-kb-datasource' last synced 209 days ago Confirm this age is acceptable for each data source's currency requirement — slow-changing reference data may legitimately sync infrequently.

Resolution

Sync Knowledge Base data sources on a schedule (weekly at most); stale KB content increases hallucination risk.

Reference

Medium Failed
111122223333 us-west-2 OW-09
OWASP LLM09: Knowledge-Base Ingestion Freshness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check FS-31: 2 data source(s) not synced in >7 days (a configurable review threshold, NOT an AWS-mandated limit): - KB 'knowledge-base-semiconductors' source 'knowledge-base-quick-start-qpvuv-data-source' last synced 731 days ago - KB '111122223333-us-east-1-kb' source '111122223333-us-east-1-kb-datasource' last synced 209 days ago Confirm this age is acceptable for each data source's currency requirement — slow-changing reference data may legitimately sync infrequently.

Resolution

Sync Knowledge Base data sources on a schedule (weekly at most); stale KB content increases hallucination risk.

Reference

Medium Failed
111122223333 us-east-1 OW-09
OWASP LLM09: Source Attribution
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check FS-32: Source attribution in GenAI responses cannot be verified via AWS APIs. Manual review required to confirm responses include citations.

Resolution

Return citations in RetrieveAndGenerate responses so end users can verify grounding.

Reference

Informational N/A
111122223333 us-east-2 OW-09
OWASP LLM09: Source Attribution
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check FS-32: Source attribution in GenAI responses cannot be verified via AWS APIs. Manual review required to confirm responses include citations.

Resolution

Return citations in RetrieveAndGenerate responses so end users can verify grounding.

Reference

Informational N/A
111122223333 us-west-2 OW-09
OWASP LLM09: Source Attribution
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check FS-32: Source attribution in GenAI responses cannot be verified via AWS APIs. Manual review required to confirm responses include citations.

Resolution

Return citations in RetrieveAndGenerate responses so end users can verify grounding.

Reference

Informational N/A
111122223333 us-east-1 OW-09
OWASP LLM09: KB S3 Data-Source Integrity
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check FS-33: KB data source S3 buckets without versioning: 111122223333-us-east-1-kb-data-bucket.

Resolution

Enable S3 versioning + notifications on Knowledge Base data-source buckets so ingest failures are visible.

Reference

Medium Failed
111122223333 us-east-2 OW-09
OWASP LLM09: KB S3 Data-Source Integrity
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check FS-33: KB data source S3 buckets without versioning: 111122223333-us-east-1-kb-data-bucket.

Resolution

Enable S3 versioning + notifications on Knowledge Base data-source buckets so ingest failures are visible.

Reference

Medium Failed
111122223333 us-west-2 OW-09
OWASP LLM09: KB S3 Data-Source Integrity
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check FS-33: KB data source S3 buckets without versioning: 111122223333-us-east-1-kb-data-bucket.

Resolution

Enable S3 versioning + notifications on Knowledge Base data-source buckets so ingest failures are visible.

Reference

Medium Failed
111122223333 us-east-1 OW-04
OWASP LLM04: SageMaker Model Card Documentation
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check FS-42: No SageMaker Model Cards found. Production AI models lack documented intended use, limitations, and bias evaluations.

Resolution

Create SageMaker Model Cards for production models that document intended use, training data provenance, and bias/fairness evaluations so poisoned or drifted models are detectable against a documented baseline.

Reference

Medium Failed
111122223333 us-east-1 OW-09
OWASP LLM09: SageMaker Model Card Documentation
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check FS-42: No SageMaker Model Cards found. Production AI models lack documented intended use, limitations, and bias evaluations.

Resolution

Document each production model's intended use, known limitations, and evaluation results in a SageMaker Model Card so misinformation risks tied to model behaviour are traceable to a reviewed system card.

Reference

Medium Failed
111122223333 us-east-2 OW-04
OWASP LLM04: SageMaker Model Card Documentation
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check FS-42: No SageMaker Model Cards found. Production AI models lack documented intended use, limitations, and bias evaluations.

Resolution

Create SageMaker Model Cards for production models that document intended use, training data provenance, and bias/fairness evaluations so poisoned or drifted models are detectable against a documented baseline.

Reference

Medium Failed
111122223333 us-east-2 OW-09
OWASP LLM09: SageMaker Model Card Documentation
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check FS-42: No SageMaker Model Cards found. Production AI models lack documented intended use, limitations, and bias evaluations.

Resolution

Document each production model's intended use, known limitations, and evaluation results in a SageMaker Model Card so misinformation risks tied to model behaviour are traceable to a reviewed system card.

Reference

Medium Failed
111122223333 us-west-2 OW-04
OWASP LLM04: SageMaker Model Card Documentation
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check FS-42: No SageMaker Model Cards found. Production AI models lack documented intended use, limitations, and bias evaluations.

Resolution

Create SageMaker Model Cards for production models that document intended use, training data provenance, and bias/fairness evaluations so poisoned or drifted models are detectable against a documented baseline.

Reference

Medium Failed
111122223333 us-west-2 OW-09
OWASP LLM09: SageMaker Model Card Documentation
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check FS-42: No SageMaker Model Cards found. Production AI models lack documented intended use, limitations, and bias evaluations.

Resolution

Document each production model's intended use, known limitations, and evaluation results in a SageMaker Model Card so misinformation risks tied to model behaviour are traceable to a reviewed system card.

Reference

Medium Failed
111122223333 us-east-1 OW-02
OWASP LLM02: CloudWatch Log Data Protection Policies
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-43: No CloudWatch Logs data protection policies found. PII (SSN, account numbers, credit card numbers) in Bedrock invocation logs may be stored in plaintext.

Resolution

Apply a CloudWatch Logs data protection policy to log groups that receive Bedrock invocation logs.

Reference

High Failed
111122223333 us-east-2 OW-02
OWASP LLM02: CloudWatch Log Data Protection Policies
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-43: No CloudWatch Logs data protection policies found. PII (SSN, account numbers, credit card numbers) in Bedrock invocation logs may be stored in plaintext.

Resolution

Apply a CloudWatch Logs data protection policy to log groups that receive Bedrock invocation logs.

Reference

High Failed
111122223333 us-west-2 OW-02
OWASP LLM02: CloudWatch Log Data Protection Policies
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-43: No CloudWatch Logs data protection policies found. PII (SSN, account numbers, credit card numbers) in Bedrock invocation logs may be stored in plaintext.

Resolution

Apply a CloudWatch Logs data protection policy to log groups that receive Bedrock invocation logs.

Reference

High Failed
111122223333 us-east-1 OW-02
OWASP LLM02: Macie Sensitive-Data Discovery
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-44: Amazon Macie is enabled and scanning S3 buckets.

Resolution

Enable Amazon Macie with automated discovery on S3 buckets that hold training or knowledge-base data.

Reference

High Passed
111122223333 us-east-2 OW-02
OWASP LLM02: Macie Sensitive-Data Discovery
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-44: Amazon Macie is enabled and scanning S3 buckets.

Resolution

Enable Amazon Macie with automated discovery on S3 buckets that hold training or knowledge-base data.

Reference

High Passed
111122223333 us-west-2 OW-02
OWASP LLM02: Macie Sensitive-Data Discovery
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-44: Amazon Macie is enabled and scanning S3 buckets.

Resolution

Enable Amazon Macie with automated discovery on S3 buckets that hold training or knowledge-base data.

Reference

High Passed
111122223333 us-east-1 OW-02
OWASP LLM02: Guardrail PII Entities Coverage
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-45: Guardrails with PII filters: nist-ai-rmf-guardrail.

Resolution

Add the required PII entity types to the guardrail sensitiveInformationPolicy so PII in prompts/responses is filtered.

Reference

High Passed
111122223333 us-east-2 OW-02
OWASP LLM02: Guardrail PII Entities Coverage
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-45: Guardrails with PII filters: nist-ai-rmf-guardrail.

Resolution

Add the required PII entity types to the guardrail sensitiveInformationPolicy so PII in prompts/responses is filtered.

Reference

High Passed
111122223333 us-west-2 OW-02
OWASP LLM02: Guardrail PII Entities Coverage
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-45: Guardrails with PII filters: nist-ai-rmf-guardrail.

Resolution

Add the required PII entity types to the guardrail sensitiveInformationPolicy so PII in prompts/responses is filtered.

Reference

High Passed
111122223333 us-east-1 OW-02
OWASP LLM02: S3 Data-Classification Tagging
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-46: 18 AI/ML bucket(s) without data-classification tags: 111122223333-us-east-1-kb-data-bucket, ancbedrocklogging, ancknowledgebase, aws-streaming-data-solut-outputaccesslogsbucket8b-1o7m0kb4bafm4, bedrock-agentcore-codebuild-sources-111122223333-us-east-1, bedrock-bda-us-east-1-dda43109-6557-48bb-993d-3f97126b64b4, bedrock-bda-us-east-1-logging-00719114-debd-4487-85d1-09cbc3fc8, bedrock-kb-bucket-f736570b, bedrock-video-generation-us-east-1-h5ltpm, create-customer-resources-kb-bucket-111122223333.

Resolution

Tag training and knowledge-base S3 buckets with a data-classification tag so downstream automations enforce controls consistent with the sensitivity level.

Reference

Medium Failed
111122223333 us-east-2 OW-02
OWASP LLM02: S3 Data-Classification Tagging
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-46: 18 AI/ML bucket(s) without data-classification tags: 111122223333-us-east-1-kb-data-bucket, ancbedrocklogging, ancknowledgebase, aws-streaming-data-solut-outputaccesslogsbucket8b-1o7m0kb4bafm4, bedrock-agentcore-codebuild-sources-111122223333-us-east-1, bedrock-bda-us-east-1-dda43109-6557-48bb-993d-3f97126b64b4, bedrock-bda-us-east-1-logging-00719114-debd-4487-85d1-09cbc3fc8, bedrock-kb-bucket-f736570b, bedrock-video-generation-us-east-1-h5ltpm, create-customer-resources-kb-bucket-111122223333.

Resolution

Tag training and knowledge-base S3 buckets with a data-classification tag so downstream automations enforce controls consistent with the sensitivity level.

Reference

Medium Failed
111122223333 us-west-2 OW-02
OWASP LLM02: S3 Data-Classification Tagging
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-46: 18 AI/ML bucket(s) without data-classification tags: 111122223333-us-east-1-kb-data-bucket, ancbedrocklogging, ancknowledgebase, aws-streaming-data-solut-outputaccesslogsbucket8b-1o7m0kb4bafm4, bedrock-agentcore-codebuild-sources-111122223333-us-east-1, bedrock-bda-us-east-1-dda43109-6557-48bb-993d-3f97126b64b4, bedrock-bda-us-east-1-logging-00719114-debd-4487-85d1-09cbc3fc8, bedrock-kb-bucket-f736570b, bedrock-video-generation-us-east-1-h5ltpm, create-customer-resources-kb-bucket-111122223333.

Resolution

Tag training and knowledge-base S3 buckets with a data-classification tag so downstream automations enforce controls consistent with the sensitivity level.

Reference

Medium Failed
111122223333 us-east-1 OW-09
OWASP LLM09: Grounding Filter Threshold
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check FS-47: All 1 guardrail(s) with a GROUNDING filter have thresholds ≥0.7.

Resolution

Set the contextual grounding filter threshold to at least 0.70 on guardrails used for RAG workflows.

Reference

High Passed
111122223333 us-east-2 OW-09
OWASP LLM09: Grounding Filter Threshold
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check FS-47: All 1 guardrail(s) with a GROUNDING filter have thresholds ≥0.7.

Resolution

Set the contextual grounding filter threshold to at least 0.70 on guardrails used for RAG workflows.

Reference

High Passed
111122223333 us-west-2 OW-09
OWASP LLM09: Grounding Filter Threshold
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check FS-47: All 1 guardrail(s) with a GROUNDING filter have thresholds ≥0.7.

Resolution

Set the contextual grounding filter threshold to at least 0.70 on guardrails used for RAG workflows.

Reference

High Passed
111122223333 us-east-1 OW-09
OWASP LLM09: Active Knowledge Base Present
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check FS-48: Found 3 active Knowledge Base(s) for RAG grounding.

Resolution

Deploy at least one ACTIVE Knowledge Base when Bedrock models are used, so grounded retrieval is available.

Reference

Medium Passed
111122223333 us-east-2 OW-09
OWASP LLM09: Active Knowledge Base Present
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check FS-48: Found 3 active Knowledge Base(s) for RAG grounding.

Resolution

Deploy at least one ACTIVE Knowledge Base when Bedrock models are used, so grounded retrieval is available.

Reference

Medium Passed
111122223333 us-west-2 OW-09
OWASP LLM09: Active Knowledge Base Present
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check FS-48: Found 3 active Knowledge Base(s) for RAG grounding.

Resolution

Deploy at least one ACTIVE Knowledge Base when Bedrock models are used, so grounded retrieval is available.

Reference

Medium Passed
111122223333 us-east-1 OW-01
OWASP LLM01: PROMPT_ATTACK Filter at Standard Tier
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check FS-51: Found 1 guardrail(s) but none have PROMPT_ATTACK filters. Prompt injection attacks may bypass system prompts and access controls.

Resolution

Set guardrail PROMPT_ATTACK filter to Standard tier with inputStrength=HIGH.

Reference

High Failed
111122223333 us-east-2 OW-01
OWASP LLM01: PROMPT_ATTACK Filter at Standard Tier
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check FS-51: Found 1 guardrail(s) but none have PROMPT_ATTACK filters. Prompt injection attacks may bypass system prompts and access controls.

Resolution

Set guardrail PROMPT_ATTACK filter to Standard tier with inputStrength=HIGH.

Reference

High Failed
111122223333 us-west-2 OW-01
OWASP LLM01: PROMPT_ATTACK Filter at Standard Tier
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check FS-51: Found 1 guardrail(s) but none have PROMPT_ATTACK filters. Prompt injection attacks may bypass system prompts and access controls.

Resolution

Set guardrail PROMPT_ATTACK filter to Standard tier with inputStrength=HIGH.

Reference

High Failed
111122223333 us-east-1 OW-01
OWASP LLM01: Bedrock-Calling Lambda Runtimes
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check FS-52: Functions on deprecated runtimes: e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk, e2ebedrockrag-OSSInfraSta-OSSIndexCreationProvider-g56en9UzRjII. Deprecated runtimes may use outdated boto3/SDK versions lacking security patches.

Resolution

Ensure Lambda functions that invoke Bedrock use a supported (non-deprecated) runtime to receive security patches.

Reference

Medium Failed
111122223333 us-east-2 OW-01
OWASP LLM01: Bedrock-Calling Lambda Runtimes
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check FS-52: Functions on deprecated runtimes: e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk, e2ebedrockrag-OSSInfraSta-OSSIndexCreationProvider-g56en9UzRjII. Deprecated runtimes may use outdated boto3/SDK versions lacking security patches.

Resolution

Ensure Lambda functions that invoke Bedrock use a supported (non-deprecated) runtime to receive security patches.

Reference

Medium Failed
111122223333 us-west-2 OW-01
OWASP LLM01: Bedrock-Calling Lambda Runtimes
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check FS-52: Functions on deprecated runtimes: e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk, e2ebedrockrag-OSSInfraSta-OSSIndexCreationProvider-g56en9UzRjII. Deprecated runtimes may use outdated boto3/SDK versions lacking security patches.

Resolution

Ensure Lambda functions that invoke Bedrock use a supported (non-deprecated) runtime to receive security patches.

Reference

Medium Failed
111122223333 us-east-1 OW-01
OWASP LLM01: WAF SQLi & KnownBadInputs Coverage
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check FS-53: No regional WAF Web ACLs found.

Resolution

Add AWS Managed Rule Groups AWSManagedRulesSQLiRuleSet and AWSManagedRulesKnownBadInputsRuleSet to the WAF Web ACL guarding GenAI ingress.

Reference

Informational N/A
111122223333 us-east-2 OW-01
OWASP LLM01: WAF SQLi & KnownBadInputs Coverage
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check FS-53: No regional WAF Web ACLs found.

Resolution

Add AWS Managed Rule Groups AWSManagedRulesSQLiRuleSet and AWSManagedRulesKnownBadInputsRuleSet to the WAF Web ACL guarding GenAI ingress.

Reference

Informational N/A
111122223333 us-west-2 OW-01
OWASP LLM01: WAF SQLi & KnownBadInputs Coverage
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check FS-53: No regional WAF Web ACLs found.

Resolution

Add AWS Managed Rule Groups AWSManagedRulesSQLiRuleSet and AWSManagedRulesKnownBadInputsRuleSet to the WAF Web ACL guarding GenAI ingress.

Reference

Informational N/A
111122223333 us-east-1 OW-01
OWASP LLM01: Adversarial Testing Evidence
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check FS-54: Penetration testing evidence cannot be verified via AWS APIs. Manual review required to confirm GenAI applications have been tested.

Resolution

Track adversarial / red-team penetration test evidence for the GenAI application via resource tags or an equivalent audit trail.

Reference

Informational N/A
111122223333 us-east-2 OW-01
OWASP LLM01: Adversarial Testing Evidence
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check FS-54: Penetration testing evidence cannot be verified via AWS APIs. Manual review required to confirm GenAI applications have been tested.

Resolution

Track adversarial / red-team penetration test evidence for the GenAI application via resource tags or an equivalent audit trail.

Reference

Informational N/A
111122223333 us-west-2 OW-01
OWASP LLM01: Adversarial Testing Evidence
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check FS-54: Penetration testing evidence cannot be verified via AWS APIs. Manual review required to confirm GenAI applications have been tested.

Resolution

Track adversarial / red-team penetration test evidence for the GenAI application via resource tags or an equivalent audit trail.

Reference

Informational N/A
111122223333 us-east-1 OW-05
OWASP LLM05: Output-Validation Lambda
Details and remediation
Details

OWASP category: LLM05:2025 Improper Output Handling. Source check FS-55: No Lambda functions with output validation/sanitization naming found. GenAI outputs may be passed directly to downstream systems without validation.

Resolution

Deploy an output-validation / sanitisation Lambda between the model response and any downstream consumer to filter injection payloads in generated output.

Reference

Medium Failed
111122223333 us-east-2 OW-05
OWASP LLM05: Output-Validation Lambda
Details and remediation
Details

OWASP category: LLM05:2025 Improper Output Handling. Source check FS-55: No Lambda functions with output validation/sanitization naming found. GenAI outputs may be passed directly to downstream systems without validation.

Resolution

Deploy an output-validation / sanitisation Lambda between the model response and any downstream consumer to filter injection payloads in generated output.

Reference

Medium Failed
111122223333 us-west-2 OW-05
OWASP LLM05: Output-Validation Lambda
Details and remediation
Details

OWASP category: LLM05:2025 Improper Output Handling. Source check FS-55: No Lambda functions with output validation/sanitization naming found. GenAI outputs may be passed directly to downstream systems without validation.

Resolution

Deploy an output-validation / sanitisation Lambda between the model response and any downstream consumer to filter injection payloads in generated output.

Reference

Medium Failed
111122223333 us-east-1 OW-05
OWASP LLM05: WAF XSS Protection
Details and remediation
Details

OWASP category: LLM05:2025 Improper Output Handling. Source check FS-56: No regional WAF Web ACLs found.

Resolution

Ensure the WAF Web ACL guarding GenAI ingress includes AWSManagedRulesCommonRuleSet (XSS) or an equivalent XssMatchStatement.

Reference

Informational N/A
111122223333 us-east-2 OW-05
OWASP LLM05: WAF XSS Protection
Details and remediation
Details

OWASP category: LLM05:2025 Improper Output Handling. Source check FS-56: No regional WAF Web ACLs found.

Resolution

Ensure the WAF Web ACL guarding GenAI ingress includes AWSManagedRulesCommonRuleSet (XSS) or an equivalent XssMatchStatement.

Reference

Informational N/A
111122223333 us-west-2 OW-05
OWASP LLM05: WAF XSS Protection
Details and remediation
Details

OWASP category: LLM05:2025 Improper Output Handling. Source check FS-56: No regional WAF Web ACLs found.

Resolution

Ensure the WAF Web ACL guarding GenAI ingress includes AWSManagedRulesCommonRuleSet (XSS) or an equivalent XssMatchStatement.

Reference

Informational N/A
111122223333 us-east-1 OW-05
OWASP LLM05: Output Encoding Libraries
Details and remediation
Details

OWASP category: LLM05:2025 Improper Output Handling. Source check FS-57: Output encoding practices cannot be verified via AWS APIs. Manual code review required.

Resolution

Ensure Lambdas that render model output use a well-known output-encoding library appropriate to the downstream sink (HTML, SQL, shell, etc.).

Reference

Informational N/A
111122223333 us-east-2 OW-05
OWASP LLM05: Output Encoding Libraries
Details and remediation
Details

OWASP category: LLM05:2025 Improper Output Handling. Source check FS-57: Output encoding practices cannot be verified via AWS APIs. Manual code review required.

Resolution

Ensure Lambdas that render model output use a well-known output-encoding library appropriate to the downstream sink (HTML, SQL, shell, etc.).

Reference

Informational N/A
111122223333 us-west-2 OW-05
OWASP LLM05: Output Encoding Libraries
Details and remediation
Details

OWASP category: LLM05:2025 Improper Output Handling. Source check FS-57: Output encoding practices cannot be verified via AWS APIs. Manual code review required.

Resolution

Ensure Lambdas that render model output use a well-known output-encoding library appropriate to the downstream sink (HTML, SQL, shell, etc.).

Reference

Informational N/A
111122223333 us-east-1 OW-05
OWASP LLM05: Step Functions Output Schema Validation
Details and remediation
Details

OWASP category: LLM05:2025 Improper Output Handling. Source check FS-58: Found 0 Lambda function(s) whose names suggest schema/validation handling. Structured-output / JSON-schema validation of GenAI responses is an application-layer control that cannot be verified automatically — manual review required.

Resolution

Add explicit schema-validation states in Step Functions workflows that consume model output.

Reference

Informational N/A
111122223333 us-east-2 OW-05
OWASP LLM05: Step Functions Output Schema Validation
Details and remediation
Details

OWASP category: LLM05:2025 Improper Output Handling. Source check FS-58: Found 0 Lambda function(s) whose names suggest schema/validation handling. Structured-output / JSON-schema validation of GenAI responses is an application-layer control that cannot be verified automatically — manual review required.

Resolution

Add explicit schema-validation states in Step Functions workflows that consume model output.

Reference

Informational N/A
111122223333 us-west-2 OW-05
OWASP LLM05: Step Functions Output Schema Validation
Details and remediation
Details

OWASP category: LLM05:2025 Improper Output Handling. Source check FS-58: Found 0 Lambda function(s) whose names suggest schema/validation handling. Structured-output / JSON-schema validation of GenAI responses is an application-layer control that cannot be verified automatically — manual review required.

Resolution

Add explicit schema-validation states in Step Functions workflows that consume model output.

Reference

Informational N/A
111122223333 us-east-1 OW-06
OWASP LLM06: Agent Transaction Thresholds
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check FS-67: The following agent action-group Lambda functions have no environment variables whose names suggest transaction-value threshold configuration (this is a best-effort heuristic — a threshold enforced in code or in an AgentCore Policy Engine rule would not be detected here, so treat this as a prompt for manual verification rather than a definitive gap). Without explicit limits, agents could initiate unbounded financial transactions: - aiml-security-aiml-security-111122223333-FinServAssessment - aiml-security-aiml-security-111122223333-BedrockAssessment - resco-aiml-BedrockAssessment - aiml-security-aiml-security-111122223333-AgentCoreAssessment - e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk - e2ebedrockrag-OSSInfraSta-OSSIndexCreationProvider-g56en9UzRjII - resco-aiml-AgentCoreAssessment

Resolution

Encode agent transaction thresholds in Cedar policies or Lambda configuration so per-action limits are enforced.

Reference

High Failed
111122223333 us-east-2 OW-06
OWASP LLM06: Agent Transaction Thresholds
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check FS-67: The following agent action-group Lambda functions have no environment variables whose names suggest transaction-value threshold configuration (this is a best-effort heuristic — a threshold enforced in code or in an AgentCore Policy Engine rule would not be detected here, so treat this as a prompt for manual verification rather than a definitive gap). Without explicit limits, agents could initiate unbounded financial transactions: - aiml-security-aiml-security-111122223333-FinServAssessment - aiml-security-aiml-security-111122223333-BedrockAssessment - resco-aiml-BedrockAssessment - aiml-security-aiml-security-111122223333-AgentCoreAssessment - e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk - e2ebedrockrag-OSSInfraSta-OSSIndexCreationProvider-g56en9UzRjII - resco-aiml-AgentCoreAssessment

Resolution

Encode agent transaction thresholds in Cedar policies or Lambda configuration so per-action limits are enforced.

Reference

High Failed
111122223333 us-west-2 OW-06
OWASP LLM06: Agent Transaction Thresholds
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check FS-67: The following agent action-group Lambda functions have no environment variables whose names suggest transaction-value threshold configuration (this is a best-effort heuristic — a threshold enforced in code or in an AgentCore Policy Engine rule would not be detected here, so treat this as a prompt for manual verification rather than a definitive gap). Without explicit limits, agents could initiate unbounded financial transactions: - aiml-security-aiml-security-111122223333-FinServAssessment - aiml-security-aiml-security-111122223333-BedrockAssessment - resco-aiml-BedrockAssessment - aiml-security-aiml-security-111122223333-AgentCoreAssessment - e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk - e2ebedrockrag-OSSInfraSta-OSSIndexCreationProvider-g56en9UzRjII - resco-aiml-AgentCoreAssessment

Resolution

Encode agent transaction thresholds in Cedar policies or Lambda configuration so per-action limits are enforced.

Reference

High Failed
111122223333 us-east-1 OW-10
OWASP LLM10: API Gateway Request Body Size Limits
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-68: Found 3 REST API(s) and 0 regional WAF Web ACL(s), but none enforce a maximum request-body size. Note: an API Gateway request validator does NOT cap body size (it validates the schema and required params; the REST limit is a fixed 10 MB), and a WAF body SizeConstraint only inspects the first ~16 KB of the body by default. Oversized prompts can exhaust Bedrock token quotas and inflate costs.

Resolution

Configure API Gateway request validation or an equivalent ingress control so GenAI endpoints reject oversized request bodies before they can drive excessive model consumption.

Reference

Medium Failed
111122223333 us-east-2 OW-10
OWASP LLM10: API Gateway Request Body Size Limits
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-68: Found 3 REST API(s) and 0 regional WAF Web ACL(s), but none enforce a maximum request-body size. Note: an API Gateway request validator does NOT cap body size (it validates the schema and required params; the REST limit is a fixed 10 MB), and a WAF body SizeConstraint only inspects the first ~16 KB of the body by default. Oversized prompts can exhaust Bedrock token quotas and inflate costs.

Resolution

Configure API Gateway request validation or an equivalent ingress control so GenAI endpoints reject oversized request bodies before they can drive excessive model consumption.

Reference

Medium Failed
111122223333 us-west-2 OW-10
OWASP LLM10: API Gateway Request Body Size Limits
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-68: Found 3 REST API(s) and 0 regional WAF Web ACL(s), but none enforce a maximum request-body size. Note: an API Gateway request validator does NOT cap body size (it validates the schema and required params; the REST limit is a fixed 10 MB), and a WAF body SizeConstraint only inspects the first ~16 KB of the body by default. Oversized prompts can exhaust Bedrock token quotas and inflate costs.

Resolution

Configure API Gateway request validation or an equivalent ingress control so GenAI endpoints reject oversized request bodies before they can drive excessive model consumption.

Reference

Medium Failed
111122223333 us-east-1 OW-01
OWASP LLM01: Prompt-Input Validation Lambda
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check FS-69: Found 3 Lambda function(s) with input validation/sanitization naming patterns: resco-aiml-CleanupBucket, visa-bulletin-tracker-prod-cleanup, aiml-security-aiml-security-111122223333-CleanupBucket.

Resolution

Deploy a prompt-input validation Lambda in front of Bedrock invocations to sanitise untrusted input before it reaches the model.

Reference

Medium Passed
111122223333 us-east-2 OW-01
OWASP LLM01: Prompt-Input Validation Lambda
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check FS-69: Found 3 Lambda function(s) with input validation/sanitization naming patterns: resco-aiml-CleanupBucket, visa-bulletin-tracker-prod-cleanup, aiml-security-aiml-security-111122223333-CleanupBucket.

Resolution

Deploy a prompt-input validation Lambda in front of Bedrock invocations to sanitise untrusted input before it reaches the model.

Reference

Medium Passed
111122223333 us-west-2 OW-01
OWASP LLM01: Prompt-Input Validation Lambda
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check FS-69: Found 3 Lambda function(s) with input validation/sanitization naming patterns: resco-aiml-CleanupBucket, visa-bulletin-tracker-prod-cleanup, aiml-security-aiml-security-111122223333-CleanupBucket.

Resolution

Deploy a prompt-input validation Lambda in front of Bedrock invocations to sanitise untrusted input before it reaches the model.

Reference

Medium Passed
111122223333 us-east-1 OW-11
OWASP LLM07: System Prompt Embedded in Lambda Env Var
Details and remediation
Details

No Lambda function env vars in us-east-1 match the embedded-system-prompt heuristic (>= 200 chars containing prompt-shaped tokens).

Resolution

No action required.

Reference

Medium Passed
111122223333 us-east-1 OW-12
OWASP LLM07: System-Prompt-Disclosure Denied Topic
Details and remediation
Details

No Bedrock guardrail in us-east-1 has a DENY topic covering system-prompt disclosure. Attackers can craft prompts that ask the agent to reveal its system prompt or instructions.

Resolution

Add a DENY topic to at least one guardrail. Suggested topic name: 'SystemPromptDisclosure'. Suggested definition: 'Requests to reveal, describe, or summarise the system prompt, instructions, or internal role definition given to the assistant.'

Reference

Medium Failed
111122223333 eu-west-1 OW-01
OWASP LLM01: Model Invocation Logging
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging

Resolution

Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis.

Reference

Informational N/A
111122223333 eu-west-1 OW-07
OWASP LLM07: Model Invocation Logging
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging

Resolution

Enable Bedrock model invocation logging so prompt-extraction attempts against the system prompt are auditable after the fact.

Reference

Informational N/A
111122223333 eu-west-1 OW-07
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses.

Resolution

Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident.

Reference

Informational N/A
111122223333 eu-west-1 OW-07
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-16: No Bedrock guardrails configured in this region

Resolution

Set guardrail contentPolicy.tier.tierName to STANDARD; Standard tier additionally detects prompt-leakage attacks.

Reference

Informational N/A
111122223333 eu-west-1 OW-09
OWASP LLM09: Model Evaluation Jobs
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs

Resolution

Run Bedrock model evaluation jobs that include correctness and safety datasets.

Reference

Informational N/A
111122223333 eu-west-1 OW-08
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: No Bedrock knowledge bases found in this region

Resolution

Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption.

Reference

Informational N/A
111122223333 eu-west-1 OW-06
OWASP LLM06: Agent Action-Group Least Privilege
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-21: No Bedrock agents configured in this region

Resolution

Restrict agent action-group Lambda roles to only the specific actions and resources needed for each tool.

Reference

Informational N/A
111122223333 eu-west-1 OW-10
OWASP LLM10: Service Quota Throttling Limits
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas

Resolution

Customise Bedrock TPM / RPM service quotas above the account default to establish an explicit consumption ceiling.

Reference

Informational N/A
111122223333 eu-west-1 OW-01
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: No Bedrock guardrails configured in this region

Resolution

Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier.

Reference

Informational N/A
111122223333 eu-west-1 OW-04
OWASP LLM04: RAG Evaluation Coverage
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: No Bedrock knowledge bases found in this region

Resolution

Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context.

Reference

Informational N/A
111122223333 eu-west-1 OW-09
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-25: No Bedrock knowledge bases found in this region

Resolution

Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates.

Reference

Informational N/A
111122223333 eu-west-1 OW-02
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check BR-26: No Bedrock guardrails configured in this region

Resolution

Configure guardrail sensitiveInformationPolicy with PII entities and regex patterns; set outputAction=ANONYMIZE or BLOCK.

Reference

Informational N/A
111122223333 eu-west-1 OW-01
OWASP LLM01: Contextual Grounding Guardrail
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Enable Bedrock guardrail contextual grounding checks to reduce the surface for indirect prompt injection through retrieved context.

Reference

Informational N/A
111122223333 eu-west-1 OW-04
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Enable contextual grounding guardrail filters so retrieved context that diverges from ground truth is filtered before reaching the model.

Reference

Informational N/A
111122223333 eu-west-1 OW-09
OWASP LLM09: Contextual Grounding for Faithfulness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Set the contextual grounding filter threshold to at least 0.70 to reduce hallucinated responses.

Reference

Informational N/A
111122223333 eu-west-1 OW-06
OWASP LLM06: Bedrock Agent Guardrail Association
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-28: No Bedrock agents configured in this region

Resolution

Attach an approved Bedrock guardrail to every Bedrock agent so autonomous actions are filtered consistently.

Reference

Informational N/A
111122223333 eu-west-1 OW-06
OWASP LLM06: Agent Idle Session TTL
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-29: No Bedrock agents configured in this region

Resolution

Set idleSessionTTLInSeconds to a conservative value (e.g., <= 3600) so long-lived agent sessions cannot be reused.

Reference

Informational N/A
111122223333 eu-west-1 OW-03
OWASP LLM03: Imported-Model KMS Provenance
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check BR-30: Unable to check Imported model encryption check: An error occurred (AccessDeniedException) when calling the ListImportedModels operation: Your account is not authorized to invoke this API operation.

Resolution

Encrypt imported Bedrock models with a customer-managed KMS key to preserve provenance and access control across model artefacts.

Reference

Informational N/A
111122223333 eu-west-1 OW-10
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms

Resolution

Create CloudWatch alarms on Bedrock InvocationThrottles, InputTokenCount, OutputTokenCount, and EstimatedTPMQuotaUsage.

Reference

Informational N/A
111122223333 eu-west-1 OW-03
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check BR-33: No Lambda functions with Bedrock indicators were found in eu-west-1; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads.

Resolution

Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain.

Reference

Informational N/A
111122223333 eu-west-1 OW-03
OWASP LLM03: SageMaker Internet Exposure
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-01: No SageMaker notebook instances or domains found to check

Resolution

Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths.

Reference

Informational N/A
111122223333 eu-west-1 OW-02
OWASP LLM02: SageMaker Data Encryption
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: No SageMaker resources found to check for data protection

Resolution

Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data.

Reference

Informational N/A
111122223333 eu-west-1 OW-09
OWASP LLM09: SageMaker Clarify Evaluation
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-06: No SageMaker Clarify jobs found

Resolution

Use SageMaker Clarify to evaluate bias and explainability for models whose generated outputs can influence user decisions.

Reference

Informational N/A
111122223333 eu-west-1 OW-04
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-07: No Model Monitor schedules found

Resolution

Configure active SageMaker Model Monitor schedules so data-quality and model-quality regressions caused by poisoned inputs or drift are detected.

Reference

Informational N/A
111122223333 eu-west-1 OW-09
OWASP LLM09: SageMaker Model Monitor Coverage
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-07: No Model Monitor schedules found

Resolution

Configure SageMaker Model Monitor schedules for production models so quality regressions that can produce incorrect outputs are detected.

Reference

Informational N/A
111122223333 eu-west-1 OW-03
OWASP LLM03: SageMaker Notebook VPC Deployment
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-10: No notebook instances found

Resolution

Deploy SageMaker notebook instances inside a VPC so package, data, and model artifact access can be controlled through private network paths.

Reference

Informational N/A
111122223333 eu-west-1 OW-03
OWASP LLM03: SageMaker Model Network Isolation
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-11: No models found

Resolution

Enable network isolation on SageMaker models so inference containers cannot make unmanaged outbound calls that alter dependencies or exfiltrate model artifacts.

Reference

Informational N/A
111122223333 eu-west-1 OW-10
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check SM-11: No models found

Resolution

Enable SageMaker model network isolation to prevent deployed model containers from making uncontrolled outbound calls that can amplify consumption or abuse downstream services.

Reference

Informational N/A
111122223333 eu-west-1 OW-03
OWASP LLM03: SageMaker Container Repository Access
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-14: No models found or all use default Platform access

Resolution

Configure SageMaker models to pull container images from private ECR repositories through VPC repository access instead of platform or public registry paths.

Reference

Informational N/A
111122223333 eu-west-1 OW-02
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-15: No feature groups with offline stores found

Resolution

Encrypt SageMaker Feature Store offline stores with customer-managed KMS keys so sensitive feature data is protected at rest.

Reference

Informational N/A
111122223333 eu-west-1 OW-03
OWASP LLM03: SageMaker AutoML Network Isolation
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-21: No AutoML jobs found

Resolution

Enable network isolation on AutoML jobs so generated training containers cannot fetch unapproved dependencies or send data over unmanaged network paths.

Reference

Informational N/A
111122223333 eu-west-1 OW-04
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance.

Resolution

Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically.

Reference

Informational N/A
111122223333 eu-west-1 OW-09
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance.

Resolution

Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release.

Reference

Informational N/A
111122223333 eu-west-1 OW-04
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-23: No InService endpoints found to monitor.

Resolution

Enable SageMaker Model Monitor drift detection for production endpoints so poisoning, data drift, and model-quality degradation are identified.

Reference

Medium Passed
111122223333 eu-west-1 OW-09
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-23: No InService endpoints found to monitor.

Resolution

Configure data-quality and model-quality monitoring for SageMaker endpoints so degraded model behavior that can produce misinformation is detected.

Reference

Medium Passed
111122223333 eu-west-1 OW-03
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain.

Reference

Informational N/A
111122223333 eu-west-1 OW-04
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated.

Reference

Informational N/A
111122223333 eu-west-1 OW-06
OWASP LLM06: AgentCore Resource-Based Policies
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check AC-10: No AgentCore resources found to check for resource-based policies

Resolution

Attach resource-based policies to AgentCore runtimes and gateways so caller identities are constrained.

Reference

Informational N/A
111122223333 eu-west-1 OW-11
OWASP LLM07: System Prompt Embedded in Lambda Env Var
Details and remediation
Details

No Lambda functions found in eu-west-1; nothing to inspect.

Resolution

No action required.

Reference

Informational N/A
111122223333 eu-west-1 OW-12
OWASP LLM07: System-Prompt-Disclosure Denied Topic
Details and remediation
Details

No Bedrock guardrails configured in eu-west-1; nothing to inspect.

Resolution

No action required.

Reference

Informational N/A
111122223333 us-east-2 BR-02
Amazon Bedrock private connectivity check
Details and remediation
Details

No regional Bedrock resources found to assess private connectivity

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 BR-04
Bedrock Model Invocation Logging Check
Details and remediation
Details

No regional Bedrock resources found to monitor with invocation logging

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 BR-05
Bedrock Guardrails Check
Details and remediation
Details

No regional Bedrock resources found to protect with guardrails

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 BR-06
Bedrock CloudTrail Logging Check
Details and remediation
Details

No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 BR-07
Bedrock Prompt Management Check
Details and remediation
Details

Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses.

Resolution

Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates

Reference

Informational N/A
111122223333 us-east-2 BR-08
Bedrock Agent IAM Roles Check
Details and remediation
Details

No Bedrock agents found in the account

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 BR-09
Bedrock Knowledge Base Encryption Check
Details and remediation
Details

No Knowledge Bases found in the account

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 BR-10
Bedrock Guardrail IAM Enforcement Check
Details and remediation
Details

No guardrails configured - IAM enforcement check not applicable

Resolution

Configure Bedrock Guardrails first, then enforce their use via IAM policies

Reference

Informational N/A
111122223333 us-east-2 BR-11
Bedrock Custom Model Encryption Check
Details and remediation
Details

Custom model API not available in us-east-2

Resolution

Verify permissions to access Bedrock custom models

Reference

Low N/A
111122223333 us-east-2 BR-12
Bedrock Invocation Log Encryption Check
Details and remediation
Details

Model invocation logging to S3 is not configured

Resolution

If logging is enabled to CloudWatch only, ensure CloudWatch log group uses CMK encryption

Reference

Informational N/A
111122223333 us-east-2 BR-13
Bedrock Flows Guardrails Check
Details and remediation
Details

No Bedrock Flows found in the account

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 BR-16
Guardrail Tier Validation Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create Bedrock guardrails with Standard tier for enhanced content filtering and protection

Reference

Medium N/A
111122223333 us-east-2 BR-17
Custom Model Customer-Managed KMS Encryption Check
Details and remediation
Details

Could not assess this check in us-east-2. Assessment error: UnknownOperationException.

Resolution

No action required on the assessed workload. Resolve the assessment prerequisite or permission issue and rerun the assessment.

Reference

Informational N/A
111122223333 us-east-2 BR-18
Model Evaluation Implementation Check
Details and remediation
Details

No regional Bedrock resources found to assess with model evaluation jobs

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 BR-19
Prompt Flow Validation Check
Details and remediation
Details

No Bedrock prompt flows configured in this region

Resolution

When creating prompt flows, use the ValidateFlowDefinition API to validate flow definitions before deployment

Reference

Medium N/A
111122223333 us-east-2 BR-20
Knowledge Base Customer-Managed KMS Encryption Check
Details and remediation
Details

No Bedrock knowledge bases found in this region

Resolution

When creating knowledge bases, specify customer-managed KMS keys for both vector store and data source encryption

Reference

High N/A
111122223333 us-east-2 BR-21
Agent Action Group IAM Least Privilege Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents with action groups, ensure Lambda execution roles follow least privilege principles

Reference

High N/A
111122223333 us-east-2 BR-22
Model Invocation Throttling Limits Check
Details and remediation
Details

No regional Bedrock resources found to assess model invocation throttling quotas

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 BR-23
Guardrail Content Filter Coverage Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with all content filters enabled (hate, insults, sexual, violence) with appropriate thresholds

Reference

High N/A
111122223333 us-east-2 BR-24
Automated Reasoning Policy Implementation Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with Automated Reasoning policies for formal verification of model responses

Reference

Medium N/A
111122223333 us-east-2 BR-25
RAG Evaluation Jobs Check
Details and remediation
Details

No Bedrock knowledge bases found in this region

Resolution

When implementing RAG applications, configure evaluation jobs to assess context relevance, response correctness, and prevent hallucinations

Reference

Low N/A
111122223333 us-east-2 BR-26
Guardrail Sensitive Information Filter Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with sensitive-information filters (PII entities and/or regex patterns) to detect and redact sensitive data in prompts and model responses

Reference

High N/A
111122223333 us-east-2 BR-27
Guardrail Contextual Grounding Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with contextual grounding checks to detect hallucinations (ungrounded responses) and irrelevant answers, especially for RAG applications

Reference

Medium N/A
111122223333 us-east-2 BR-28
Agent Guardrail Association Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents, associate a Bedrock guardrail so agent inputs and responses are filtered for harmful content, PII, and denied topics

Reference

High N/A
111122223333 us-east-2 BR-29
Agent Idle Session TTL Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents, set a conservative idleSessionTTLInSeconds to limit how long an idle session remains resumable

Reference

Low N/A
111122223333 us-east-2 BR-30
Imported Model Customer-Managed KMS Encryption Check
Details and remediation
Details

No imported custom Bedrock models found in this region

Resolution

When importing models, specify a customer-managed KMS key for encryption to maintain control over encryption keys

Reference

High N/A
111122223333 us-east-2 BR-31
Batch Inference Output Encryption Check
Details and remediation
Details

No Bedrock batch inference (model invocation) jobs found in this region

Resolution

When creating batch inference jobs, set outputDataConfig.s3OutputDataConfig.s3EncryptionKeyId to a customer-managed KMS key to encrypt the job output

Reference

Medium N/A
111122223333 us-east-2 BR-32
Bedrock CloudWatch Alarm Check
Details and remediation
Details

No regional Bedrock resources found to monitor with CloudWatch alarms

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 BR-33
Amazon Inspector Lambda Code Scanning Check
Details and remediation
Details

No Lambda functions with Bedrock indicators were found in us-east-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads.

Resolution

No action required. If Bedrock-calling Lambda functions exist, ensure their function name, ARN, description, handler, role, or environment variables contain a Bedrock identifier that the assessment can detect, or evaluate Inspector coverage manually.

Reference

Informational N/A
111122223333 us-east-2 AG-07
Agentic AI Model Invocation Logging
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging

Resolution

Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements.

Reference

Informational N/A
111122223333 us-east-2 AG-08
Agentic AI API Audit Trail
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage

Resolution

Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured.

Reference

Informational N/A
111122223333 us-east-2 AG-10
Agentic AI Adversarial Evaluation Coverage
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs

Resolution

Configure model or application evaluations that include adversarial, safety, and security-relevant test cases.

Reference

Informational N/A
111122223333 us-east-2 AG-11
Agentic AI Prompt Flow Validation
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region

Resolution

Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions.

Reference

Informational N/A
111122223333 us-east-2 AG-06
Agentic AI Tool Execution Least Privilege
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region

Resolution

Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required.

Reference

Informational N/A
111122223333 us-east-2 AG-12
Agentic AI Invocation Abuse Controls
Details and remediation
Details

Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas

Resolution

Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns.

Reference

Informational N/A
111122223333 us-east-2 AG-02
Agentic AI Harmful Content Guardrail Coverage
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: No Bedrock guardrails configured in this region

Resolution

Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads.

Reference

Informational N/A
111122223333 us-east-2 AG-04
Agentic AI Automated Reasoning Guardrails
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: No Bedrock guardrails configured in this region

Resolution

Configure automated reasoning policies on guardrails where formal response validation is required.

Reference

Informational N/A
111122223333 us-east-2 AG-03
Agentic AI Sensitive Information Protection
Details and remediation
Details

Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: No Bedrock guardrails configured in this region

Resolution

Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns.

Reference

Informational N/A
111122223333 us-east-2 AG-05
Agentic AI Grounding Controls
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows.

Reference

Informational N/A
111122223333 us-east-2 AG-01
Agentic AI Agent Guardrail Association
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region

Resolution

Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating.

Reference

Informational N/A
111122223333 us-east-2 AG-13
Agentic AI Session Boundary
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region

Resolution

Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements.

Reference

Informational N/A
111122223333 us-east-2 AG-14
Agentic AI Operational Abuse Alarms
Details and remediation
Details

Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms

Resolution

Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available.

Reference

Informational N/A
111122223333 eu-west-1 SM-01
SageMaker Internet Access Check
Details and remediation
Details

No SageMaker notebook instances or domains found to check

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 SM-02
SageMaker SSO Configuration Check
Details and remediation
Details

No SageMaker domains found, or all domains use SSO with IAM Identity Center configured

Resolution

No action required

Reference

Medium Passed
111122223333 eu-west-1 SM-03
Data Protection Check
Details and remediation
Details

No SageMaker resources found to check for data protection

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 SM-04
GuardDuty Enabled
Details and remediation
Details

Amazon GuardDuty is properly enabled and monitoring for security threats in SageMaker workloads.

Resolution

No action required

Reference

Medium Passed
111122223333 eu-west-1 SM-05
SageMaker Model Registry Issue
Details and remediation
Details

No model package groups found

Resolution

Implement model versioning using SageMaker Model Registry to track model lineage, approve model versions, and manage model deployment

Reference

Informational N/A
111122223333 eu-west-1 SM-05
SageMaker Feature Store Issue
Details and remediation
Details

No feature groups found

Resolution

Utilize SageMaker Feature Store to create, share, and manage features for machine learning development and production

Reference

Informational N/A
111122223333 eu-west-1 SM-05
SageMaker Pipelines Issue
Details and remediation
Details

No ML pipelines found

Resolution

Implement SageMaker Pipelines to automate and manage ML workflows, including data preparation, training, and model deployment

Reference

Informational N/A
111122223333 eu-west-1 SM-06
SageMaker Clarify No Clarify Usage
Details and remediation
Details

No SageMaker Clarify jobs found

Resolution

Implement SageMaker Clarify for model explainability and bias detection

Reference

Informational N/A
111122223333 eu-west-1 SM-07
SageMaker Model Monitor No Model Monitoring
Details and remediation
Details

No Model Monitor schedules found

Resolution

Configure comprehensive model monitoring schedules

Reference

Informational N/A
111122223333 eu-west-1 SM-08
Model Registry Registry Not Used
Details and remediation
Details

Model Registry is not being utilized

Resolution

Implement proper model versioning and approval workflows

Reference

Informational N/A
111122223333 eu-west-1 SM-09
SageMaker Notebook Root Access Check
Details and remediation
Details

No notebook instances found

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 SM-10
SageMaker Notebook VPC Deployment Check
Details and remediation
Details

No notebook instances found

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 SM-11
SageMaker Model Network Isolation Check
Details and remediation
Details

No models found

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 SM-12
SageMaker Endpoint Instance Count Check
Details and remediation
Details

No InService endpoints found

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 SM-13
SageMaker Monitoring Network Isolation Check
Details and remediation
Details

No monitoring schedules found

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 SM-14
SageMaker Model Repository Access Check
Details and remediation
Details

No models found or all use default Platform access

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 SM-15
SageMaker Feature Store Encryption Check
Details and remediation
Details

No feature groups with offline stores found

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 SM-16
SageMaker Data Quality Job Encryption Check
Details and remediation
Details

No data quality job definitions found

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 SM-17
SageMaker Processing Job Encryption Check
Details and remediation
Details

No processing jobs found

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 SM-18
SageMaker Transform Job Encryption Check
Details and remediation
Details

No transform jobs found

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 SM-19
SageMaker Hyperparameter Tuning Job Encryption Check
Details and remediation
Details

No hyperparameter tuning jobs found

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 SM-20
SageMaker Compilation Job Encryption Check
Details and remediation
Details

No compilation jobs found

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 SM-21
SageMaker AutoML Job Network Isolation Check
Details and remediation
Details

No AutoML jobs found

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 SM-22
Model Approval Workflow Check
Details and remediation
Details

No model package groups found. Model Registry is not being used for model governance.

Resolution

Implement Model Registry to track model versions and enforce approval workflows before production deployment.

Reference

Informational N/A
111122223333 eu-west-1 SM-23
Model Drift Detection Check
Details and remediation
Details

No InService endpoints found to monitor.

Resolution

No action required

Reference

Medium Passed
111122223333 eu-west-1 SM-24
A/B Testing and Shadow Deployment Check
Details and remediation
Details

No InService endpoints found.

Resolution

No action required

Reference

Low Passed
111122223333 eu-west-1 SM-25
ML Lineage Tracking - Experiments Not Used
Details and remediation
Details

No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Implement SageMaker Experiments to track ML training runs, hyperparameters, metrics, and model artifacts. This enables reproducibility and auditability.

Reference

Informational N/A
111122223333 eu-west-1 BR-02
Amazon Bedrock private connectivity check
Details and remediation
Details

No regional Bedrock resources found to assess private connectivity

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 BR-04
Bedrock Model Invocation Logging Check
Details and remediation
Details

No regional Bedrock resources found to monitor with invocation logging

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 BR-05
Bedrock Guardrails Check
Details and remediation
Details

No regional Bedrock resources found to protect with guardrails

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 BR-06
Bedrock CloudTrail Logging Check
Details and remediation
Details

No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 BR-07
Bedrock Prompt Management Check
Details and remediation
Details

Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses.

Resolution

Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates

Reference

Informational N/A
111122223333 eu-west-1 BR-08
Bedrock Agent IAM Roles Check
Details and remediation
Details

No Bedrock agents found in the account

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 BR-09
Bedrock Knowledge Base Encryption Check
Details and remediation
Details

No Knowledge Bases found in the account

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 BR-10
Bedrock Guardrail IAM Enforcement Check
Details and remediation
Details

No guardrails configured - IAM enforcement check not applicable

Resolution

Configure Bedrock Guardrails first, then enforce their use via IAM policies

Reference

Informational N/A
111122223333 eu-west-1 BR-11
Bedrock Custom Model Encryption Check
Details and remediation
Details

No custom/fine-tuned models found in the account

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 BR-12
Bedrock Invocation Log Encryption Check
Details and remediation
Details

Model invocation logging to S3 is not configured

Resolution

If logging is enabled to CloudWatch only, ensure CloudWatch log group uses CMK encryption

Reference

Informational N/A
111122223333 eu-west-1 BR-13
Bedrock Flows Guardrails Check
Details and remediation
Details

No Bedrock Flows found in the account

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 BR-16
Guardrail Tier Validation Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create Bedrock guardrails with Standard tier for enhanced content filtering and protection

Reference

Medium N/A
111122223333 eu-west-1 BR-17
Custom Model Customer-Managed KMS Encryption Check
Details and remediation
Details

No custom (fine-tuned) Bedrock models found in this region

Resolution

When creating custom models, specify a customer-managed KMS key for encryption to maintain control over encryption keys

Reference

High N/A
111122223333 eu-west-1 BR-18
Model Evaluation Implementation Check
Details and remediation
Details

No regional Bedrock resources found to assess with model evaluation jobs

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 BR-19
Prompt Flow Validation Check
Details and remediation
Details

No Bedrock prompt flows configured in this region

Resolution

When creating prompt flows, use the ValidateFlowDefinition API to validate flow definitions before deployment

Reference

Medium N/A
111122223333 eu-west-1 BR-20
Knowledge Base Customer-Managed KMS Encryption Check
Details and remediation
Details

No Bedrock knowledge bases found in this region

Resolution

When creating knowledge bases, specify customer-managed KMS keys for both vector store and data source encryption

Reference

High N/A
111122223333 eu-west-1 BR-21
Agent Action Group IAM Least Privilege Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents with action groups, ensure Lambda execution roles follow least privilege principles

Reference

High N/A
111122223333 eu-west-1 BR-22
Model Invocation Throttling Limits Check
Details and remediation
Details

No regional Bedrock resources found to assess model invocation throttling quotas

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 BR-23
Guardrail Content Filter Coverage Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with all content filters enabled (hate, insults, sexual, violence) with appropriate thresholds

Reference

High N/A
111122223333 eu-west-1 BR-24
Automated Reasoning Policy Implementation Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with Automated Reasoning policies for formal verification of model responses

Reference

Medium N/A
111122223333 eu-west-1 BR-25
RAG Evaluation Jobs Check
Details and remediation
Details

No Bedrock knowledge bases found in this region

Resolution

When implementing RAG applications, configure evaluation jobs to assess context relevance, response correctness, and prevent hallucinations

Reference

Low N/A
111122223333 eu-west-1 BR-26
Guardrail Sensitive Information Filter Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with sensitive-information filters (PII entities and/or regex patterns) to detect and redact sensitive data in prompts and model responses

Reference

High N/A
111122223333 eu-west-1 BR-27
Guardrail Contextual Grounding Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with contextual grounding checks to detect hallucinations (ungrounded responses) and irrelevant answers, especially for RAG applications

Reference

Medium N/A
111122223333 eu-west-1 BR-28
Agent Guardrail Association Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents, associate a Bedrock guardrail so agent inputs and responses are filtered for harmful content, PII, and denied topics

Reference

High N/A
111122223333 eu-west-1 BR-29
Agent Idle Session TTL Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents, set a conservative idleSessionTTLInSeconds to limit how long an idle session remains resumable

Reference

Low N/A
111122223333 eu-west-1 BR-30
Imported Model Customer-Managed KMS Encryption Check
Details and remediation
Details

Unable to check Imported model encryption check: An error occurred (AccessDeniedException) when calling the ListImportedModels operation: Your account is not authorized to invoke this API operation.

Resolution

Amazon Bedrock Custom Model Import is not enabled or available for this account in this region. No IAM change is required; the check applies only once model import is in use.

Reference

Low N/A
111122223333 eu-west-1 BR-31
Batch Inference Output Encryption Check
Details and remediation
Details

No Bedrock batch inference (model invocation) jobs found in this region

Resolution

When creating batch inference jobs, set outputDataConfig.s3OutputDataConfig.s3EncryptionKeyId to a customer-managed KMS key to encrypt the job output

Reference

Medium N/A
111122223333 eu-west-1 BR-32
Bedrock CloudWatch Alarm Check
Details and remediation
Details

No regional Bedrock resources found to monitor with CloudWatch alarms

Resolution

No action required

Reference

Informational N/A
111122223333 eu-west-1 BR-33
Amazon Inspector Lambda Code Scanning Check
Details and remediation
Details

No Lambda functions with Bedrock indicators were found in eu-west-1; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads.

Resolution

No action required. If Bedrock-calling Lambda functions exist, ensure their function name, ARN, description, handler, role, or environment variables contain a Bedrock identifier that the assessment can detect, or evaluate Inspector coverage manually.

Reference

Informational N/A
111122223333 eu-west-1 AG-07
Agentic AI Model Invocation Logging
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging

Resolution

Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements.

Reference

Informational N/A
111122223333 eu-west-1 AG-08
Agentic AI API Audit Trail
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage

Resolution

Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured.

Reference

Informational N/A
111122223333 eu-west-1 AG-10
Agentic AI Adversarial Evaluation Coverage
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs

Resolution

Configure model or application evaluations that include adversarial, safety, and security-relevant test cases.

Reference

Informational N/A
111122223333 eu-west-1 AG-11
Agentic AI Prompt Flow Validation
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region

Resolution

Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions.

Reference

Informational N/A
111122223333 eu-west-1 AG-06
Agentic AI Tool Execution Least Privilege
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region

Resolution

Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required.

Reference

Informational N/A
111122223333 eu-west-1 AG-12
Agentic AI Invocation Abuse Controls
Details and remediation
Details

Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas

Resolution

Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns.

Reference

Informational N/A
111122223333 eu-west-1 AG-02
Agentic AI Harmful Content Guardrail Coverage
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: No Bedrock guardrails configured in this region

Resolution

Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads.

Reference

Informational N/A
111122223333 eu-west-1 AG-04
Agentic AI Automated Reasoning Guardrails
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: No Bedrock guardrails configured in this region

Resolution

Configure automated reasoning policies on guardrails where formal response validation is required.

Reference

Informational N/A
111122223333 eu-west-1 AG-03
Agentic AI Sensitive Information Protection
Details and remediation
Details

Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: No Bedrock guardrails configured in this region

Resolution

Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns.

Reference

Informational N/A
111122223333 eu-west-1 AG-05
Agentic AI Grounding Controls
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows.

Reference

Informational N/A
111122223333 eu-west-1 AG-01
Agentic AI Agent Guardrail Association
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region

Resolution

Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating.

Reference

Informational N/A
111122223333 eu-west-1 AG-13
Agentic AI Session Boundary
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region

Resolution

Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements.

Reference

Informational N/A
111122223333 eu-west-1 AG-14
Agentic AI Operational Abuse Alarms
Details and remediation
Details

Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms

Resolution

Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available.

Reference

Informational N/A
111122223333 Global SM-02
SageMaker Full Access Policy Used
Details and remediation
Details

Role 'AmazonSageMaker-ExecutionRole-20231014T200029' has AmazonSageMakerFullAccess policy attached

Resolution

Replace AmazonSageMakerFullAccess with more restrictive custom policies that follow the principle of least privilege

Reference

High Failed
111122223333 Global SM-02
SageMaker Full Access Policy Used
Details and remediation
Details

Role 'AmazonSageMaker-ExecutionRole-20250525T153161' has AmazonSageMakerFullAccess policy attached

Resolution

Replace AmazonSageMakerFullAccess with more restrictive custom policies that follow the principle of least privilege

Reference

High Failed
111122223333 Global SM-02
SageMaker Full Access Policy Used
Details and remediation
Details

Role 'AmazonSageMakerServiceCatalogProductsExecutionRole' has AmazonSageMakerFullAccess policy attached

Resolution

Replace AmazonSageMakerFullAccess with more restrictive custom policies that follow the principle of least privilege

Reference

High Failed
111122223333 Global SM-02
SageMaker Full Access Policy Used
Details and remediation
Details

Role 'EMR_EC2_DefaultRole' has AmazonSageMakerFullAccess policy attached

Resolution

Replace AmazonSageMakerFullAccess with more restrictive custom policies that follow the principle of least privilege

Reference

High Failed
111122223333 Global SM-02
SageMaker Full Access Policy Used
Details and remediation
Details

Role 'IDPSageMakerCfnStack-SageMakerExecutionRole-aqrHz6dVkoHC' has AmazonSageMakerFullAccess policy attached

Resolution

Replace AmazonSageMakerFullAccess with more restrictive custom policies that follow the principle of least privilege

Reference

High Failed
111122223333 Global SM-02
SageMaker Full Access Policy Used
Details and remediation
Details

Role 'LLMEvaluationPromptfoo-SageMakerExecutionRole-M69xCHJ9c3LU' has AmazonSageMakerFullAccess policy attached

Resolution

Replace AmazonSageMakerFullAccess with more restrictive custom policies that follow the principle of least privilege

Reference

High Failed
111122223333 Global SM-02
SageMaker Full Access Policy Used
Details and remediation
Details

Role 'SageMaker-EMR-ExecutionRole' has AmazonSageMakerFullAccess policy attached

Resolution

Replace AmazonSageMakerFullAccess with more restrictive custom policies that follow the principle of least privilege

Reference

High Failed
111122223333 us-east-1 SM-01
Non-VPC Only Network Access
Details and remediation
Details

SageMaker domain 'd-cz8qi7j81si3' (QuickSetupDomain-20250525T153160) is not configured for VPC-only access

Resolution

Configure the SageMaker domain to use VPC-only network access type

Reference

High Failed
111122223333 us-east-1 SM-02
SSO Not Properly Configured
Details and remediation
Details

SageMaker domain 'd-cz8qi7j81si3' (QuickSetupDomain-20250525T153160) is using authentication mode: IAM

Resolution

Enable and properly configure AWS IAM Identity Center (successor to AWS SSO) for centralized access management. Ensure Identity Store ID is configured.

Reference

Medium Failed
111122223333 us-east-1 SM-03
Missing Encryption Configuration
Details and remediation
Details

Domain 'QuickSetupDomain-20250525T153160' - No KMS key configured

Resolution

Configure encryption using AWS KMS customer managed keys for enhanced security

Reference

High Failed
111122223333 us-east-1 SM-04
GuardDuty Enabled
Details and remediation
Details

Amazon GuardDuty is properly enabled and monitoring for security threats in SageMaker workloads.

Resolution

No action required

Reference

Medium Passed
111122223333 us-east-1 SM-05
SageMaker Model Registry Issue
Details and remediation
Details

No model package groups found

Resolution

Implement model versioning using SageMaker Model Registry to track model lineage, approve model versions, and manage model deployment

Reference

Informational N/A
111122223333 us-east-1 SM-05
SageMaker Feature Store Issue
Details and remediation
Details

No feature groups found

Resolution

Utilize SageMaker Feature Store to create, share, and manage features for machine learning development and production

Reference

Informational N/A
111122223333 us-east-1 SM-05
SageMaker Pipelines Issue
Details and remediation
Details

No ML pipelines found

Resolution

Implement SageMaker Pipelines to automate and manage ML workflows, including data preparation, training, and model deployment

Reference

Informational N/A
111122223333 us-east-1 SM-06
SageMaker Clarify No Clarify Usage
Details and remediation
Details

No SageMaker Clarify jobs found

Resolution

Implement SageMaker Clarify for model explainability and bias detection

Reference

Informational N/A
111122223333 us-east-1 SM-07
SageMaker Model Monitor No Model Monitoring
Details and remediation
Details

No Model Monitor schedules found

Resolution

Configure comprehensive model monitoring schedules

Reference

Informational N/A
111122223333 us-east-1 SM-08
Model Registry Registry Not Used
Details and remediation
Details

Model Registry is not being utilized

Resolution

Implement proper model versioning and approval workflows

Reference

Informational N/A
111122223333 us-east-1 SM-09
SageMaker Notebook Root Access Check
Details and remediation
Details

No notebook instances found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-1 SM-10
SageMaker Notebook VPC Deployment Check
Details and remediation
Details

No notebook instances found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-1 SM-11
SageMaker Model Network Isolation Check
Details and remediation
Details

No models found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-1 SM-12
SageMaker Endpoint Instance Count Check
Details and remediation
Details

No InService endpoints found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-1 SM-13
SageMaker Monitoring Network Isolation Check
Details and remediation
Details

No monitoring schedules found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-1 SM-14
SageMaker Model Repository Access Check
Details and remediation
Details

No models found or all use default Platform access

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-1 SM-15
SageMaker Feature Store Encryption Check
Details and remediation
Details

No feature groups with offline stores found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-1 SM-16
SageMaker Data Quality Job Encryption Check
Details and remediation
Details

No data quality job definitions found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-1 SM-17
SageMaker Processing Job Encryption Check
Details and remediation
Details

No processing jobs found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-1 SM-18
SageMaker Transform Job Encryption Check
Details and remediation
Details

No transform jobs found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-1 SM-19
SageMaker Hyperparameter Tuning Job Encryption Check
Details and remediation
Details

No hyperparameter tuning jobs found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-1 SM-20
SageMaker Compilation Job Encryption Check
Details and remediation
Details

No compilation jobs found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-1 SM-21
SageMaker AutoML Job Network Isolation Check
Details and remediation
Details

No AutoML jobs found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-1 SM-22
Model Approval Workflow Check
Details and remediation
Details

No model package groups found. Model Registry is not being used for model governance.

Resolution

Implement Model Registry to track model versions and enforce approval workflows before production deployment.

Reference

Informational N/A
111122223333 us-east-1 SM-23
Model Drift Detection Check
Details and remediation
Details

No InService endpoints found to monitor.

Resolution

No action required

Reference

Medium Passed
111122223333 us-east-1 SM-24
A/B Testing and Shadow Deployment Check
Details and remediation
Details

No InService endpoints found.

Resolution

No action required

Reference

Low Passed
111122223333 us-east-1 SM-25
ML Lineage Tracking - Experiments Not Used
Details and remediation
Details

No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Implement SageMaker Experiments to track ML training runs, hyperparameters, metrics, and model artifacts. This enables reproducibility and auditability.

Reference

Informational N/A
111122223333 us-west-2 SM-01
Non-VPC Only Network Access
Details and remediation
Details

SageMaker domain 'd-krxh4fmtaxjl' (PromptEvaluationDomain) is not configured for VPC-only access

Resolution

Configure the SageMaker domain to use VPC-only network access type

Reference

High Failed
111122223333 us-west-2 SM-02
SSO Not Properly Configured
Details and remediation
Details

SageMaker domain 'd-krxh4fmtaxjl' (PromptEvaluationDomain) is using authentication mode: IAM

Resolution

Enable and properly configure AWS IAM Identity Center (successor to AWS SSO) for centralized access management. Ensure Identity Store ID is configured.

Reference

Medium Failed
111122223333 us-west-2 SM-03
Missing Encryption Configuration
Details and remediation
Details

Domain 'PromptEvaluationDomain' - No KMS key configured

Resolution

Configure encryption using AWS KMS customer managed keys for enhanced security

Reference

High Failed
111122223333 us-west-2 SM-04
GuardDuty Enabled
Details and remediation
Details

Amazon GuardDuty is properly enabled and monitoring for security threats in SageMaker workloads.

Resolution

No action required

Reference

Medium Passed
111122223333 us-west-2 SM-05
SageMaker Model Registry Issue
Details and remediation
Details

No model package groups found

Resolution

Implement model versioning using SageMaker Model Registry to track model lineage, approve model versions, and manage model deployment

Reference

Informational N/A
111122223333 us-west-2 SM-05
SageMaker Feature Store Issue
Details and remediation
Details

No feature groups found

Resolution

Utilize SageMaker Feature Store to create, share, and manage features for machine learning development and production

Reference

Informational N/A
111122223333 us-west-2 SM-05
SageMaker Pipelines Issue
Details and remediation
Details

No ML pipelines found

Resolution

Implement SageMaker Pipelines to automate and manage ML workflows, including data preparation, training, and model deployment

Reference

Informational N/A
111122223333 us-west-2 SM-06
SageMaker Clarify No Clarify Usage
Details and remediation
Details

No SageMaker Clarify jobs found

Resolution

Implement SageMaker Clarify for model explainability and bias detection

Reference

Informational N/A
111122223333 us-west-2 SM-07
SageMaker Model Monitor No Model Monitoring
Details and remediation
Details

No Model Monitor schedules found

Resolution

Configure comprehensive model monitoring schedules

Reference

Informational N/A
111122223333 us-west-2 SM-08
Model Registry Registry Not Used
Details and remediation
Details

Model Registry is not being utilized

Resolution

Implement proper model versioning and approval workflows

Reference

Informational N/A
111122223333 us-west-2 SM-09
SageMaker Notebook Root Access Check
Details and remediation
Details

No notebook instances found

Resolution

No action required

Reference

Informational N/A
111122223333 us-west-2 SM-10
SageMaker Notebook VPC Deployment Check
Details and remediation
Details

No notebook instances found

Resolution

No action required

Reference

Informational N/A
111122223333 us-west-2 SM-11
SageMaker Model Network Isolation Check
Details and remediation
Details

No models found

Resolution

No action required

Reference

Informational N/A
111122223333 us-west-2 SM-12
SageMaker Endpoint Instance Count Check
Details and remediation
Details

No InService endpoints found

Resolution

No action required

Reference

Informational N/A
111122223333 us-west-2 SM-13
SageMaker Monitoring Network Isolation Check
Details and remediation
Details

No monitoring schedules found

Resolution

No action required

Reference

Informational N/A
111122223333 us-west-2 SM-14
SageMaker Model Repository Access Check
Details and remediation
Details

No models found or all use default Platform access

Resolution

No action required

Reference

Informational N/A
111122223333 us-west-2 SM-15
SageMaker Feature Store Encryption Check
Details and remediation
Details

No feature groups with offline stores found

Resolution

No action required

Reference

Informational N/A
111122223333 us-west-2 SM-16
SageMaker Data Quality Job Encryption Check
Details and remediation
Details

No data quality job definitions found

Resolution

No action required

Reference

Informational N/A
111122223333 us-west-2 SM-17
SageMaker Processing Job Encryption Check
Details and remediation
Details

No processing jobs found

Resolution

No action required

Reference

Informational N/A
111122223333 us-west-2 SM-18
SageMaker Transform Job Encryption Check
Details and remediation
Details

No transform jobs found

Resolution

No action required

Reference

Informational N/A
111122223333 us-west-2 SM-19
SageMaker Hyperparameter Tuning Job Encryption Check
Details and remediation
Details

No hyperparameter tuning jobs found

Resolution

No action required

Reference

Informational N/A
111122223333 us-west-2 SM-20
SageMaker Compilation Job Encryption Check
Details and remediation
Details

No compilation jobs found

Resolution

No action required

Reference

Informational N/A
111122223333 us-west-2 SM-21
SageMaker AutoML Job Network Isolation Check
Details and remediation
Details

No AutoML jobs found

Resolution

No action required

Reference

Informational N/A
111122223333 us-west-2 SM-22
Model Approval Workflow Check
Details and remediation
Details

No model package groups found. Model Registry is not being used for model governance.

Resolution

Implement Model Registry to track model versions and enforce approval workflows before production deployment.

Reference

Informational N/A
111122223333 us-west-2 SM-23
Model Drift Detection Check
Details and remediation
Details

No InService endpoints found to monitor.

Resolution

No action required

Reference

Medium Passed
111122223333 us-west-2 SM-24
A/B Testing and Shadow Deployment Check
Details and remediation
Details

No InService endpoints found.

Resolution

No action required

Reference

Low Passed
111122223333 us-west-2 SM-25
ML Lineage Tracking - Experiments Not Used
Details and remediation
Details

No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Implement SageMaker Experiments to track ML training runs, hyperparameters, metrics, and model artifacts. This enables reproducibility and auditability.

Reference

Informational N/A
111122223333 Global BR-01
AmazonBedrockFullAccess role check
Details and remediation
Details

Role 'IDPSageMakerCfnStack-SageMakerExecutionRole-aqrHz6dVkoHC' has AmazonBedrockFullAccess policy attached

Resolution

Limit the AmazonBedrockFullAccess policy only to required access

Reference

High Failed
111122223333 Global BR-01
AmazonBedrockFullAccess role check
Details and remediation
Details

Role 'LLMEvaluationPromptfoo-SageMakerExecutionRole-M69xCHJ9c3LU' has AmazonBedrockFullAccess policy attached

Resolution

Limit the AmazonBedrockFullAccess policy only to required access

Reference

High Failed
111122223333 Global BR-01
AmazonBedrockFullAccess role check
Details and remediation
Details

Role 'myAskMeAnything-role-kmsizqwf' has AmazonBedrockFullAccess policy attached

Resolution

Limit the AmazonBedrockFullAccess policy only to required access

Reference

High Failed
111122223333 Global BR-03
Marketplace Subscription Access Check
Details and remediation
Details

Role 'AmazonBedrockAgentCoreSDKRuntime-us-east-1-a6ddf3fc76' has overly permissive marketplace subscription access through policy 'BedrockAgentCoreRuntimeExecutionPolicy-cdk_agent_core'

Resolution

Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check.

Reference

High Failed
111122223333 Global BR-03
Marketplace Subscription Access Check
Details and remediation
Details

Role 'AmazonBedrockAgentCoreSDKRuntime-us-east-1-ed660add8b' has overly permissive marketplace subscription access through policy 'BedrockAgentCoreRuntimeExecutionPolicy-neoCyan_Agent'

Resolution

Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check.

Reference

High Failed
111122223333 Global BR-03
Marketplace Subscription Access Check
Details and remediation
Details

Role 'AmazonBedrockExecutionRoleForKnowledgeBase_knnc9' has overly permissive marketplace subscription access through policy 'AmazonBedrockFoundationModelPolicyForKnowledgeBase_knnc9'

Resolution

Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check.

Reference

High Failed
111122223333 Global BR-03
Marketplace Subscription Access Check
Details and remediation
Details

Role 'AmazonBedrockExecutionRoleForKnowledgeBase_qxqw2' has overly permissive marketplace subscription access through policy 'AmazonBedrockFoundationModelPolicyForKnowledgeBase_qxqw2'

Resolution

Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check.

Reference

High Failed
111122223333 Global BR-03
Marketplace Subscription Access Check
Details and remediation
Details

Role 'AmazonSageMaker-ExecutionRole-20250525T153161' has overly permissive marketplace subscription access through policy 'AmazonBedrockLimitedAccess'

Resolution

Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check.

Reference

High Failed
111122223333 Global BR-03
Marketplace Subscription Access Check
Details and remediation
Details

Role 'IDPSageMakerCfnStack-SageMakerExecutionRole-aqrHz6dVkoHC' has overly permissive marketplace subscription access through policy 'AmazonBedrockFullAccess'

Resolution

Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check.

Reference

High Failed
111122223333 Global BR-03
Marketplace Subscription Access Check
Details and remediation
Details

Role 'LLMEvaluationPromptfoo-SageMakerExecutionRole-M69xCHJ9c3LU' has overly permissive marketplace subscription access through policy 'AmazonBedrockFullAccess'

Resolution

Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check.

Reference

High Failed
111122223333 Global BR-03
Marketplace Subscription Access Check
Details and remediation
Details

Role 'myAskMeAnything-role-kmsizqwf' has overly permissive marketplace subscription access through policy 'AmazonBedrockFullAccess'

Resolution

Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check.

Reference

High Failed
111122223333 Global BR-03
Marketplace Subscription Access Check
Details and remediation
Details

User 'BedrockAPIKey-20pp' has overly permissive marketplace subscription access through policy 'AmazonBedrockLimitedAccess'

Resolution

Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check.

Reference

High Failed
111122223333 Global BR-03
Marketplace Subscription Access Check
Details and remediation
Details

User 'BedrockAPIKey-yhc3' has overly permissive marketplace subscription access through policy 'AmazonBedrockLimitedAccess'

Resolution

Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check.

Reference

High Failed
111122223333 Global BR-03
Marketplace Subscription Access Check
Details and remediation
Details

User 'BedrockClientUser' has overly permissive marketplace subscription access through policy 'AmazonBedrockFullAccess'

Resolution

Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check.

Reference

High Failed
111122223333 us-east-1 BR-02
Amazon Bedrock private connectivity not used
Details and remediation
Details

No Bedrock service VPC endpoints found in VPCs: vpc-03472be90d65c2f68, vpc-39319f44, vpc-064f3e808e378cbc8, vpc-02d020a365a06c7fe

Resolution

Create a VPC endpoint in your VPC with any of the following Bedrock service endpoints that your application may be using: - com.amazonaws.region.bedrock - com.amazonaws.region.bedrock-runtime - com.amazonaws.region.bedrock-agent - com.amazonaws.region.bedrock-agent-runtime

Reference

Medium Failed
111122223333 us-east-1 BR-04
Bedrock Model Invocation Logging Check
Details and remediation
Details

Model invocation logging is properly configured with delivery to: Amazon S3, CloudWatch Logs

Resolution

No action required

Reference

Medium Passed
111122223333 us-east-1 BR-05
Bedrock Guardrails Check
Details and remediation
Details

Amazon Bedrock Guardrails are properly configured with 1 guardrails

Resolution

No action required. Continue monitoring and updating guardrails as needed.

Reference

High Passed
111122223333 us-east-1 BR-06
Bedrock CloudTrail Logging Check
Details and remediation
Details

CloudTrail is properly configured to log Bedrock API activity in trails: IsengardTrail-DO-NOT-DELETE

Resolution

No action required. Continue monitoring CloudTrail logs for Bedrock activity.

Reference

Medium Passed
111122223333 us-east-1 BR-07
Bedrock Prompt Management Check
Details and remediation
Details

Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses.

Resolution

Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates

Reference

Informational N/A
111122223333 us-east-1 BR-08
Bedrock Agent IAM Roles Check
Details and remediation
Details

No Bedrock agents found in the account

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-1 BR-09
Bedrock Knowledge Base Encryption Review
Details and remediation
Details

Knowledge Base 'knowledge-base-semiconductors' (RQYFDSE1LT) uses 'OPENSEARCH_SERVERLESS' storage. Encryption is managed at the storage layer and cannot be validated from the KB API. Verify encryption configuration on the underlying storage resource.

Resolution

1. For OpenSearch Serverless: Verify encryption with CMK at collection level 2. For S3 data sources: Verify CMK-encrypted S3 buckets 3. For RDS: Verify KMS encryption on the database 4. Consider using CMK for transient data during ingestion

Reference

Informational N/A
111122223333 us-east-1 BR-09
Bedrock Knowledge Base Encryption Review
Details and remediation
Details

Knowledge Base '111122223333-us-east-1-kb' (PAJOKBSIMQ) uses 'S3_VECTORS' storage. Encryption is managed at the storage layer and cannot be validated from the KB API. Verify encryption configuration on the underlying storage resource.

Resolution

1. For OpenSearch Serverless: Verify encryption with CMK at collection level 2. For S3 data sources: Verify CMK-encrypted S3 buckets 3. For RDS: Verify KMS encryption on the database 4. Consider using CMK for transient data during ingestion

Reference

Informational N/A
111122223333 us-east-1 BR-09
Bedrock Knowledge Base Encryption Review
Details and remediation
Details

Knowledge Base 'e2e-rag-knowledgebase' (ESIYAYSYTJ) uses 'OPENSEARCH_SERVERLESS' storage. Encryption is managed at the storage layer and cannot be validated from the KB API. Verify encryption configuration on the underlying storage resource.

Resolution

1. For OpenSearch Serverless: Verify encryption with CMK at collection level 2. For S3 data sources: Verify CMK-encrypted S3 buckets 3. For RDS: Verify KMS encryption on the database 4. Consider using CMK for transient data during ingestion

Reference

Informational N/A
111122223333 us-east-1 BR-10
Bedrock Guardrail IAM Enforcement Missing
Details and remediation
Details

The following roles can invoke Bedrock models without enforced guardrails: 111122223333-us-east-1-kb-bedrock-service-role, agentcore-wildrydes_gateway_role_ab3991f6-role, AgentCoreEvalsSDK-us-east-1-d04ba7b68b, AmazonBedrockAgentCoreSDKRuntime-us-east-1-a6ddf3fc76, AmazonBedrockAgentCoreSDKRuntime-us-east-1-ed660add8b, AmazonBedrockExecutionRoleForAgents_S0T9VNPP9D, AmazonBedrockExecutionRoleForAgents_WNCOPE29NZ, AmazonBedrockExecutionRoleForKnowledgeBase_072pr, AmazonBedrockExecutionRoleForKnowledgeBase_byjin, AmazonBedrockExecutionRoleForKnowledgeBase_h9718...

Resolution

Add IAM policy conditions to enforce guardrail usage: 1. Use 'bedrock:GuardrailIdentifier' condition key 2. Specify required guardrail ARN or ID 3. Example: "Condition": {"StringEquals": {"bedrock:GuardrailIdentifier": "arn:aws:bedrock:region:account:guardrail/guardrail-id"}}

Reference

High Failed
111122223333 us-east-1 BR-11
Bedrock Custom Model Encryption Check
Details and remediation
Details

No custom/fine-tuned models found in the account

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-1 BR-12
Bedrock Invocation Log Encryption
Details and remediation
Details

S3 bucket 'nistairmfguardrail-invocationlogsbucket8fe5371b-wmlsng7pkyhm' for invocation logs uses SSE-S3 encryption instead of customer-managed KMS. Invocation logs may contain sensitive prompts and responses.

Resolution

1. Enable SSE-KMS with a customer-managed key on the S3 bucket 2. Update bucket policy to require encrypted uploads 3. Consider enabling S3 bucket versioning and MFA delete for log integrity

Reference

Medium Failed
111122223333 us-east-1 BR-13
Bedrock Flows Guardrails Check
Details and remediation
Details

No Bedrock Flows found in the account

Resolution

No action required

Reference

Informational N/A
111122223333 Global BR-15
Cross-Account Guardrails Enforcement Check
Details and remediation
Details

Check must run in AWS Organizations management account to evaluate organizational policies

Resolution

Run assessment in management account to check cross-account guardrails enforcement

Reference

Medium N/A
111122223333 us-east-1 BR-16
Guardrail Tier Validation Check
Details and remediation
Details

Guardrail 'nist-ai-rmf-guardrail' (ID: do7xkmhadx7k) is using the 'CLASSIC' content-filter tier instead of 'STANDARD'. The STANDARD tier provides more robust content filtering and broader language support than the CLASSIC tier.

Resolution

Update the guardrail to use the STANDARD content-filter tier for improved contextual understanding, better prompt attack filtering (distinguishing jailbreaks from prompt injection), and broader language support. The STANDARD tier requires cross-Region inference. Review pricing implications before upgrading.

Reference

Medium Failed
111122223333 us-east-1 BR-17
Custom Model Customer-Managed KMS Encryption Check
Details and remediation
Details

No custom (fine-tuned) Bedrock models found in this region

Resolution

When creating custom models, specify a customer-managed KMS key for encryption to maintain control over encryption keys

Reference

High N/A
111122223333 us-east-1 BR-18
Model Evaluation Implementation Check
Details and remediation
Details

No Bedrock model evaluation jobs found. Model evaluation helps assess toxicity, accuracy, semantic robustness, and other safety metrics before production deployment.

Resolution

Create model evaluation jobs using Amazon Bedrock Evaluations to assess foundation model performance against safety and quality metrics. Use built-in datasets or custom test sets. Enable LLM-as-a-judge evaluation for comprehensive assessment.

Reference

Medium Failed
111122223333 us-east-1 BR-19
Prompt Flow Validation Check
Details and remediation
Details

No Bedrock prompt flows configured in this region

Resolution

When creating prompt flows, use the ValidateFlowDefinition API to validate flow definitions before deployment

Reference

Medium N/A
111122223333 us-east-1 BR-20
Knowledge Base Customer-Managed KMS Encryption Review
Details and remediation
Details

Knowledge base 'knowledge-base-semiconductors' (ID: RQYFDSE1LT) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store.

Resolution

1. For OpenSearch Serverless: verify the collection uses a customer-managed KMS key 2. For Amazon RDS/Aurora: verify KMS encryption on the database 3. For third-party stores (Pinecone, Redis, MongoDB): verify the provider's encryption configuration 4. Verify the customer-managed KMS key used for transient data during ingestion

Reference

Informational N/A
111122223333 us-east-1 BR-20
Knowledge Base Customer-Managed KMS Encryption Review
Details and remediation
Details

Knowledge base '111122223333-us-east-1-kb' (ID: PAJOKBSIMQ) uses 'S3_VECTORS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store.

Resolution

1. For OpenSearch Serverless: verify the collection uses a customer-managed KMS key 2. For Amazon RDS/Aurora: verify KMS encryption on the database 3. For third-party stores (Pinecone, Redis, MongoDB): verify the provider's encryption configuration 4. Verify the customer-managed KMS key used for transient data during ingestion

Reference

Informational N/A
111122223333 us-east-1 BR-20
Knowledge Base Customer-Managed KMS Encryption Review
Details and remediation
Details

Knowledge base 'e2e-rag-knowledgebase' (ID: ESIYAYSYTJ) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store.

Resolution

1. For OpenSearch Serverless: verify the collection uses a customer-managed KMS key 2. For Amazon RDS/Aurora: verify KMS encryption on the database 3. For third-party stores (Pinecone, Redis, MongoDB): verify the provider's encryption configuration 4. Verify the customer-managed KMS key used for transient data during ingestion

Reference

Informational N/A
111122223333 us-east-1 BR-21
Agent Action Group IAM Least Privilege Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents with action groups, ensure Lambda execution roles follow least privilege principles

Reference

High N/A
111122223333 us-east-1 BR-22
Model Invocation Throttling Limits Check
Details and remediation
Details

11 custom throttling quotas are configured. Regular quota review helps maintain appropriate rate limits.

Resolution

Continue monitoring quota utilization. Review and adjust quotas as application requirements change.

Reference

Low Passed
111122223333 us-east-1 BR-23
Guardrail Content Filter Coverage Check
Details and remediation
Details

1 guardrails have complete content filter coverage (hate, insults, sexual, violence)

Resolution

No action required. Continue monitoring filter effectiveness and adjust thresholds as needed.

Reference

Low Passed
111122223333 us-east-1 BR-24
Automated Reasoning Policy Implementation Check
Details and remediation
Details

Guardrail 'nist-ai-rmf-guardrail' (ID: do7xkmhadx7k) does not have an Automated Reasoning policy configured. Automated Reasoning provides formal verification of model responses against defined policies.

Resolution

Configure Automated Reasoning policies on guardrails to mathematically verify model responses. Define policies that specify allowed and disallowed behaviors. Use for high-assurance use cases where formal verification is required.

Reference

Medium Failed
111122223333 us-east-1 BR-25
RAG Evaluation Jobs Check
Details and remediation
Details

Knowledge base 'knowledge-base-semiconductors' (ID: RQYFDSE1LT) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations.

Resolution

Create RAG evaluation jobs for knowledge bases using Amazon Bedrock Model Evaluation. Configure evaluations to test context relevance, answer correctness, and faithfulness metrics. Run evaluations regularly (monthly or after significant KB updates) to maintain quality.

Reference

Low Failed
111122223333 us-east-1 BR-25
RAG Evaluation Jobs Check
Details and remediation
Details

Knowledge base '111122223333-us-east-1-kb' (ID: PAJOKBSIMQ) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations.

Resolution

Create RAG evaluation jobs for knowledge bases using Amazon Bedrock Model Evaluation. Configure evaluations to test context relevance, answer correctness, and faithfulness metrics. Run evaluations regularly (monthly or after significant KB updates) to maintain quality.

Reference

Low Failed
111122223333 us-east-1 BR-25
RAG Evaluation Jobs Check
Details and remediation
Details

Knowledge base 'e2e-rag-knowledgebase' (ID: ESIYAYSYTJ) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations.

Resolution

Create RAG evaluation jobs for knowledge bases using Amazon Bedrock Model Evaluation. Configure evaluations to test context relevance, answer correctness, and faithfulness metrics. Run evaluations regularly (monthly or after significant KB updates) to maintain quality.

Reference

Low Failed
111122223333 us-east-1 BR-26
Guardrail Sensitive Information Filter Check
Details and remediation
Details

1 guardrails have sensitive-information (PII) filters configured

Resolution

No action required. Periodically review the PII entity types and regex patterns to ensure coverage matches your data.

Reference

Low Passed
111122223333 us-east-1 BR-27
Guardrail Contextual Grounding Check
Details and remediation
Details

1 guardrails have contextual grounding checks enabled

Resolution

No action required. Review grounding and relevance thresholds periodically to balance hallucination detection against false positives.

Reference

Low Passed
111122223333 us-east-1 BR-28
Agent Guardrail Association Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents, associate a Bedrock guardrail so agent inputs and responses are filtered for harmful content, PII, and denied topics

Reference

High N/A
111122223333 us-east-1 BR-29
Agent Idle Session TTL Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents, set a conservative idleSessionTTLInSeconds to limit how long an idle session remains resumable

Reference

Low N/A
111122223333 us-east-1 BR-30
Imported Model Customer-Managed KMS Encryption Check
Details and remediation
Details

No imported custom Bedrock models found in this region

Resolution

When importing models, specify a customer-managed KMS key for encryption to maintain control over encryption keys

Reference

High N/A
111122223333 us-east-1 BR-31
Batch Inference Output Encryption Check
Details and remediation
Details

No Bedrock batch inference (model invocation) jobs found in this region

Resolution

When creating batch inference jobs, set outputDataConfig.s3OutputDataConfig.s3EncryptionKeyId to a customer-managed KMS key to encrypt the job output

Reference

Medium N/A
111122223333 us-east-1 BR-32
Bedrock CloudWatch Alarm Check
Details and remediation
Details

No CloudWatch alarms are configured on Amazon Bedrock runtime metrics (AWS/Bedrock namespace). Without alarms, abuse, denial-of-wallet, sustained throttling, and content-filter spikes can go undetected.

Resolution

Create CloudWatch alarms on AWS/Bedrock runtime metrics such as Invocations, InvocationThrottles, InputTokenCount, OutputTokenCount, and ContentFilteredCount, and route them to an Amazon SNS topic for notification.

Reference

Medium Failed
111122223333 us-east-1 BR-33
Amazon Inspector Lambda Code Scanning Check
Details and remediation
Details

Amazon Inspector Lambda scanning is not fully enabled in us-east-1. Lambda standard scan status: ENABLED. Lambda code scan status: DISABLED. Detected 6 Lambda function(s) with Bedrock indicators: aiml-security-aiml-security-111122223333-BedrockAssessment, e2ebedrockrag-OSSInfraStack-BKBOSSInfraSetupLambda-031La8JAQXtk, gateway_lambda, myAskMeAnything, resco-aiml-BedrockAssessment (and 1 more). Without both scan types enabled, vulnerable dependencies and hardcoded secrets in these in-scope functions will not be detected.

Resolution

Enable both Lambda standard scanning and Lambda code scanning in Amazon Inspector for this account and region. Console: Inspector -> Account management -> Activate for Lambda functions and Lambda code.

Reference

Medium Failed
111122223333 us-east-1 AG-07
Agentic AI Model Invocation Logging
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: Model invocation logging is properly configured with delivery to: Amazon S3, CloudWatch Logs

Resolution

Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements.

Reference

Medium Passed
111122223333 us-east-1 AG-08
Agentic AI API Audit Trail
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: CloudTrail is properly configured to log Bedrock API activity in trails: IsengardTrail-DO-NOT-DELETE

Resolution

Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured.

Reference

Medium Passed
111122223333 Global AG-09
Agentic AI Guardrail Enforcement Boundary
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Organization-level guardrail enforcement helps prevent agents from bypassing required safety controls across accounts. Source check BR-15: Check must run in AWS Organizations management account to evaluate organizational policies

Resolution

Use IAM and organization controls to require approved guardrails for model and agent invocations where supported.

Reference

Informational N/A
111122223333 us-east-1 AG-10
Agentic AI Adversarial Evaluation Coverage
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No Bedrock model evaluation jobs found. Model evaluation helps assess toxicity, accuracy, semantic robustness, and other safety metrics before production deployment.

Resolution

Configure model or application evaluations that include adversarial, safety, and security-relevant test cases.

Reference

Medium Failed
111122223333 us-east-1 AG-11
Agentic AI Prompt Flow Validation
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region

Resolution

Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions.

Reference

Informational N/A
111122223333 us-east-1 AG-06
Agentic AI Tool Execution Least Privilege
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region

Resolution

Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required.

Reference

Informational N/A
111122223333 us-east-1 AG-12
Agentic AI Invocation Abuse Controls
Details and remediation
Details

Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: 11 custom throttling quotas are configured. Regular quota review helps maintain appropriate rate limits.

Resolution

Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns.

Reference

Low Passed
111122223333 us-east-1 AG-02
Agentic AI Harmful Content Guardrail Coverage
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: 1 guardrails have complete content filter coverage (hate, insults, sexual, violence)

Resolution

Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads.

Reference

Low Passed
111122223333 us-east-1 AG-04
Agentic AI Automated Reasoning Guardrails
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: Guardrail 'nist-ai-rmf-guardrail' (ID: do7xkmhadx7k) does not have an Automated Reasoning policy configured. Automated Reasoning provides formal verification of model responses against defined policies.

Resolution

Configure automated reasoning policies on guardrails where formal response validation is required.

Reference

Medium Failed
111122223333 us-east-1 AG-03
Agentic AI Sensitive Information Protection
Details and remediation
Details

Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: 1 guardrails have sensitive-information (PII) filters configured

Resolution

Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns.

Reference

Low Passed
111122223333 us-east-1 AG-05
Agentic AI Grounding Controls
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: 1 guardrails have contextual grounding checks enabled

Resolution

Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows.

Reference

Low Passed
111122223333 us-east-1 AG-01
Agentic AI Agent Guardrail Association
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region

Resolution

Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating.

Reference

Informational N/A
111122223333 us-east-1 AG-13
Agentic AI Session Boundary
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region

Resolution

Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements.

Reference

Informational N/A
111122223333 us-east-1 AG-14
Agentic AI Operational Abuse Alarms
Details and remediation
Details

Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No CloudWatch alarms are configured on Amazon Bedrock runtime metrics (AWS/Bedrock namespace). Without alarms, abuse, denial-of-wallet, sustained throttling, and content-filter spikes can go undetected.

Resolution

Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available.

Reference

Medium Failed
111122223333 us-east-2 SM-01
SageMaker Internet Access Check
Details and remediation
Details

No SageMaker notebook instances or domains found to check

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 SM-02
SageMaker SSO Configuration Check
Details and remediation
Details

No SageMaker domains found, or all domains use SSO with IAM Identity Center configured

Resolution

No action required

Reference

Medium Passed
111122223333 us-east-2 SM-03
Missing Encryption Configuration
Details and remediation
Details

Training Job 'xgboost-2021-12-19-01-07-45-798' - No output encryption configured

Resolution

Configure encryption using AWS KMS customer managed keys for enhanced security

Reference

High Failed
111122223333 us-east-2 SM-03
Missing VPC Encryption
Details and remediation
Details

Training Job 'xgboost-2021-12-19-01-07-45-798' - Inter-container traffic encryption not enabled

Resolution

Enable encryption for inter-container traffic and VPC communication

Reference

Medium Failed
111122223333 us-east-2 SM-04
GuardDuty Enabled
Details and remediation
Details

Amazon GuardDuty is properly enabled and monitoring for security threats in SageMaker workloads.

Resolution

No action required

Reference

Medium Passed
111122223333 us-east-2 SM-05
SageMaker Model Registry Issue
Details and remediation
Details

No model package groups found

Resolution

Implement model versioning using SageMaker Model Registry to track model lineage, approve model versions, and manage model deployment

Reference

Informational N/A
111122223333 us-east-2 SM-05
SageMaker Feature Store Issue
Details and remediation
Details

No feature groups found

Resolution

Utilize SageMaker Feature Store to create, share, and manage features for machine learning development and production

Reference

Informational N/A
111122223333 us-east-2 SM-05
SageMaker Pipelines Issue
Details and remediation
Details

No ML pipelines found

Resolution

Implement SageMaker Pipelines to automate and manage ML workflows, including data preparation, training, and model deployment

Reference

Informational N/A
111122223333 us-east-2 SM-06
SageMaker Clarify No Clarify Usage
Details and remediation
Details

No SageMaker Clarify jobs found

Resolution

Implement SageMaker Clarify for model explainability and bias detection

Reference

Informational N/A
111122223333 us-east-2 SM-07
SageMaker Model Monitor No Model Monitoring
Details and remediation
Details

No Model Monitor schedules found

Resolution

Configure comprehensive model monitoring schedules

Reference

Informational N/A
111122223333 us-east-2 SM-08
Model Registry Registry Not Used
Details and remediation
Details

Model Registry is not being utilized

Resolution

Implement proper model versioning and approval workflows

Reference

Informational N/A
111122223333 us-east-2 SM-09
SageMaker Notebook Root Access Check
Details and remediation
Details

No notebook instances found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 SM-10
SageMaker Notebook VPC Deployment Check
Details and remediation
Details

No notebook instances found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 SM-11
SageMaker Model Network Isolation Disabled
Details and remediation
Details

Model 'xgboost-2021-12-19-01-25-44-527' does not have network isolation enabled. Model containers can make outbound network calls, potentially exfiltrating data.

Resolution

Enable network isolation by setting EnableNetworkIsolation=True when creating models. This prevents containers from making outbound network calls.

Reference

High Failed
111122223333 us-east-2 SM-12
SageMaker Endpoint Instance Count Check
Details and remediation
Details

No InService endpoints found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 SM-13
SageMaker Monitoring Network Isolation Check
Details and remediation
Details

No monitoring schedules found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 SM-14
SageMaker Model Platform Repository Access
Details and remediation
Details

Model 'xgboost-2021-12-19-01-25-44-527' uses Platform repository access mode. Container images are pulled from public/external registries, exposing supply chain risks.

Resolution

Configure RepositoryAccessMode=Vpc in ImageConfig to pull images from private ECR repositories through VPC. This provides supply chain security.

Reference

Medium Failed
111122223333 us-east-2 SM-15
SageMaker Feature Store Encryption Check
Details and remediation
Details

No feature groups with offline stores found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 SM-16
SageMaker Data Quality Job Encryption Check
Details and remediation
Details

No data quality job definitions found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 SM-17
SageMaker Processing Job Encryption Check
Details and remediation
Details

No processing jobs found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 SM-18
SageMaker Transform Job Volume Encryption Missing
Details and remediation
Details

Transform job 'xgboost-2021-12-19-01-25-49-740' does not have volume encryption configured. Data at rest on transform instances is not encrypted with customer-managed keys.

Resolution

Configure VolumeKmsKeyId in TransformResources when creating transform jobs to encrypt attached EBS volumes.

Reference

Medium Failed
111122223333 us-east-2 SM-19
SageMaker Hyperparameter Tuning Job Encryption Check
Details and remediation
Details

No hyperparameter tuning jobs found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 SM-20
SageMaker Compilation Job Encryption Check
Details and remediation
Details

No compilation jobs found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 SM-21
SageMaker AutoML Job Network Isolation Check
Details and remediation
Details

No AutoML jobs found

Resolution

No action required

Reference

Informational N/A
111122223333 us-east-2 SM-22
Model Approval Workflow Check
Details and remediation
Details

No model package groups found. Model Registry is not being used for model governance.

Resolution

Implement Model Registry to track model versions and enforce approval workflows before production deployment.

Reference

Informational N/A
111122223333 us-east-2 SM-23
Model Drift Detection Check
Details and remediation
Details

No InService endpoints found to monitor.

Resolution

No action required

Reference

Medium Passed
111122223333 us-east-2 SM-24
A/B Testing and Shadow Deployment Check
Details and remediation
Details

No InService endpoints found.

Resolution

No action required

Reference

Low Passed
111122223333 us-east-2 SM-25
ML Lineage Tracking - Experiments Not Used
Details and remediation
Details

No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Implement SageMaker Experiments to track ML training runs, hyperparameters, metrics, and model artifacts. This enables reproducibility and auditability.

Reference

Informational N/A
444455556666 eu-west-1 AC-01
AgentCore VPC Configuration Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 AC-04
AgentCore Observability Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 AC-05
AgentCore Encryption Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 AC-06
AgentCore Browser Tool Recording Check
Details and remediation
Details

No AgentCore Runtimes found to check browser tool configuration

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 AC-07
AgentCore Memory Configuration Check
Details and remediation
Details

No Memory resources found

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 AC-13
AgentCore Gateway Configuration Check
Details and remediation
Details

No Gateway resources found

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 AC-08
AgentCore VPC Endpoints Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 AC-10
AgentCore Resource-Based Policies Check
Details and remediation
Details

No AgentCore resources found to check for resource-based policies

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 AC-11
AgentCore Policy Engine Encryption Check
Details and remediation
Details

No Policy Engines found

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 AC-12
AgentCore Gateway Encryption Check
Details and remediation
Details

No Gateways found

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 AG-24
Agentic AI Gateway Inbound Authorization
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 AG-25
Agentic AI Gateway Tool Policy Enforcement
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 AG-26
Agentic AI Gateway Error Detail Exposure
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 AG-27
Agentic AI Gateway WAF Protection
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 AG-15
Agentic AI Runtime Network Boundary
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found

Resolution

Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services.

Reference

Informational N/A
444455556666 eu-west-1 AG-18
Agentic AI AgentCore Observability
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found

Resolution

Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported.

Reference

Informational N/A
444455556666 eu-west-1 AG-19
Agentic AI Memory Data Protection
Details and remediation
Details

Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found

Resolution

Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions.

Reference

Informational N/A
444455556666 eu-west-1 AG-20
Agentic AI Private AgentCore Connectivity
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found

Resolution

Create required VPC endpoints for AgentCore services and validate endpoint availability.

Reference

Informational N/A
444455556666 eu-west-1 AG-21
Agentic AI Resource Policy Boundary
Details and remediation
Details

Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies

Resolution

Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources.

Reference

Informational N/A
444455556666 eu-west-1 AG-22
Agentic AI Policy Engine Data Protection
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found

Resolution

Configure policy engines with customer-managed KMS keys where enhanced key control is required.

Reference

Informational N/A
444455556666 eu-west-1 AG-23
Agentic AI Gateway Data Protection
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found

Resolution

Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required.

Reference

Informational N/A
444455556666 us-east-1 OW-01
OWASP LLM01: Model Invocation Logging
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging

Resolution

Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis.

Reference

Informational N/A
444455556666 us-east-1 OW-07
OWASP LLM07: Model Invocation Logging
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging

Resolution

Enable Bedrock model invocation logging so prompt-extraction attempts against the system prompt are auditable after the fact.

Reference

Informational N/A
444455556666 us-east-1 OW-07
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses.

Resolution

Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident.

Reference

Informational N/A
444455556666 us-east-1 OW-07
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-16: No Bedrock guardrails configured in this region

Resolution

Set guardrail contentPolicy.tier.tierName to STANDARD; Standard tier additionally detects prompt-leakage attacks.

Reference

Informational N/A
444455556666 us-east-1 OW-09
OWASP LLM09: Model Evaluation Jobs
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs

Resolution

Run Bedrock model evaluation jobs that include correctness and safety datasets.

Reference

Informational N/A
444455556666 us-east-1 OW-08
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: No Bedrock knowledge bases found in this region

Resolution

Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption.

Reference

Informational N/A
444455556666 us-east-1 OW-06
OWASP LLM06: Agent Action-Group Least Privilege
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-21: No Bedrock agents configured in this region

Resolution

Restrict agent action-group Lambda roles to only the specific actions and resources needed for each tool.

Reference

Informational N/A
444455556666 us-east-1 OW-10
OWASP LLM10: Service Quota Throttling Limits
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas

Resolution

Customise Bedrock TPM / RPM service quotas above the account default to establish an explicit consumption ceiling.

Reference

Informational N/A
444455556666 us-east-1 OW-01
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: No Bedrock guardrails configured in this region

Resolution

Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier.

Reference

Informational N/A
444455556666 us-east-1 OW-04
OWASP LLM04: RAG Evaluation Coverage
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: No Bedrock knowledge bases found in this region

Resolution

Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context.

Reference

Informational N/A
444455556666 us-east-1 OW-09
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-25: No Bedrock knowledge bases found in this region

Resolution

Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates.

Reference

Informational N/A
444455556666 us-east-1 OW-02
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check BR-26: No Bedrock guardrails configured in this region

Resolution

Configure guardrail sensitiveInformationPolicy with PII entities and regex patterns; set outputAction=ANONYMIZE or BLOCK.

Reference

Informational N/A
444455556666 us-east-1 OW-01
OWASP LLM01: Contextual Grounding Guardrail
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Enable Bedrock guardrail contextual grounding checks to reduce the surface for indirect prompt injection through retrieved context.

Reference

Informational N/A
444455556666 us-east-1 OW-04
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Enable contextual grounding guardrail filters so retrieved context that diverges from ground truth is filtered before reaching the model.

Reference

Informational N/A
444455556666 us-east-1 OW-09
OWASP LLM09: Contextual Grounding for Faithfulness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Set the contextual grounding filter threshold to at least 0.70 to reduce hallucinated responses.

Reference

Informational N/A
444455556666 us-east-1 OW-06
OWASP LLM06: Bedrock Agent Guardrail Association
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-28: No Bedrock agents configured in this region

Resolution

Attach an approved Bedrock guardrail to every Bedrock agent so autonomous actions are filtered consistently.

Reference

Informational N/A
444455556666 us-east-1 OW-06
OWASP LLM06: Agent Idle Session TTL
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-29: No Bedrock agents configured in this region

Resolution

Set idleSessionTTLInSeconds to a conservative value (e.g., <= 3600) so long-lived agent sessions cannot be reused.

Reference

Informational N/A
444455556666 us-east-1 OW-03
OWASP LLM03: Imported-Model KMS Provenance
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check BR-30: No imported custom Bedrock models found in this region

Resolution

Encrypt imported Bedrock models with a customer-managed KMS key to preserve provenance and access control across model artefacts.

Reference

Informational N/A
444455556666 us-east-1 OW-10
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms

Resolution

Create CloudWatch alarms on Bedrock InvocationThrottles, InputTokenCount, OutputTokenCount, and EstimatedTPMQuotaUsage.

Reference

Informational N/A
444455556666 us-east-1 OW-03
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check BR-33: Amazon Inspector Lambda standard scanning and Lambda code scanning are both ENABLED in us-east-1. Detected 2 Lambda function(s) with Bedrock indicators: aiml-security-aiml-security-444455556666-BedrockAssessment, resco-aiml-BedrockAssessment.

Resolution

Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain.

Reference

Medium Passed
444455556666 us-east-1 OW-03
OWASP LLM03: SageMaker Internet Exposure
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-01: No SageMaker notebook instances or domains found to check

Resolution

Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths.

Reference

Informational N/A
444455556666 us-east-1 OW-02
OWASP LLM02: SageMaker Data Encryption
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: No SageMaker resources found to check for data protection

Resolution

Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data.

Reference

Informational N/A
444455556666 us-east-1 OW-09
OWASP LLM09: SageMaker Clarify Evaluation
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-06: No SageMaker Clarify jobs found

Resolution

Use SageMaker Clarify to evaluate bias and explainability for models whose generated outputs can influence user decisions.

Reference

Informational N/A
444455556666 us-east-1 OW-04
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-07: No Model Monitor schedules found

Resolution

Configure active SageMaker Model Monitor schedules so data-quality and model-quality regressions caused by poisoned inputs or drift are detected.

Reference

Informational N/A
444455556666 us-east-1 OW-09
OWASP LLM09: SageMaker Model Monitor Coverage
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-07: No Model Monitor schedules found

Resolution

Configure SageMaker Model Monitor schedules for production models so quality regressions that can produce incorrect outputs are detected.

Reference

Informational N/A
444455556666 us-east-1 OW-03
OWASP LLM03: SageMaker Notebook VPC Deployment
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-10: No notebook instances found

Resolution

Deploy SageMaker notebook instances inside a VPC so package, data, and model artifact access can be controlled through private network paths.

Reference

Informational N/A
444455556666 us-east-1 OW-03
OWASP LLM03: SageMaker Model Network Isolation
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-11: No models found

Resolution

Enable network isolation on SageMaker models so inference containers cannot make unmanaged outbound calls that alter dependencies or exfiltrate model artifacts.

Reference

Informational N/A
444455556666 us-east-1 OW-10
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check SM-11: No models found

Resolution

Enable SageMaker model network isolation to prevent deployed model containers from making uncontrolled outbound calls that can amplify consumption or abuse downstream services.

Reference

Informational N/A
444455556666 us-east-1 OW-03
OWASP LLM03: SageMaker Container Repository Access
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-14: No models found or all use default Platform access

Resolution

Configure SageMaker models to pull container images from private ECR repositories through VPC repository access instead of platform or public registry paths.

Reference

Informational N/A
444455556666 us-east-1 OW-02
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-15: No feature groups with offline stores found

Resolution

Encrypt SageMaker Feature Store offline stores with customer-managed KMS keys so sensitive feature data is protected at rest.

Reference

Informational N/A
444455556666 us-east-1 OW-03
OWASP LLM03: SageMaker AutoML Network Isolation
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-21: No AutoML jobs found

Resolution

Enable network isolation on AutoML jobs so generated training containers cannot fetch unapproved dependencies or send data over unmanaged network paths.

Reference

Informational N/A
444455556666 us-east-1 OW-04
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance.

Resolution

Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically.

Reference

Informational N/A
444455556666 us-east-1 OW-09
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance.

Resolution

Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release.

Reference

Informational N/A
444455556666 us-east-1 OW-04
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-23: No InService endpoints found to monitor.

Resolution

Enable SageMaker Model Monitor drift detection for production endpoints so poisoning, data drift, and model-quality degradation are identified.

Reference

Medium Passed
444455556666 us-east-1 OW-09
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-23: No InService endpoints found to monitor.

Resolution

Configure data-quality and model-quality monitoring for SageMaker endpoints so degraded model behavior that can produce misinformation is detected.

Reference

Medium Passed
444455556666 us-east-1 OW-03
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain.

Reference

Informational N/A
444455556666 us-east-1 OW-04
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated.

Reference

Informational N/A
444455556666 Global OW-06
OWASP LLM06: AgentCore IAM Least Privilege
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check AC-02: No roles with overly permissive AgentCore access found

Resolution

Remove AmazonBedrockAgentCoreFullAccess (or equivalents) from identities that only need read/execute permissions.

Reference

High Passed
444455556666 us-east-1 OW-06
OWASP LLM06: AgentCore Resource-Based Policies
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check AC-10: No AgentCore resources found to check for resource-based policies

Resolution

Attach resource-based policies to AgentCore runtimes and gateways so caller identities are constrained.

Reference

Informational N/A
444455556666 us-east-1 OW-11
OWASP LLM07: System Prompt Embedded in Lambda Env Var
Details and remediation
Details

No Lambda function env vars in us-east-1 match the embedded-system-prompt heuristic (>= 200 chars containing prompt-shaped tokens).

Resolution

No action required.

Reference

Medium Passed
444455556666 us-east-1 OW-12
OWASP LLM07: System-Prompt-Disclosure Denied Topic
Details and remediation
Details

No Bedrock guardrails configured in us-east-1; nothing to inspect.

Resolution

No action required.

Reference

Informational N/A
444455556666 Global AC-02
AgentCore IAM Full Access Check
Details and remediation
Details

No roles with overly permissive AgentCore access found

Resolution

No action required

Reference

High Passed
444455556666 Global AC-03
AgentCore Stale Access
Details and remediation
Details

The following principals have not accessed AgentCore in 60+ days: role 'resco-aiml-security-23026-AgentCoreSecurityAssessme-2AEt2MTxg4AU' (91 days)

Resolution

Review and remove unused AgentCore permissions following least privilege principle

Reference

Medium Failed
444455556666 Global AC-03
AgentCore Unused Permissions
Details and remediation
Details

The following principals have AgentCore permissions but have never accessed the service: role 'AIMLSecurityMemberRole', role 'CloudSeerTrustedServiceRole'

Resolution

Review and remove unused AgentCore permissions following least privilege principle

Reference

Informational N/A
444455556666 Global AC-09
AgentCore Service-Linked Role Missing
Details and remediation
Details

Service-linked role 'AWSServiceRoleForBedrockAgentCoreNetwork' does not exist. VPC configuration for AgentCore Runtimes will fail without this role.

Resolution

The service-linked role is automatically created when you configure VPC for an AgentCore Runtime. Ensure IAM permissions allow service-linked role creation.

Reference

Medium Failed
444455556666 us-east-1 AC-01
AgentCore VPC Configuration Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 AC-04
AgentCore Observability Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 AC-05
AgentCore Encryption Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 AC-06
AgentCore Browser Tool Recording Check
Details and remediation
Details

No AgentCore Runtimes found to check browser tool configuration

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 AC-07
AgentCore Memory Configuration Check
Details and remediation
Details

No Memory resources found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 AC-13
AgentCore Gateway Configuration Check
Details and remediation
Details

No Gateway resources found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 AC-08
AgentCore VPC Endpoints Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 AC-10
AgentCore Resource-Based Policies Check
Details and remediation
Details

No AgentCore resources found to check for resource-based policies

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 AC-11
AgentCore Policy Engine Encryption Check
Details and remediation
Details

No Policy Engines found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 AC-12
AgentCore Gateway Encryption Check
Details and remediation
Details

No Gateways found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 AG-24
Agentic AI Gateway Inbound Authorization
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 AG-25
Agentic AI Gateway Tool Policy Enforcement
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 AG-26
Agentic AI Gateway Error Detail Exposure
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 AG-27
Agentic AI Gateway WAF Protection
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
444455556666 Global AG-16
Agentic AI AgentCore Least Privilege
Details and remediation
Details

Agentic AI security domain: Agent Identity & Access. Over-permissive AgentCore principals can let agents or operators bypass intended autonomy and tool boundaries. Source check AC-02: No roles with overly permissive AgentCore access found

Resolution

Replace full-access AgentCore permissions with least-privilege IAM policies scoped to required resources and actions.

Reference

High Passed
444455556666 Global AG-17
Agentic AI Stale AgentCore Access
Details and remediation
Details

Agentic AI security domain: Agent Identity & Access. Unused AgentCore permissions increase the blast radius of compromised principals. Source check AC-03: The following principals have not accessed AgentCore in 60+ days: role 'resco-aiml-security-23026-AgentCoreSecurityAssessme-2AEt2MTxg4AU' (91 days)

Resolution

Remove or restrict stale AgentCore permissions for principals that no longer need access.

Reference

Medium Failed
444455556666 Global AG-17
Agentic AI Stale AgentCore Access
Details and remediation
Details

Agentic AI security domain: Agent Identity & Access. Unused AgentCore permissions increase the blast radius of compromised principals. Source check AC-03: The following principals have AgentCore permissions but have never accessed the service: role 'AIMLSecurityMemberRole', role 'CloudSeerTrustedServiceRole'

Resolution

Remove or restrict stale AgentCore permissions for principals that no longer need access.

Reference

Informational N/A
444455556666 us-east-1 AG-15
Agentic AI Runtime Network Boundary
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found

Resolution

Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services.

Reference

Informational N/A
444455556666 us-east-1 AG-18
Agentic AI AgentCore Observability
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found

Resolution

Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported.

Reference

Informational N/A
444455556666 us-east-1 AG-19
Agentic AI Memory Data Protection
Details and remediation
Details

Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found

Resolution

Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions.

Reference

Informational N/A
444455556666 us-east-1 AG-20
Agentic AI Private AgentCore Connectivity
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found

Resolution

Create required VPC endpoints for AgentCore services and validate endpoint availability.

Reference

Informational N/A
444455556666 us-east-1 AG-21
Agentic AI Resource Policy Boundary
Details and remediation
Details

Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies

Resolution

Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources.

Reference

Informational N/A
444455556666 us-east-1 AG-22
Agentic AI Policy Engine Data Protection
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found

Resolution

Configure policy engines with customer-managed KMS keys where enhanced key control is required.

Reference

Informational N/A
444455556666 us-east-1 AG-23
Agentic AI Gateway Data Protection
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found

Resolution

Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required.

Reference

Informational N/A
444455556666 us-west-2 OW-01
OWASP LLM01: Model Invocation Logging
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging

Resolution

Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis.

Reference

Informational N/A
444455556666 us-west-2 OW-07
OWASP LLM07: Model Invocation Logging
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging

Resolution

Enable Bedrock model invocation logging so prompt-extraction attempts against the system prompt are auditable after the fact.

Reference

Informational N/A
444455556666 us-west-2 OW-07
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses.

Resolution

Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident.

Reference

Informational N/A
444455556666 us-west-2 OW-07
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-16: No Bedrock guardrails configured in this region

Resolution

Set guardrail contentPolicy.tier.tierName to STANDARD; Standard tier additionally detects prompt-leakage attacks.

Reference

Informational N/A
444455556666 us-west-2 OW-09
OWASP LLM09: Model Evaluation Jobs
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs

Resolution

Run Bedrock model evaluation jobs that include correctness and safety datasets.

Reference

Informational N/A
444455556666 us-west-2 OW-08
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: No Bedrock knowledge bases found in this region

Resolution

Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption.

Reference

Informational N/A
444455556666 us-west-2 OW-06
OWASP LLM06: Agent Action-Group Least Privilege
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-21: No Bedrock agents configured in this region

Resolution

Restrict agent action-group Lambda roles to only the specific actions and resources needed for each tool.

Reference

Informational N/A
444455556666 us-west-2 OW-10
OWASP LLM10: Service Quota Throttling Limits
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas

Resolution

Customise Bedrock TPM / RPM service quotas above the account default to establish an explicit consumption ceiling.

Reference

Informational N/A
444455556666 us-west-2 OW-01
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: No Bedrock guardrails configured in this region

Resolution

Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier.

Reference

Informational N/A
444455556666 us-west-2 OW-04
OWASP LLM04: RAG Evaluation Coverage
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: No Bedrock knowledge bases found in this region

Resolution

Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context.

Reference

Informational N/A
444455556666 us-west-2 OW-09
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-25: No Bedrock knowledge bases found in this region

Resolution

Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates.

Reference

Informational N/A
444455556666 us-west-2 OW-02
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check BR-26: No Bedrock guardrails configured in this region

Resolution

Configure guardrail sensitiveInformationPolicy with PII entities and regex patterns; set outputAction=ANONYMIZE or BLOCK.

Reference

Informational N/A
444455556666 us-west-2 OW-01
OWASP LLM01: Contextual Grounding Guardrail
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Enable Bedrock guardrail contextual grounding checks to reduce the surface for indirect prompt injection through retrieved context.

Reference

Informational N/A
444455556666 us-west-2 OW-04
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Enable contextual grounding guardrail filters so retrieved context that diverges from ground truth is filtered before reaching the model.

Reference

Informational N/A
444455556666 us-west-2 OW-09
OWASP LLM09: Contextual Grounding for Faithfulness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Set the contextual grounding filter threshold to at least 0.70 to reduce hallucinated responses.

Reference

Informational N/A
444455556666 us-west-2 OW-06
OWASP LLM06: Bedrock Agent Guardrail Association
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-28: No Bedrock agents configured in this region

Resolution

Attach an approved Bedrock guardrail to every Bedrock agent so autonomous actions are filtered consistently.

Reference

Informational N/A
444455556666 us-west-2 OW-06
OWASP LLM06: Agent Idle Session TTL
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-29: No Bedrock agents configured in this region

Resolution

Set idleSessionTTLInSeconds to a conservative value (e.g., <= 3600) so long-lived agent sessions cannot be reused.

Reference

Informational N/A
444455556666 us-west-2 OW-03
OWASP LLM03: Imported-Model KMS Provenance
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check BR-30: No imported custom Bedrock models found in this region

Resolution

Encrypt imported Bedrock models with a customer-managed KMS key to preserve provenance and access control across model artefacts.

Reference

Informational N/A
444455556666 us-west-2 OW-10
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms

Resolution

Create CloudWatch alarms on Bedrock InvocationThrottles, InputTokenCount, OutputTokenCount, and EstimatedTPMQuotaUsage.

Reference

Informational N/A
444455556666 us-west-2 OW-03
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check BR-33: No Lambda functions with Bedrock indicators were found in us-west-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads.

Resolution

Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain.

Reference

Informational N/A
444455556666 us-west-2 OW-03
OWASP LLM03: SageMaker Internet Exposure
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-01: No SageMaker notebook instances or domains found to check

Resolution

Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths.

Reference

Informational N/A
444455556666 us-west-2 OW-02
OWASP LLM02: SageMaker Data Encryption
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: No SageMaker resources found to check for data protection

Resolution

Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data.

Reference

Informational N/A
444455556666 us-west-2 OW-09
OWASP LLM09: SageMaker Clarify Evaluation
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-06: No SageMaker Clarify jobs found

Resolution

Use SageMaker Clarify to evaluate bias and explainability for models whose generated outputs can influence user decisions.

Reference

Informational N/A
444455556666 us-west-2 OW-04
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-07: No Model Monitor schedules found

Resolution

Configure active SageMaker Model Monitor schedules so data-quality and model-quality regressions caused by poisoned inputs or drift are detected.

Reference

Informational N/A
444455556666 us-west-2 OW-09
OWASP LLM09: SageMaker Model Monitor Coverage
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-07: No Model Monitor schedules found

Resolution

Configure SageMaker Model Monitor schedules for production models so quality regressions that can produce incorrect outputs are detected.

Reference

Informational N/A
444455556666 us-west-2 OW-03
OWASP LLM03: SageMaker Notebook VPC Deployment
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-10: No notebook instances found

Resolution

Deploy SageMaker notebook instances inside a VPC so package, data, and model artifact access can be controlled through private network paths.

Reference

Informational N/A
444455556666 us-west-2 OW-03
OWASP LLM03: SageMaker Model Network Isolation
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-11: No models found

Resolution

Enable network isolation on SageMaker models so inference containers cannot make unmanaged outbound calls that alter dependencies or exfiltrate model artifacts.

Reference

Informational N/A
444455556666 us-west-2 OW-10
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check SM-11: No models found

Resolution

Enable SageMaker model network isolation to prevent deployed model containers from making uncontrolled outbound calls that can amplify consumption or abuse downstream services.

Reference

Informational N/A
444455556666 us-west-2 OW-03
OWASP LLM03: SageMaker Container Repository Access
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-14: No models found or all use default Platform access

Resolution

Configure SageMaker models to pull container images from private ECR repositories through VPC repository access instead of platform or public registry paths.

Reference

Informational N/A
444455556666 us-west-2 OW-02
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-15: No feature groups with offline stores found

Resolution

Encrypt SageMaker Feature Store offline stores with customer-managed KMS keys so sensitive feature data is protected at rest.

Reference

Informational N/A
444455556666 us-west-2 OW-03
OWASP LLM03: SageMaker AutoML Network Isolation
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-21: No AutoML jobs found

Resolution

Enable network isolation on AutoML jobs so generated training containers cannot fetch unapproved dependencies or send data over unmanaged network paths.

Reference

Informational N/A
444455556666 us-west-2 OW-04
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance.

Resolution

Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically.

Reference

Informational N/A
444455556666 us-west-2 OW-09
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance.

Resolution

Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release.

Reference

Informational N/A
444455556666 us-west-2 OW-04
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-23: No InService endpoints found to monitor.

Resolution

Enable SageMaker Model Monitor drift detection for production endpoints so poisoning, data drift, and model-quality degradation are identified.

Reference

Medium Passed
444455556666 us-west-2 OW-09
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-23: No InService endpoints found to monitor.

Resolution

Configure data-quality and model-quality monitoring for SageMaker endpoints so degraded model behavior that can produce misinformation is detected.

Reference

Medium Passed
444455556666 us-west-2 OW-03
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain.

Reference

Informational N/A
444455556666 us-west-2 OW-04
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated.

Reference

Informational N/A
444455556666 us-west-2 OW-06
OWASP LLM06: AgentCore Resource-Based Policies
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check AC-10: No AgentCore resources found to check for resource-based policies

Resolution

Attach resource-based policies to AgentCore runtimes and gateways so caller identities are constrained.

Reference

Informational N/A
444455556666 us-west-2 OW-11
OWASP LLM07: System Prompt Embedded in Lambda Env Var
Details and remediation
Details

No Lambda functions found in us-west-2; nothing to inspect.

Resolution

No action required.

Reference

Informational N/A
444455556666 us-west-2 OW-12
OWASP LLM07: System-Prompt-Disclosure Denied Topic
Details and remediation
Details

No Bedrock guardrails configured in us-west-2; nothing to inspect.

Resolution

No action required.

Reference

Informational N/A
444455556666 us-east-2 OW-01
OWASP LLM01: Model Invocation Logging
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging

Resolution

Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis.

Reference

Informational N/A
444455556666 us-east-2 OW-07
OWASP LLM07: Model Invocation Logging
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging

Resolution

Enable Bedrock model invocation logging so prompt-extraction attempts against the system prompt are auditable after the fact.

Reference

Informational N/A
444455556666 us-east-2 OW-07
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses.

Resolution

Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident.

Reference

Informational N/A
444455556666 us-east-2 OW-07
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-16: No Bedrock guardrails configured in this region

Resolution

Set guardrail contentPolicy.tier.tierName to STANDARD; Standard tier additionally detects prompt-leakage attacks.

Reference

Informational N/A
444455556666 us-east-2 OW-09
OWASP LLM09: Model Evaluation Jobs
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs

Resolution

Run Bedrock model evaluation jobs that include correctness and safety datasets.

Reference

Informational N/A
444455556666 us-east-2 OW-08
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: No Bedrock knowledge bases found in this region

Resolution

Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption.

Reference

Informational N/A
444455556666 us-east-2 OW-06
OWASP LLM06: Agent Action-Group Least Privilege
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-21: No Bedrock agents configured in this region

Resolution

Restrict agent action-group Lambda roles to only the specific actions and resources needed for each tool.

Reference

Informational N/A
444455556666 us-east-2 OW-10
OWASP LLM10: Service Quota Throttling Limits
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas

Resolution

Customise Bedrock TPM / RPM service quotas above the account default to establish an explicit consumption ceiling.

Reference

Informational N/A
444455556666 us-east-2 OW-01
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: No Bedrock guardrails configured in this region

Resolution

Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier.

Reference

Informational N/A
444455556666 us-east-2 OW-04
OWASP LLM04: RAG Evaluation Coverage
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: No Bedrock knowledge bases found in this region

Resolution

Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context.

Reference

Informational N/A
444455556666 us-east-2 OW-09
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-25: No Bedrock knowledge bases found in this region

Resolution

Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates.

Reference

Informational N/A
444455556666 us-east-2 OW-02
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check BR-26: No Bedrock guardrails configured in this region

Resolution

Configure guardrail sensitiveInformationPolicy with PII entities and regex patterns; set outputAction=ANONYMIZE or BLOCK.

Reference

Informational N/A
444455556666 us-east-2 OW-01
OWASP LLM01: Contextual Grounding Guardrail
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Enable Bedrock guardrail contextual grounding checks to reduce the surface for indirect prompt injection through retrieved context.

Reference

Informational N/A
444455556666 us-east-2 OW-04
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Enable contextual grounding guardrail filters so retrieved context that diverges from ground truth is filtered before reaching the model.

Reference

Informational N/A
444455556666 us-east-2 OW-09
OWASP LLM09: Contextual Grounding for Faithfulness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Set the contextual grounding filter threshold to at least 0.70 to reduce hallucinated responses.

Reference

Informational N/A
444455556666 us-east-2 OW-06
OWASP LLM06: Bedrock Agent Guardrail Association
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-28: No Bedrock agents configured in this region

Resolution

Attach an approved Bedrock guardrail to every Bedrock agent so autonomous actions are filtered consistently.

Reference

Informational N/A
444455556666 us-east-2 OW-06
OWASP LLM06: Agent Idle Session TTL
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-29: No Bedrock agents configured in this region

Resolution

Set idleSessionTTLInSeconds to a conservative value (e.g., <= 3600) so long-lived agent sessions cannot be reused.

Reference

Informational N/A
444455556666 us-east-2 OW-03
OWASP LLM03: Imported-Model KMS Provenance
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check BR-30: No imported custom Bedrock models found in this region

Resolution

Encrypt imported Bedrock models with a customer-managed KMS key to preserve provenance and access control across model artefacts.

Reference

Informational N/A
444455556666 us-east-2 OW-10
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms

Resolution

Create CloudWatch alarms on Bedrock InvocationThrottles, InputTokenCount, OutputTokenCount, and EstimatedTPMQuotaUsage.

Reference

Informational N/A
444455556666 us-east-2 OW-03
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check BR-33: No Lambda functions with Bedrock indicators were found in us-east-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads.

Resolution

Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain.

Reference

Informational N/A
444455556666 us-east-2 OW-03
OWASP LLM03: SageMaker Internet Exposure
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-01: SageMaker notebook instance 'aws-neptune-Mybookstore-Bookstore-WS-Notebook' has direct internet access enabled

Resolution

Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths.

Reference

High Failed
444455556666 us-east-2 OW-02
OWASP LLM02: SageMaker Data Encryption
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: Notebook Instance 'aws-neptune-Mybookstore-Bookstore-WS-Notebook' - No KMS key configured

Resolution

Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data.

Reference

High Failed
444455556666 us-east-2 OW-09
OWASP LLM09: SageMaker Clarify Evaluation
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-06: No SageMaker Clarify jobs found

Resolution

Use SageMaker Clarify to evaluate bias and explainability for models whose generated outputs can influence user decisions.

Reference

Informational N/A
444455556666 us-east-2 OW-04
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-07: No Model Monitor schedules found

Resolution

Configure active SageMaker Model Monitor schedules so data-quality and model-quality regressions caused by poisoned inputs or drift are detected.

Reference

Informational N/A
444455556666 us-east-2 OW-09
OWASP LLM09: SageMaker Model Monitor Coverage
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-07: No Model Monitor schedules found

Resolution

Configure SageMaker Model Monitor schedules for production models so quality regressions that can produce incorrect outputs are detected.

Reference

Informational N/A
444455556666 us-east-2 OW-03
OWASP LLM03: SageMaker Notebook VPC Deployment
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-10: All 1 notebook instances are deployed in custom VPCs

Resolution

Deploy SageMaker notebook instances inside a VPC so package, data, and model artifact access can be controlled through private network paths.

Reference

High Passed
444455556666 us-east-2 OW-03
OWASP LLM03: SageMaker Model Network Isolation
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-11: No models found

Resolution

Enable network isolation on SageMaker models so inference containers cannot make unmanaged outbound calls that alter dependencies or exfiltrate model artifacts.

Reference

Informational N/A
444455556666 us-east-2 OW-10
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check SM-11: No models found

Resolution

Enable SageMaker model network isolation to prevent deployed model containers from making uncontrolled outbound calls that can amplify consumption or abuse downstream services.

Reference

Informational N/A
444455556666 us-east-2 OW-03
OWASP LLM03: SageMaker Container Repository Access
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-14: No models found or all use default Platform access

Resolution

Configure SageMaker models to pull container images from private ECR repositories through VPC repository access instead of platform or public registry paths.

Reference

Informational N/A
444455556666 us-east-2 OW-02
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-15: No feature groups with offline stores found

Resolution

Encrypt SageMaker Feature Store offline stores with customer-managed KMS keys so sensitive feature data is protected at rest.

Reference

Informational N/A
444455556666 us-east-2 OW-03
OWASP LLM03: SageMaker AutoML Network Isolation
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-21: No AutoML jobs found

Resolution

Enable network isolation on AutoML jobs so generated training containers cannot fetch unapproved dependencies or send data over unmanaged network paths.

Reference

Informational N/A
444455556666 us-east-2 OW-04
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance.

Resolution

Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically.

Reference

Informational N/A
444455556666 us-east-2 OW-09
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance.

Resolution

Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release.

Reference

Informational N/A
444455556666 us-east-2 OW-04
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-23: No InService endpoints found to monitor.

Resolution

Enable SageMaker Model Monitor drift detection for production endpoints so poisoning, data drift, and model-quality degradation are identified.

Reference

Medium Passed
444455556666 us-east-2 OW-09
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-23: No InService endpoints found to monitor.

Resolution

Configure data-quality and model-quality monitoring for SageMaker endpoints so degraded model behavior that can produce misinformation is detected.

Reference

Medium Passed
444455556666 us-east-2 OW-03
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain.

Reference

Informational N/A
444455556666 us-east-2 OW-04
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated.

Reference

Informational N/A
444455556666 us-east-2 OW-06
OWASP LLM06: AgentCore Resource-Based Policies
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check AC-10: No AgentCore resources found to check for resource-based policies

Resolution

Attach resource-based policies to AgentCore runtimes and gateways so caller identities are constrained.

Reference

Informational N/A
444455556666 us-east-2 OW-11
OWASP LLM07: System Prompt Embedded in Lambda Env Var
Details and remediation
Details

No Lambda function env vars in us-east-2 match the embedded-system-prompt heuristic (>= 200 chars containing prompt-shaped tokens).

Resolution

No action required.

Reference

Medium Passed
444455556666 us-east-2 OW-12
OWASP LLM07: System-Prompt-Disclosure Denied Topic
Details and remediation
Details

No Bedrock guardrails configured in us-east-2; nothing to inspect.

Resolution

No action required.

Reference

Informational N/A
444455556666 us-east-2 AC-01
AgentCore VPC Configuration Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 AC-04
AgentCore Observability Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 AC-05
AgentCore Encryption Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 AC-06
AgentCore Browser Tool Recording Check
Details and remediation
Details

No AgentCore Runtimes found to check browser tool configuration

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 AC-07
AgentCore Memory Configuration Check
Details and remediation
Details

No Memory resources found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 AC-13
AgentCore Gateway Configuration Check
Details and remediation
Details

No Gateway resources found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 AC-08
AgentCore VPC Endpoints Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 AC-10
AgentCore Resource-Based Policies Check
Details and remediation
Details

No AgentCore resources found to check for resource-based policies

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 AC-11
AgentCore Policy Engine Encryption Check
Details and remediation
Details

No Policy Engines found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 AC-12
AgentCore Gateway Encryption Check
Details and remediation
Details

No Gateways found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 AG-24
Agentic AI Gateway Inbound Authorization
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 AG-25
Agentic AI Gateway Tool Policy Enforcement
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 AG-26
Agentic AI Gateway Error Detail Exposure
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 AG-27
Agentic AI Gateway WAF Protection
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 AG-15
Agentic AI Runtime Network Boundary
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found

Resolution

Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services.

Reference

Informational N/A
444455556666 us-east-2 AG-18
Agentic AI AgentCore Observability
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found

Resolution

Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported.

Reference

Informational N/A
444455556666 us-east-2 AG-19
Agentic AI Memory Data Protection
Details and remediation
Details

Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found

Resolution

Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions.

Reference

Informational N/A
444455556666 us-east-2 AG-20
Agentic AI Private AgentCore Connectivity
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found

Resolution

Create required VPC endpoints for AgentCore services and validate endpoint availability.

Reference

Informational N/A
444455556666 us-east-2 AG-21
Agentic AI Resource Policy Boundary
Details and remediation
Details

Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies

Resolution

Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources.

Reference

Informational N/A
444455556666 us-east-2 AG-22
Agentic AI Policy Engine Data Protection
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found

Resolution

Configure policy engines with customer-managed KMS keys where enhanced key control is required.

Reference

Informational N/A
444455556666 us-east-2 AG-23
Agentic AI Gateway Data Protection
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found

Resolution

Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required.

Reference

Informational N/A
444455556666 Global BR-01
AmazonBedrockFullAccess role check
Details and remediation
Details

No roles found with AmazonBedrockFullAccess policy

Resolution

No action required

Reference

High Passed
444455556666 Global BR-03
Marketplace Subscription Access Check
Details and remediation
Details

No identities found with overly permissive marketplace subscription access

Resolution

No action required

Reference

Medium Passed
444455556666 us-east-1 BR-02
Amazon Bedrock private connectivity check
Details and remediation
Details

No regional Bedrock resources found to assess private connectivity

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 BR-04
Bedrock Model Invocation Logging Check
Details and remediation
Details

No regional Bedrock resources found to monitor with invocation logging

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 BR-05
Bedrock Guardrails Check
Details and remediation
Details

No regional Bedrock resources found to protect with guardrails

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 BR-06
Bedrock CloudTrail Logging Check
Details and remediation
Details

No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 BR-07
Bedrock Prompt Management Check
Details and remediation
Details

Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses.

Resolution

Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates

Reference

Informational N/A
444455556666 us-east-1 BR-08
Bedrock Agent IAM Roles Check
Details and remediation
Details

No Bedrock agents found in the account

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 BR-09
Bedrock Knowledge Base Encryption Check
Details and remediation
Details

No Knowledge Bases found in the account

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 BR-10
Bedrock Guardrail IAM Enforcement Check
Details and remediation
Details

No guardrails configured - IAM enforcement check not applicable

Resolution

Configure Bedrock Guardrails first, then enforce their use via IAM policies

Reference

Informational N/A
444455556666 us-east-1 BR-11
Bedrock Custom Model Encryption Check
Details and remediation
Details

No custom/fine-tuned models found in the account

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 BR-12
Bedrock Invocation Log Encryption Check
Details and remediation
Details

Model invocation logging to S3 is not configured

Resolution

If logging is enabled to CloudWatch only, ensure CloudWatch log group uses CMK encryption

Reference

Informational N/A
444455556666 us-east-1 BR-13
Bedrock Flows Guardrails Check
Details and remediation
Details

No Bedrock Flows found in the account

Resolution

No action required

Reference

Informational N/A
444455556666 Global BR-15
Cross-Account Guardrails Enforcement Check
Details and remediation
Details

Check must run in AWS Organizations management account to evaluate organizational policies

Resolution

Run assessment in management account to check cross-account guardrails enforcement

Reference

Medium N/A
444455556666 us-east-1 BR-16
Guardrail Tier Validation Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create Bedrock guardrails with Standard tier for enhanced content filtering and protection

Reference

Medium N/A
444455556666 us-east-1 BR-17
Custom Model Customer-Managed KMS Encryption Check
Details and remediation
Details

No custom (fine-tuned) Bedrock models found in this region

Resolution

When creating custom models, specify a customer-managed KMS key for encryption to maintain control over encryption keys

Reference

High N/A
444455556666 us-east-1 BR-18
Model Evaluation Implementation Check
Details and remediation
Details

No regional Bedrock resources found to assess with model evaluation jobs

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 BR-19
Prompt Flow Validation Check
Details and remediation
Details

No Bedrock prompt flows configured in this region

Resolution

When creating prompt flows, use the ValidateFlowDefinition API to validate flow definitions before deployment

Reference

Medium N/A
444455556666 us-east-1 BR-20
Knowledge Base Customer-Managed KMS Encryption Check
Details and remediation
Details

No Bedrock knowledge bases found in this region

Resolution

When creating knowledge bases, specify customer-managed KMS keys for both vector store and data source encryption

Reference

High N/A
444455556666 us-east-1 BR-21
Agent Action Group IAM Least Privilege Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents with action groups, ensure Lambda execution roles follow least privilege principles

Reference

High N/A
444455556666 us-east-1 BR-22
Model Invocation Throttling Limits Check
Details and remediation
Details

No regional Bedrock resources found to assess model invocation throttling quotas

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 BR-23
Guardrail Content Filter Coverage Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with all content filters enabled (hate, insults, sexual, violence) with appropriate thresholds

Reference

High N/A
444455556666 us-east-1 BR-24
Automated Reasoning Policy Implementation Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with Automated Reasoning policies for formal verification of model responses

Reference

Medium N/A
444455556666 us-east-1 BR-25
RAG Evaluation Jobs Check
Details and remediation
Details

No Bedrock knowledge bases found in this region

Resolution

When implementing RAG applications, configure evaluation jobs to assess context relevance, response correctness, and prevent hallucinations

Reference

Low N/A
444455556666 us-east-1 BR-26
Guardrail Sensitive Information Filter Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with sensitive-information filters (PII entities and/or regex patterns) to detect and redact sensitive data in prompts and model responses

Reference

High N/A
444455556666 us-east-1 BR-27
Guardrail Contextual Grounding Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with contextual grounding checks to detect hallucinations (ungrounded responses) and irrelevant answers, especially for RAG applications

Reference

Medium N/A
444455556666 us-east-1 BR-28
Agent Guardrail Association Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents, associate a Bedrock guardrail so agent inputs and responses are filtered for harmful content, PII, and denied topics

Reference

High N/A
444455556666 us-east-1 BR-29
Agent Idle Session TTL Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents, set a conservative idleSessionTTLInSeconds to limit how long an idle session remains resumable

Reference

Low N/A
444455556666 us-east-1 BR-30
Imported Model Customer-Managed KMS Encryption Check
Details and remediation
Details

No imported custom Bedrock models found in this region

Resolution

When importing models, specify a customer-managed KMS key for encryption to maintain control over encryption keys

Reference

High N/A
444455556666 us-east-1 BR-31
Batch Inference Output Encryption Check
Details and remediation
Details

No Bedrock batch inference (model invocation) jobs found in this region

Resolution

When creating batch inference jobs, set outputDataConfig.s3OutputDataConfig.s3EncryptionKeyId to a customer-managed KMS key to encrypt the job output

Reference

Medium N/A
444455556666 us-east-1 BR-32
Bedrock CloudWatch Alarm Check
Details and remediation
Details

No regional Bedrock resources found to monitor with CloudWatch alarms

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 BR-33
Amazon Inspector Lambda Code Scanning Check
Details and remediation
Details

Amazon Inspector Lambda standard scanning and Lambda code scanning are both ENABLED in us-east-1. Detected 2 Lambda function(s) with Bedrock indicators: aiml-security-aiml-security-444455556666-BedrockAssessment, resco-aiml-BedrockAssessment.

Resolution

No action required.

Reference

Medium Passed
444455556666 us-east-1 AG-07
Agentic AI Model Invocation Logging
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging

Resolution

Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements.

Reference

Informational N/A
444455556666 us-east-1 AG-08
Agentic AI API Audit Trail
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage

Resolution

Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured.

Reference

Informational N/A
444455556666 Global AG-09
Agentic AI Guardrail Enforcement Boundary
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Organization-level guardrail enforcement helps prevent agents from bypassing required safety controls across accounts. Source check BR-15: Check must run in AWS Organizations management account to evaluate organizational policies

Resolution

Use IAM and organization controls to require approved guardrails for model and agent invocations where supported.

Reference

Informational N/A
444455556666 us-east-1 AG-10
Agentic AI Adversarial Evaluation Coverage
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs

Resolution

Configure model or application evaluations that include adversarial, safety, and security-relevant test cases.

Reference

Informational N/A
444455556666 us-east-1 AG-11
Agentic AI Prompt Flow Validation
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region

Resolution

Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions.

Reference

Informational N/A
444455556666 us-east-1 AG-06
Agentic AI Tool Execution Least Privilege
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region

Resolution

Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required.

Reference

Informational N/A
444455556666 us-east-1 AG-12
Agentic AI Invocation Abuse Controls
Details and remediation
Details

Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas

Resolution

Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns.

Reference

Informational N/A
444455556666 us-east-1 AG-02
Agentic AI Harmful Content Guardrail Coverage
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: No Bedrock guardrails configured in this region

Resolution

Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads.

Reference

Informational N/A
444455556666 us-east-1 AG-04
Agentic AI Automated Reasoning Guardrails
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: No Bedrock guardrails configured in this region

Resolution

Configure automated reasoning policies on guardrails where formal response validation is required.

Reference

Informational N/A
444455556666 us-east-1 AG-03
Agentic AI Sensitive Information Protection
Details and remediation
Details

Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: No Bedrock guardrails configured in this region

Resolution

Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns.

Reference

Informational N/A
444455556666 us-east-1 AG-05
Agentic AI Grounding Controls
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows.

Reference

Informational N/A
444455556666 us-east-1 AG-01
Agentic AI Agent Guardrail Association
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region

Resolution

Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating.

Reference

Informational N/A
444455556666 us-east-1 AG-13
Agentic AI Session Boundary
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region

Resolution

Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements.

Reference

Informational N/A
444455556666 us-east-1 AG-14
Agentic AI Operational Abuse Alarms
Details and remediation
Details

Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms

Resolution

Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available.

Reference

Informational N/A
444455556666 eu-west-1 BR-02
Amazon Bedrock private connectivity check
Details and remediation
Details

No regional Bedrock resources found to assess private connectivity

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 BR-04
Bedrock Model Invocation Logging Check
Details and remediation
Details

No regional Bedrock resources found to monitor with invocation logging

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 BR-05
Bedrock Guardrails Check
Details and remediation
Details

No regional Bedrock resources found to protect with guardrails

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 BR-06
Bedrock CloudTrail Logging Check
Details and remediation
Details

No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 BR-07
Bedrock Prompt Management Check
Details and remediation
Details

Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses.

Resolution

Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates

Reference

Informational N/A
444455556666 eu-west-1 BR-08
Bedrock Agent IAM Roles Check
Details and remediation
Details

No Bedrock agents found in the account

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 BR-09
Bedrock Knowledge Base Encryption Check
Details and remediation
Details

No Knowledge Bases found in the account

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 BR-10
Bedrock Guardrail IAM Enforcement Check
Details and remediation
Details

No guardrails configured - IAM enforcement check not applicable

Resolution

Configure Bedrock Guardrails first, then enforce their use via IAM policies

Reference

Informational N/A
444455556666 eu-west-1 BR-11
Bedrock Custom Model Encryption Check
Details and remediation
Details

No custom/fine-tuned models found in the account

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 BR-12
Bedrock Invocation Log Encryption Check
Details and remediation
Details

Model invocation logging to S3 is not configured

Resolution

If logging is enabled to CloudWatch only, ensure CloudWatch log group uses CMK encryption

Reference

Informational N/A
444455556666 eu-west-1 BR-13
Bedrock Flows Guardrails Check
Details and remediation
Details

No Bedrock Flows found in the account

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 BR-16
Guardrail Tier Validation Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create Bedrock guardrails with Standard tier for enhanced content filtering and protection

Reference

Medium N/A
444455556666 eu-west-1 BR-17
Custom Model Customer-Managed KMS Encryption Check
Details and remediation
Details

No custom (fine-tuned) Bedrock models found in this region

Resolution

When creating custom models, specify a customer-managed KMS key for encryption to maintain control over encryption keys

Reference

High N/A
444455556666 eu-west-1 BR-18
Model Evaluation Implementation Check
Details and remediation
Details

No regional Bedrock resources found to assess with model evaluation jobs

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 BR-19
Prompt Flow Validation Check
Details and remediation
Details

No Bedrock prompt flows configured in this region

Resolution

When creating prompt flows, use the ValidateFlowDefinition API to validate flow definitions before deployment

Reference

Medium N/A
444455556666 eu-west-1 BR-20
Knowledge Base Customer-Managed KMS Encryption Check
Details and remediation
Details

No Bedrock knowledge bases found in this region

Resolution

When creating knowledge bases, specify customer-managed KMS keys for both vector store and data source encryption

Reference

High N/A
444455556666 eu-west-1 BR-21
Agent Action Group IAM Least Privilege Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents with action groups, ensure Lambda execution roles follow least privilege principles

Reference

High N/A
444455556666 eu-west-1 BR-22
Model Invocation Throttling Limits Check
Details and remediation
Details

No regional Bedrock resources found to assess model invocation throttling quotas

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 BR-23
Guardrail Content Filter Coverage Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with all content filters enabled (hate, insults, sexual, violence) with appropriate thresholds

Reference

High N/A
444455556666 eu-west-1 BR-24
Automated Reasoning Policy Implementation Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with Automated Reasoning policies for formal verification of model responses

Reference

Medium N/A
444455556666 eu-west-1 BR-25
RAG Evaluation Jobs Check
Details and remediation
Details

No Bedrock knowledge bases found in this region

Resolution

When implementing RAG applications, configure evaluation jobs to assess context relevance, response correctness, and prevent hallucinations

Reference

Low N/A
444455556666 eu-west-1 BR-26
Guardrail Sensitive Information Filter Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with sensitive-information filters (PII entities and/or regex patterns) to detect and redact sensitive data in prompts and model responses

Reference

High N/A
444455556666 eu-west-1 BR-27
Guardrail Contextual Grounding Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with contextual grounding checks to detect hallucinations (ungrounded responses) and irrelevant answers, especially for RAG applications

Reference

Medium N/A
444455556666 eu-west-1 BR-28
Agent Guardrail Association Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents, associate a Bedrock guardrail so agent inputs and responses are filtered for harmful content, PII, and denied topics

Reference

High N/A
444455556666 eu-west-1 BR-29
Agent Idle Session TTL Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents, set a conservative idleSessionTTLInSeconds to limit how long an idle session remains resumable

Reference

Low N/A
444455556666 eu-west-1 BR-30
Imported Model Customer-Managed KMS Encryption Check
Details and remediation
Details

Unable to check Imported model encryption check: An error occurred (AccessDeniedException) when calling the ListImportedModels operation: Your account is not authorized to invoke this API operation.

Resolution

Amazon Bedrock Custom Model Import is not enabled or available for this account in this region. No IAM change is required; the check applies only once model import is in use.

Reference

Low N/A
444455556666 eu-west-1 BR-31
Batch Inference Output Encryption Check
Details and remediation
Details

No Bedrock batch inference (model invocation) jobs found in this region

Resolution

When creating batch inference jobs, set outputDataConfig.s3OutputDataConfig.s3EncryptionKeyId to a customer-managed KMS key to encrypt the job output

Reference

Medium N/A
444455556666 eu-west-1 BR-32
Bedrock CloudWatch Alarm Check
Details and remediation
Details

No regional Bedrock resources found to monitor with CloudWatch alarms

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 BR-33
Amazon Inspector Lambda Code Scanning Check
Details and remediation
Details

No Lambda functions with Bedrock indicators were found in eu-west-1; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads.

Resolution

No action required. If Bedrock-calling Lambda functions exist, ensure their function name, ARN, description, handler, role, or environment variables contain a Bedrock identifier that the assessment can detect, or evaluate Inspector coverage manually.

Reference

Informational N/A
444455556666 eu-west-1 AG-07
Agentic AI Model Invocation Logging
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging

Resolution

Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements.

Reference

Informational N/A
444455556666 eu-west-1 AG-08
Agentic AI API Audit Trail
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage

Resolution

Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured.

Reference

Informational N/A
444455556666 eu-west-1 AG-10
Agentic AI Adversarial Evaluation Coverage
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs

Resolution

Configure model or application evaluations that include adversarial, safety, and security-relevant test cases.

Reference

Informational N/A
444455556666 eu-west-1 AG-11
Agentic AI Prompt Flow Validation
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region

Resolution

Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions.

Reference

Informational N/A
444455556666 eu-west-1 AG-06
Agentic AI Tool Execution Least Privilege
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region

Resolution

Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required.

Reference

Informational N/A
444455556666 eu-west-1 AG-12
Agentic AI Invocation Abuse Controls
Details and remediation
Details

Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas

Resolution

Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns.

Reference

Informational N/A
444455556666 eu-west-1 AG-02
Agentic AI Harmful Content Guardrail Coverage
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: No Bedrock guardrails configured in this region

Resolution

Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads.

Reference

Informational N/A
444455556666 eu-west-1 AG-04
Agentic AI Automated Reasoning Guardrails
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: No Bedrock guardrails configured in this region

Resolution

Configure automated reasoning policies on guardrails where formal response validation is required.

Reference

Informational N/A
444455556666 eu-west-1 AG-03
Agentic AI Sensitive Information Protection
Details and remediation
Details

Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: No Bedrock guardrails configured in this region

Resolution

Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns.

Reference

Informational N/A
444455556666 eu-west-1 AG-05
Agentic AI Grounding Controls
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows.

Reference

Informational N/A
444455556666 eu-west-1 AG-01
Agentic AI Agent Guardrail Association
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region

Resolution

Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating.

Reference

Informational N/A
444455556666 eu-west-1 AG-13
Agentic AI Session Boundary
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region

Resolution

Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements.

Reference

Informational N/A
444455556666 eu-west-1 AG-14
Agentic AI Operational Abuse Alarms
Details and remediation
Details

Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms

Resolution

Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available.

Reference

Informational N/A
444455556666 us-west-2 BR-02
Amazon Bedrock private connectivity check
Details and remediation
Details

No regional Bedrock resources found to assess private connectivity

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 BR-04
Bedrock Model Invocation Logging Check
Details and remediation
Details

No regional Bedrock resources found to monitor with invocation logging

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 BR-05
Bedrock Guardrails Check
Details and remediation
Details

No regional Bedrock resources found to protect with guardrails

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 BR-06
Bedrock CloudTrail Logging Check
Details and remediation
Details

No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 BR-07
Bedrock Prompt Management Check
Details and remediation
Details

Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses.

Resolution

Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates

Reference

Informational N/A
444455556666 us-west-2 BR-08
Bedrock Agent IAM Roles Check
Details and remediation
Details

No Bedrock agents found in the account

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 BR-09
Bedrock Knowledge Base Encryption Check
Details and remediation
Details

No Knowledge Bases found in the account

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 BR-10
Bedrock Guardrail IAM Enforcement Check
Details and remediation
Details

No guardrails configured - IAM enforcement check not applicable

Resolution

Configure Bedrock Guardrails first, then enforce their use via IAM policies

Reference

Informational N/A
444455556666 us-west-2 BR-11
Bedrock Custom Model Encryption Check
Details and remediation
Details

No custom/fine-tuned models found in the account

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 BR-12
Bedrock Invocation Log Encryption Check
Details and remediation
Details

Model invocation logging to S3 is not configured

Resolution

If logging is enabled to CloudWatch only, ensure CloudWatch log group uses CMK encryption

Reference

Informational N/A
444455556666 us-west-2 BR-13
Bedrock Flows Guardrails Check
Details and remediation
Details

No Bedrock Flows found in the account

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 BR-16
Guardrail Tier Validation Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create Bedrock guardrails with Standard tier for enhanced content filtering and protection

Reference

Medium N/A
444455556666 us-west-2 BR-17
Custom Model Customer-Managed KMS Encryption Check
Details and remediation
Details

No custom (fine-tuned) Bedrock models found in this region

Resolution

When creating custom models, specify a customer-managed KMS key for encryption to maintain control over encryption keys

Reference

High N/A
444455556666 us-west-2 BR-18
Model Evaluation Implementation Check
Details and remediation
Details

No regional Bedrock resources found to assess with model evaluation jobs

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 BR-19
Prompt Flow Validation Check
Details and remediation
Details

No Bedrock prompt flows configured in this region

Resolution

When creating prompt flows, use the ValidateFlowDefinition API to validate flow definitions before deployment

Reference

Medium N/A
444455556666 us-west-2 BR-20
Knowledge Base Customer-Managed KMS Encryption Check
Details and remediation
Details

No Bedrock knowledge bases found in this region

Resolution

When creating knowledge bases, specify customer-managed KMS keys for both vector store and data source encryption

Reference

High N/A
444455556666 us-west-2 BR-21
Agent Action Group IAM Least Privilege Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents with action groups, ensure Lambda execution roles follow least privilege principles

Reference

High N/A
444455556666 us-west-2 BR-22
Model Invocation Throttling Limits Check
Details and remediation
Details

No regional Bedrock resources found to assess model invocation throttling quotas

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 BR-23
Guardrail Content Filter Coverage Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with all content filters enabled (hate, insults, sexual, violence) with appropriate thresholds

Reference

High N/A
444455556666 us-west-2 BR-24
Automated Reasoning Policy Implementation Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with Automated Reasoning policies for formal verification of model responses

Reference

Medium N/A
444455556666 us-west-2 BR-25
RAG Evaluation Jobs Check
Details and remediation
Details

No Bedrock knowledge bases found in this region

Resolution

When implementing RAG applications, configure evaluation jobs to assess context relevance, response correctness, and prevent hallucinations

Reference

Low N/A
444455556666 us-west-2 BR-26
Guardrail Sensitive Information Filter Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with sensitive-information filters (PII entities and/or regex patterns) to detect and redact sensitive data in prompts and model responses

Reference

High N/A
444455556666 us-west-2 BR-27
Guardrail Contextual Grounding Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with contextual grounding checks to detect hallucinations (ungrounded responses) and irrelevant answers, especially for RAG applications

Reference

Medium N/A
444455556666 us-west-2 BR-28
Agent Guardrail Association Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents, associate a Bedrock guardrail so agent inputs and responses are filtered for harmful content, PII, and denied topics

Reference

High N/A
444455556666 us-west-2 BR-29
Agent Idle Session TTL Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents, set a conservative idleSessionTTLInSeconds to limit how long an idle session remains resumable

Reference

Low N/A
444455556666 us-west-2 BR-30
Imported Model Customer-Managed KMS Encryption Check
Details and remediation
Details

No imported custom Bedrock models found in this region

Resolution

When importing models, specify a customer-managed KMS key for encryption to maintain control over encryption keys

Reference

High N/A
444455556666 us-west-2 BR-31
Batch Inference Output Encryption Check
Details and remediation
Details

No Bedrock batch inference (model invocation) jobs found in this region

Resolution

When creating batch inference jobs, set outputDataConfig.s3OutputDataConfig.s3EncryptionKeyId to a customer-managed KMS key to encrypt the job output

Reference

Medium N/A
444455556666 us-west-2 BR-32
Bedrock CloudWatch Alarm Check
Details and remediation
Details

No regional Bedrock resources found to monitor with CloudWatch alarms

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 BR-33
Amazon Inspector Lambda Code Scanning Check
Details and remediation
Details

No Lambda functions with Bedrock indicators were found in us-west-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads.

Resolution

No action required. If Bedrock-calling Lambda functions exist, ensure their function name, ARN, description, handler, role, or environment variables contain a Bedrock identifier that the assessment can detect, or evaluate Inspector coverage manually.

Reference

Informational N/A
444455556666 us-west-2 AG-07
Agentic AI Model Invocation Logging
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging

Resolution

Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements.

Reference

Informational N/A
444455556666 us-west-2 AG-08
Agentic AI API Audit Trail
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage

Resolution

Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured.

Reference

Informational N/A
444455556666 us-west-2 AG-10
Agentic AI Adversarial Evaluation Coverage
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs

Resolution

Configure model or application evaluations that include adversarial, safety, and security-relevant test cases.

Reference

Informational N/A
444455556666 us-west-2 AG-11
Agentic AI Prompt Flow Validation
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region

Resolution

Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions.

Reference

Informational N/A
444455556666 us-west-2 AG-06
Agentic AI Tool Execution Least Privilege
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region

Resolution

Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required.

Reference

Informational N/A
444455556666 us-west-2 AG-12
Agentic AI Invocation Abuse Controls
Details and remediation
Details

Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas

Resolution

Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns.

Reference

Informational N/A
444455556666 us-west-2 AG-02
Agentic AI Harmful Content Guardrail Coverage
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: No Bedrock guardrails configured in this region

Resolution

Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads.

Reference

Informational N/A
444455556666 us-west-2 AG-04
Agentic AI Automated Reasoning Guardrails
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: No Bedrock guardrails configured in this region

Resolution

Configure automated reasoning policies on guardrails where formal response validation is required.

Reference

Informational N/A
444455556666 us-west-2 AG-03
Agentic AI Sensitive Information Protection
Details and remediation
Details

Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: No Bedrock guardrails configured in this region

Resolution

Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns.

Reference

Informational N/A
444455556666 us-west-2 AG-05
Agentic AI Grounding Controls
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows.

Reference

Informational N/A
444455556666 us-west-2 AG-01
Agentic AI Agent Guardrail Association
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region

Resolution

Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating.

Reference

Informational N/A
444455556666 us-west-2 AG-13
Agentic AI Session Boundary
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region

Resolution

Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements.

Reference

Informational N/A
444455556666 us-west-2 AG-14
Agentic AI Operational Abuse Alarms
Details and remediation
Details

Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms

Resolution

Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available.

Reference

Informational N/A
444455556666 us-east-1 FS-00
FinServ Regional Scope Not Applicable
Details and remediation
Details

No regional Bedrock, AgentCore, or SageMaker resources were found in us-east-1; FinServ GenAI risk checks were not applied to this region.

Resolution

No action required unless GenAI workloads are expected in this region.

Reference

Informational N/A
444455556666 us-east-2 FS-00
FinServ Regional Scope Not Applicable
Details and remediation
Details

No regional Bedrock, AgentCore, or SageMaker resources were found in us-east-2; FinServ GenAI risk checks were not applied to this region.

Resolution

No action required unless GenAI workloads are expected in this region.

Reference

Informational N/A
444455556666 us-west-2 FS-00
FinServ Regional Scope Not Applicable
Details and remediation
Details

No regional Bedrock, AgentCore, or SageMaker resources were found in us-west-2; FinServ GenAI risk checks were not applied to this region.

Resolution

No action required unless GenAI workloads are expected in this region.

Reference

Informational N/A
444455556666 eu-west-1 FS-00
FinServ Regional Scope Not Applicable
Details and remediation
Details

No regional Bedrock, AgentCore, or SageMaker resources were found in eu-west-1; FinServ GenAI risk checks were not applied to this region.

Resolution

No action required unless GenAI workloads are expected in this region.

Reference

Informational N/A
444455556666 eu-west-1 OW-01
OWASP LLM01: Model Invocation Logging
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging

Resolution

Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis.

Reference

Informational N/A
444455556666 eu-west-1 OW-07
OWASP LLM07: Model Invocation Logging
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging

Resolution

Enable Bedrock model invocation logging so prompt-extraction attempts against the system prompt are auditable after the fact.

Reference

Informational N/A
444455556666 eu-west-1 OW-07
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses.

Resolution

Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident.

Reference

Informational N/A
444455556666 eu-west-1 OW-07
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-16: No Bedrock guardrails configured in this region

Resolution

Set guardrail contentPolicy.tier.tierName to STANDARD; Standard tier additionally detects prompt-leakage attacks.

Reference

Informational N/A
444455556666 eu-west-1 OW-09
OWASP LLM09: Model Evaluation Jobs
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs

Resolution

Run Bedrock model evaluation jobs that include correctness and safety datasets.

Reference

Informational N/A
444455556666 eu-west-1 OW-08
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: No Bedrock knowledge bases found in this region

Resolution

Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption.

Reference

Informational N/A
444455556666 eu-west-1 OW-06
OWASP LLM06: Agent Action-Group Least Privilege
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-21: No Bedrock agents configured in this region

Resolution

Restrict agent action-group Lambda roles to only the specific actions and resources needed for each tool.

Reference

Informational N/A
444455556666 eu-west-1 OW-10
OWASP LLM10: Service Quota Throttling Limits
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas

Resolution

Customise Bedrock TPM / RPM service quotas above the account default to establish an explicit consumption ceiling.

Reference

Informational N/A
444455556666 eu-west-1 OW-01
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: No Bedrock guardrails configured in this region

Resolution

Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier.

Reference

Informational N/A
444455556666 eu-west-1 OW-04
OWASP LLM04: RAG Evaluation Coverage
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: No Bedrock knowledge bases found in this region

Resolution

Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context.

Reference

Informational N/A
444455556666 eu-west-1 OW-09
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-25: No Bedrock knowledge bases found in this region

Resolution

Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates.

Reference

Informational N/A
444455556666 eu-west-1 OW-02
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check BR-26: No Bedrock guardrails configured in this region

Resolution

Configure guardrail sensitiveInformationPolicy with PII entities and regex patterns; set outputAction=ANONYMIZE or BLOCK.

Reference

Informational N/A
444455556666 eu-west-1 OW-01
OWASP LLM01: Contextual Grounding Guardrail
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Enable Bedrock guardrail contextual grounding checks to reduce the surface for indirect prompt injection through retrieved context.

Reference

Informational N/A
444455556666 eu-west-1 OW-04
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Enable contextual grounding guardrail filters so retrieved context that diverges from ground truth is filtered before reaching the model.

Reference

Informational N/A
444455556666 eu-west-1 OW-09
OWASP LLM09: Contextual Grounding for Faithfulness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Set the contextual grounding filter threshold to at least 0.70 to reduce hallucinated responses.

Reference

Informational N/A
444455556666 eu-west-1 OW-06
OWASP LLM06: Bedrock Agent Guardrail Association
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-28: No Bedrock agents configured in this region

Resolution

Attach an approved Bedrock guardrail to every Bedrock agent so autonomous actions are filtered consistently.

Reference

Informational N/A
444455556666 eu-west-1 OW-06
OWASP LLM06: Agent Idle Session TTL
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-29: No Bedrock agents configured in this region

Resolution

Set idleSessionTTLInSeconds to a conservative value (e.g., <= 3600) so long-lived agent sessions cannot be reused.

Reference

Informational N/A
444455556666 eu-west-1 OW-03
OWASP LLM03: Imported-Model KMS Provenance
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check BR-30: Unable to check Imported model encryption check: An error occurred (AccessDeniedException) when calling the ListImportedModels operation: Your account is not authorized to invoke this API operation.

Resolution

Encrypt imported Bedrock models with a customer-managed KMS key to preserve provenance and access control across model artefacts.

Reference

Informational N/A
444455556666 eu-west-1 OW-10
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms

Resolution

Create CloudWatch alarms on Bedrock InvocationThrottles, InputTokenCount, OutputTokenCount, and EstimatedTPMQuotaUsage.

Reference

Informational N/A
444455556666 eu-west-1 OW-03
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check BR-33: No Lambda functions with Bedrock indicators were found in eu-west-1; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads.

Resolution

Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain.

Reference

Informational N/A
444455556666 eu-west-1 OW-03
OWASP LLM03: SageMaker Internet Exposure
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-01: No SageMaker notebook instances or domains found to check

Resolution

Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths.

Reference

Informational N/A
444455556666 eu-west-1 OW-02
OWASP LLM02: SageMaker Data Encryption
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: No SageMaker resources found to check for data protection

Resolution

Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data.

Reference

Informational N/A
444455556666 eu-west-1 OW-09
OWASP LLM09: SageMaker Clarify Evaluation
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-06: No SageMaker Clarify jobs found

Resolution

Use SageMaker Clarify to evaluate bias and explainability for models whose generated outputs can influence user decisions.

Reference

Informational N/A
444455556666 eu-west-1 OW-04
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-07: No Model Monitor schedules found

Resolution

Configure active SageMaker Model Monitor schedules so data-quality and model-quality regressions caused by poisoned inputs or drift are detected.

Reference

Informational N/A
444455556666 eu-west-1 OW-09
OWASP LLM09: SageMaker Model Monitor Coverage
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-07: No Model Monitor schedules found

Resolution

Configure SageMaker Model Monitor schedules for production models so quality regressions that can produce incorrect outputs are detected.

Reference

Informational N/A
444455556666 eu-west-1 OW-03
OWASP LLM03: SageMaker Notebook VPC Deployment
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-10: No notebook instances found

Resolution

Deploy SageMaker notebook instances inside a VPC so package, data, and model artifact access can be controlled through private network paths.

Reference

Informational N/A
444455556666 eu-west-1 OW-03
OWASP LLM03: SageMaker Model Network Isolation
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-11: No models found

Resolution

Enable network isolation on SageMaker models so inference containers cannot make unmanaged outbound calls that alter dependencies or exfiltrate model artifacts.

Reference

Informational N/A
444455556666 eu-west-1 OW-10
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check SM-11: No models found

Resolution

Enable SageMaker model network isolation to prevent deployed model containers from making uncontrolled outbound calls that can amplify consumption or abuse downstream services.

Reference

Informational N/A
444455556666 eu-west-1 OW-03
OWASP LLM03: SageMaker Container Repository Access
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-14: No models found or all use default Platform access

Resolution

Configure SageMaker models to pull container images from private ECR repositories through VPC repository access instead of platform or public registry paths.

Reference

Informational N/A
444455556666 eu-west-1 OW-02
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-15: No feature groups with offline stores found

Resolution

Encrypt SageMaker Feature Store offline stores with customer-managed KMS keys so sensitive feature data is protected at rest.

Reference

Informational N/A
444455556666 eu-west-1 OW-03
OWASP LLM03: SageMaker AutoML Network Isolation
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-21: No AutoML jobs found

Resolution

Enable network isolation on AutoML jobs so generated training containers cannot fetch unapproved dependencies or send data over unmanaged network paths.

Reference

Informational N/A
444455556666 eu-west-1 OW-04
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance.

Resolution

Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically.

Reference

Informational N/A
444455556666 eu-west-1 OW-09
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance.

Resolution

Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release.

Reference

Informational N/A
444455556666 eu-west-1 OW-04
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-23: No InService endpoints found to monitor.

Resolution

Enable SageMaker Model Monitor drift detection for production endpoints so poisoning, data drift, and model-quality degradation are identified.

Reference

Medium Passed
444455556666 eu-west-1 OW-09
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-23: No InService endpoints found to monitor.

Resolution

Configure data-quality and model-quality monitoring for SageMaker endpoints so degraded model behavior that can produce misinformation is detected.

Reference

Medium Passed
444455556666 eu-west-1 OW-03
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain.

Reference

Informational N/A
444455556666 eu-west-1 OW-04
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated.

Reference

Informational N/A
444455556666 eu-west-1 OW-06
OWASP LLM06: AgentCore Resource-Based Policies
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check AC-10: No AgentCore resources found to check for resource-based policies

Resolution

Attach resource-based policies to AgentCore runtimes and gateways so caller identities are constrained.

Reference

Informational N/A
444455556666 eu-west-1 OW-11
OWASP LLM07: System Prompt Embedded in Lambda Env Var
Details and remediation
Details

No Lambda functions found in eu-west-1; nothing to inspect.

Resolution

No action required.

Reference

Informational N/A
444455556666 eu-west-1 OW-12
OWASP LLM07: System-Prompt-Disclosure Denied Topic
Details and remediation
Details

No Bedrock guardrails configured in eu-west-1; nothing to inspect.

Resolution

No action required.

Reference

Informational N/A
444455556666 eu-west-1 SM-01
SageMaker Internet Access Check
Details and remediation
Details

No SageMaker notebook instances or domains found to check

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 SM-02
SageMaker SSO Configuration Check
Details and remediation
Details

No SageMaker domains found, or all domains use SSO with IAM Identity Center configured

Resolution

No action required

Reference

Medium Passed
444455556666 eu-west-1 SM-03
Data Protection Check
Details and remediation
Details

No SageMaker resources found to check for data protection

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 SM-04
GuardDuty Enabled
Details and remediation
Details

Amazon GuardDuty is properly enabled and monitoring for security threats in SageMaker workloads.

Resolution

No action required

Reference

Medium Passed
444455556666 eu-west-1 SM-05
SageMaker Model Registry Issue
Details and remediation
Details

No model package groups found

Resolution

Implement model versioning using SageMaker Model Registry to track model lineage, approve model versions, and manage model deployment

Reference

Informational N/A
444455556666 eu-west-1 SM-05
SageMaker Feature Store Issue
Details and remediation
Details

No feature groups found

Resolution

Utilize SageMaker Feature Store to create, share, and manage features for machine learning development and production

Reference

Informational N/A
444455556666 eu-west-1 SM-05
SageMaker Pipelines Issue
Details and remediation
Details

No ML pipelines found

Resolution

Implement SageMaker Pipelines to automate and manage ML workflows, including data preparation, training, and model deployment

Reference

Informational N/A
444455556666 eu-west-1 SM-06
SageMaker Clarify No Clarify Usage
Details and remediation
Details

No SageMaker Clarify jobs found

Resolution

Implement SageMaker Clarify for model explainability and bias detection

Reference

Informational N/A
444455556666 eu-west-1 SM-07
SageMaker Model Monitor No Model Monitoring
Details and remediation
Details

No Model Monitor schedules found

Resolution

Configure comprehensive model monitoring schedules

Reference

Informational N/A
444455556666 eu-west-1 SM-08
Model Registry Registry Not Used
Details and remediation
Details

Model Registry is not being utilized

Resolution

Implement proper model versioning and approval workflows

Reference

Informational N/A
444455556666 eu-west-1 SM-09
SageMaker Notebook Root Access Check
Details and remediation
Details

No notebook instances found

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 SM-10
SageMaker Notebook VPC Deployment Check
Details and remediation
Details

No notebook instances found

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 SM-11
SageMaker Model Network Isolation Check
Details and remediation
Details

No models found

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 SM-12
SageMaker Endpoint Instance Count Check
Details and remediation
Details

No InService endpoints found

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 SM-13
SageMaker Monitoring Network Isolation Check
Details and remediation
Details

No monitoring schedules found

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 SM-14
SageMaker Model Repository Access Check
Details and remediation
Details

No models found or all use default Platform access

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 SM-15
SageMaker Feature Store Encryption Check
Details and remediation
Details

No feature groups with offline stores found

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 SM-16
SageMaker Data Quality Job Encryption Check
Details and remediation
Details

No data quality job definitions found

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 SM-17
SageMaker Processing Job Encryption Check
Details and remediation
Details

No processing jobs found

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 SM-18
SageMaker Transform Job Encryption Check
Details and remediation
Details

No transform jobs found

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 SM-19
SageMaker Hyperparameter Tuning Job Encryption Check
Details and remediation
Details

No hyperparameter tuning jobs found

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 SM-20
SageMaker Compilation Job Encryption Check
Details and remediation
Details

No compilation jobs found

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 SM-21
SageMaker AutoML Job Network Isolation Check
Details and remediation
Details

No AutoML jobs found

Resolution

No action required

Reference

Informational N/A
444455556666 eu-west-1 SM-22
Model Approval Workflow Check
Details and remediation
Details

No model package groups found. Model Registry is not being used for model governance.

Resolution

Implement Model Registry to track model versions and enforce approval workflows before production deployment.

Reference

Informational N/A
444455556666 eu-west-1 SM-23
Model Drift Detection Check
Details and remediation
Details

No InService endpoints found to monitor.

Resolution

No action required

Reference

Medium Passed
444455556666 eu-west-1 SM-24
A/B Testing and Shadow Deployment Check
Details and remediation
Details

No InService endpoints found.

Resolution

No action required

Reference

Low Passed
444455556666 eu-west-1 SM-25
ML Lineage Tracking - Experiments Not Used
Details and remediation
Details

No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Implement SageMaker Experiments to track ML training runs, hyperparameters, metrics, and model artifacts. This enables reproducibility and auditability.

Reference

Informational N/A
444455556666 us-west-2 SM-01
SageMaker Internet Access Check
Details and remediation
Details

No SageMaker notebook instances or domains found to check

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 SM-02
SageMaker SSO Configuration Check
Details and remediation
Details

No SageMaker domains found, or all domains use SSO with IAM Identity Center configured

Resolution

No action required

Reference

Medium Passed
444455556666 us-west-2 SM-03
Data Protection Check
Details and remediation
Details

No SageMaker resources found to check for data protection

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 SM-04
GuardDuty Enabled
Details and remediation
Details

Amazon GuardDuty is properly enabled and monitoring for security threats in SageMaker workloads.

Resolution

No action required

Reference

Medium Passed
444455556666 us-west-2 SM-05
SageMaker Model Registry Issue
Details and remediation
Details

No model package groups found

Resolution

Implement model versioning using SageMaker Model Registry to track model lineage, approve model versions, and manage model deployment

Reference

Informational N/A
444455556666 us-west-2 SM-05
SageMaker Feature Store Issue
Details and remediation
Details

No feature groups found

Resolution

Utilize SageMaker Feature Store to create, share, and manage features for machine learning development and production

Reference

Informational N/A
444455556666 us-west-2 SM-05
SageMaker Pipelines Issue
Details and remediation
Details

No ML pipelines found

Resolution

Implement SageMaker Pipelines to automate and manage ML workflows, including data preparation, training, and model deployment

Reference

Informational N/A
444455556666 us-west-2 SM-06
SageMaker Clarify No Clarify Usage
Details and remediation
Details

No SageMaker Clarify jobs found

Resolution

Implement SageMaker Clarify for model explainability and bias detection

Reference

Informational N/A
444455556666 us-west-2 SM-07
SageMaker Model Monitor No Model Monitoring
Details and remediation
Details

No Model Monitor schedules found

Resolution

Configure comprehensive model monitoring schedules

Reference

Informational N/A
444455556666 us-west-2 SM-08
Model Registry Registry Not Used
Details and remediation
Details

Model Registry is not being utilized

Resolution

Implement proper model versioning and approval workflows

Reference

Informational N/A
444455556666 us-west-2 SM-09
SageMaker Notebook Root Access Check
Details and remediation
Details

No notebook instances found

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 SM-10
SageMaker Notebook VPC Deployment Check
Details and remediation
Details

No notebook instances found

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 SM-11
SageMaker Model Network Isolation Check
Details and remediation
Details

No models found

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 SM-12
SageMaker Endpoint Instance Count Check
Details and remediation
Details

No InService endpoints found

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 SM-13
SageMaker Monitoring Network Isolation Check
Details and remediation
Details

No monitoring schedules found

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 SM-14
SageMaker Model Repository Access Check
Details and remediation
Details

No models found or all use default Platform access

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 SM-15
SageMaker Feature Store Encryption Check
Details and remediation
Details

No feature groups with offline stores found

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 SM-16
SageMaker Data Quality Job Encryption Check
Details and remediation
Details

No data quality job definitions found

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 SM-17
SageMaker Processing Job Encryption Check
Details and remediation
Details

No processing jobs found

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 SM-18
SageMaker Transform Job Encryption Check
Details and remediation
Details

No transform jobs found

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 SM-19
SageMaker Hyperparameter Tuning Job Encryption Check
Details and remediation
Details

No hyperparameter tuning jobs found

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 SM-20
SageMaker Compilation Job Encryption Check
Details and remediation
Details

No compilation jobs found

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 SM-21
SageMaker AutoML Job Network Isolation Check
Details and remediation
Details

No AutoML jobs found

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 SM-22
Model Approval Workflow Check
Details and remediation
Details

No model package groups found. Model Registry is not being used for model governance.

Resolution

Implement Model Registry to track model versions and enforce approval workflows before production deployment.

Reference

Informational N/A
444455556666 us-west-2 SM-23
Model Drift Detection Check
Details and remediation
Details

No InService endpoints found to monitor.

Resolution

No action required

Reference

Medium Passed
444455556666 us-west-2 SM-24
A/B Testing and Shadow Deployment Check
Details and remediation
Details

No InService endpoints found.

Resolution

No action required

Reference

Low Passed
444455556666 us-west-2 SM-25
ML Lineage Tracking - Experiments Not Used
Details and remediation
Details

No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Implement SageMaker Experiments to track ML training runs, hyperparameters, metrics, and model artifacts. This enables reproducibility and auditability.

Reference

Informational N/A
444455556666 us-east-2 SM-01
Direct Internet Access Enabled
Details and remediation
Details

SageMaker notebook instance 'aws-neptune-Mybookstore-Bookstore-WS-Notebook' has direct internet access enabled

Resolution

Configure the notebook instance to use VPC connectivity and disable direct internet access

Reference

High Failed
444455556666 us-east-2 SM-02
SageMaker SSO Configuration Check
Details and remediation
Details

No SageMaker domains found, or all domains use SSO with IAM Identity Center configured

Resolution

No action required

Reference

Medium Passed
444455556666 us-east-2 SM-03
Missing Encryption Configuration
Details and remediation
Details

Notebook Instance 'aws-neptune-Mybookstore-Bookstore-WS-Notebook' - No KMS key configured

Resolution

Configure encryption using AWS KMS customer managed keys for enhanced security

Reference

High Failed
444455556666 us-east-2 SM-04
GuardDuty Enabled
Details and remediation
Details

Amazon GuardDuty is properly enabled and monitoring for security threats in SageMaker workloads.

Resolution

No action required

Reference

Medium Passed
444455556666 us-east-2 SM-05
SageMaker Model Registry Issue
Details and remediation
Details

No model package groups found

Resolution

Implement model versioning using SageMaker Model Registry to track model lineage, approve model versions, and manage model deployment

Reference

Informational N/A
444455556666 us-east-2 SM-05
SageMaker Feature Store Issue
Details and remediation
Details

No feature groups found

Resolution

Utilize SageMaker Feature Store to create, share, and manage features for machine learning development and production

Reference

Informational N/A
444455556666 us-east-2 SM-05
SageMaker Pipelines Issue
Details and remediation
Details

No ML pipelines found

Resolution

Implement SageMaker Pipelines to automate and manage ML workflows, including data preparation, training, and model deployment

Reference

Informational N/A
444455556666 us-east-2 SM-06
SageMaker Clarify No Clarify Usage
Details and remediation
Details

No SageMaker Clarify jobs found

Resolution

Implement SageMaker Clarify for model explainability and bias detection

Reference

Informational N/A
444455556666 us-east-2 SM-07
SageMaker Model Monitor No Model Monitoring
Details and remediation
Details

No Model Monitor schedules found

Resolution

Configure comprehensive model monitoring schedules

Reference

Informational N/A
444455556666 us-east-2 SM-08
Model Registry Registry Not Used
Details and remediation
Details

Model Registry is not being utilized

Resolution

Implement proper model versioning and approval workflows

Reference

Informational N/A
444455556666 us-east-2 SM-09
SageMaker Notebook Root Access Enabled
Details and remediation
Details

Notebook instance 'aws-neptune-Mybookstore-Bookstore-WS-Notebook' has root access enabled. Root access allows users to install arbitrary software, modify system configurations, and potentially escalate privileges.

Resolution

Disable root access by updating the notebook instance with RootAccess=Disabled. Note: Lifecycle configurations will still run with root access.

Reference

High Failed
444455556666 us-east-2 SM-10
SageMaker Notebook VPC Deployment Check
Details and remediation
Details

All 1 notebook instances are deployed in custom VPCs

Resolution

No action required

Reference

High Passed
444455556666 us-east-2 SM-11
SageMaker Model Network Isolation Check
Details and remediation
Details

No models found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 SM-12
SageMaker Endpoint Instance Count Check
Details and remediation
Details

No InService endpoints found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 SM-13
SageMaker Monitoring Network Isolation Check
Details and remediation
Details

No monitoring schedules found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 SM-14
SageMaker Model Repository Access Check
Details and remediation
Details

No models found or all use default Platform access

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 SM-15
SageMaker Feature Store Encryption Check
Details and remediation
Details

No feature groups with offline stores found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 SM-16
SageMaker Data Quality Job Encryption Check
Details and remediation
Details

No data quality job definitions found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 SM-17
SageMaker Processing Job Encryption Check
Details and remediation
Details

No processing jobs found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 SM-18
SageMaker Transform Job Encryption Check
Details and remediation
Details

No transform jobs found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 SM-19
SageMaker Hyperparameter Tuning Job Encryption Check
Details and remediation
Details

No hyperparameter tuning jobs found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 SM-20
SageMaker Compilation Job Encryption Check
Details and remediation
Details

No compilation jobs found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 SM-21
SageMaker AutoML Job Network Isolation Check
Details and remediation
Details

No AutoML jobs found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 SM-22
Model Approval Workflow Check
Details and remediation
Details

No model package groups found. Model Registry is not being used for model governance.

Resolution

Implement Model Registry to track model versions and enforce approval workflows before production deployment.

Reference

Informational N/A
444455556666 us-east-2 SM-23
Model Drift Detection Check
Details and remediation
Details

No InService endpoints found to monitor.

Resolution

No action required

Reference

Medium Passed
444455556666 us-east-2 SM-24
A/B Testing and Shadow Deployment Check
Details and remediation
Details

No InService endpoints found.

Resolution

No action required

Reference

Low Passed
444455556666 us-east-2 SM-25
ML Lineage Tracking - Experiments Not Used
Details and remediation
Details

No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Implement SageMaker Experiments to track ML training runs, hyperparameters, metrics, and model artifacts. This enables reproducibility and auditability.

Reference

Informational N/A
444455556666 us-west-2 AC-01
AgentCore VPC Configuration Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 AC-04
AgentCore Observability Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 AC-05
AgentCore Encryption Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 AC-06
AgentCore Browser Tool Recording Check
Details and remediation
Details

No AgentCore Runtimes found to check browser tool configuration

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 AC-07
AgentCore Memory Configuration Check
Details and remediation
Details

No Memory resources found

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 AC-13
AgentCore Gateway Configuration Check
Details and remediation
Details

No Gateway resources found

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 AC-08
AgentCore VPC Endpoints Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 AC-10
AgentCore Resource-Based Policies Check
Details and remediation
Details

No AgentCore resources found to check for resource-based policies

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 AC-11
AgentCore Policy Engine Encryption Check
Details and remediation
Details

No Policy Engines found

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 AC-12
AgentCore Gateway Encryption Check
Details and remediation
Details

No Gateways found

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 AG-24
Agentic AI Gateway Inbound Authorization
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 AG-25
Agentic AI Gateway Tool Policy Enforcement
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 AG-26
Agentic AI Gateway Error Detail Exposure
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 AG-27
Agentic AI Gateway WAF Protection
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
444455556666 us-west-2 AG-15
Agentic AI Runtime Network Boundary
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found

Resolution

Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services.

Reference

Informational N/A
444455556666 us-west-2 AG-18
Agentic AI AgentCore Observability
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found

Resolution

Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported.

Reference

Informational N/A
444455556666 us-west-2 AG-19
Agentic AI Memory Data Protection
Details and remediation
Details

Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found

Resolution

Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions.

Reference

Informational N/A
444455556666 us-west-2 AG-20
Agentic AI Private AgentCore Connectivity
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found

Resolution

Create required VPC endpoints for AgentCore services and validate endpoint availability.

Reference

Informational N/A
444455556666 us-west-2 AG-21
Agentic AI Resource Policy Boundary
Details and remediation
Details

Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies

Resolution

Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources.

Reference

Informational N/A
444455556666 us-west-2 AG-22
Agentic AI Policy Engine Data Protection
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found

Resolution

Configure policy engines with customer-managed KMS keys where enhanced key control is required.

Reference

Informational N/A
444455556666 us-west-2 AG-23
Agentic AI Gateway Data Protection
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found

Resolution

Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required.

Reference

Informational N/A
444455556666 Global SM-02
SageMaker IAM Permissions Check
Details and remediation
Details

No issues found with IAM permissions and no stale access detected

Resolution

No action required

Reference

High Passed
444455556666 us-east-1 SM-01
SageMaker Internet Access Check
Details and remediation
Details

No SageMaker notebook instances or domains found to check

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 SM-02
SageMaker SSO Configuration Check
Details and remediation
Details

No SageMaker domains found, or all domains use SSO with IAM Identity Center configured

Resolution

No action required

Reference

Medium Passed
444455556666 us-east-1 SM-03
Data Protection Check
Details and remediation
Details

No SageMaker resources found to check for data protection

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 SM-04
GuardDuty Enabled
Details and remediation
Details

Amazon GuardDuty is properly enabled and monitoring for security threats in SageMaker workloads.

Resolution

No action required

Reference

Medium Passed
444455556666 us-east-1 SM-05
SageMaker Model Registry Issue
Details and remediation
Details

No model package groups found

Resolution

Implement model versioning using SageMaker Model Registry to track model lineage, approve model versions, and manage model deployment

Reference

Informational N/A
444455556666 us-east-1 SM-05
SageMaker Feature Store Issue
Details and remediation
Details

No feature groups found

Resolution

Utilize SageMaker Feature Store to create, share, and manage features for machine learning development and production

Reference

Informational N/A
444455556666 us-east-1 SM-05
SageMaker Pipelines Issue
Details and remediation
Details

No ML pipelines found

Resolution

Implement SageMaker Pipelines to automate and manage ML workflows, including data preparation, training, and model deployment

Reference

Informational N/A
444455556666 us-east-1 SM-06
SageMaker Clarify No Clarify Usage
Details and remediation
Details

No SageMaker Clarify jobs found

Resolution

Implement SageMaker Clarify for model explainability and bias detection

Reference

Informational N/A
444455556666 us-east-1 SM-07
SageMaker Model Monitor No Model Monitoring
Details and remediation
Details

No Model Monitor schedules found

Resolution

Configure comprehensive model monitoring schedules

Reference

Informational N/A
444455556666 us-east-1 SM-08
Model Registry Registry Not Used
Details and remediation
Details

Model Registry is not being utilized

Resolution

Implement proper model versioning and approval workflows

Reference

Informational N/A
444455556666 us-east-1 SM-09
SageMaker Notebook Root Access Check
Details and remediation
Details

No notebook instances found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 SM-10
SageMaker Notebook VPC Deployment Check
Details and remediation
Details

No notebook instances found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 SM-11
SageMaker Model Network Isolation Check
Details and remediation
Details

No models found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 SM-12
SageMaker Endpoint Instance Count Check
Details and remediation
Details

No InService endpoints found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 SM-13
SageMaker Monitoring Network Isolation Check
Details and remediation
Details

No monitoring schedules found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 SM-14
SageMaker Model Repository Access Check
Details and remediation
Details

No models found or all use default Platform access

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 SM-15
SageMaker Feature Store Encryption Check
Details and remediation
Details

No feature groups with offline stores found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 SM-16
SageMaker Data Quality Job Encryption Check
Details and remediation
Details

No data quality job definitions found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 SM-17
SageMaker Processing Job Encryption Check
Details and remediation
Details

No processing jobs found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 SM-18
SageMaker Transform Job Encryption Check
Details and remediation
Details

No transform jobs found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 SM-19
SageMaker Hyperparameter Tuning Job Encryption Check
Details and remediation
Details

No hyperparameter tuning jobs found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 SM-20
SageMaker Compilation Job Encryption Check
Details and remediation
Details

No compilation jobs found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 SM-21
SageMaker AutoML Job Network Isolation Check
Details and remediation
Details

No AutoML jobs found

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-1 SM-22
Model Approval Workflow Check
Details and remediation
Details

No model package groups found. Model Registry is not being used for model governance.

Resolution

Implement Model Registry to track model versions and enforce approval workflows before production deployment.

Reference

Informational N/A
444455556666 us-east-1 SM-23
Model Drift Detection Check
Details and remediation
Details

No InService endpoints found to monitor.

Resolution

No action required

Reference

Medium Passed
444455556666 us-east-1 SM-24
A/B Testing and Shadow Deployment Check
Details and remediation
Details

No InService endpoints found.

Resolution

No action required

Reference

Low Passed
444455556666 us-east-1 SM-25
ML Lineage Tracking - Experiments Not Used
Details and remediation
Details

No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Implement SageMaker Experiments to track ML training runs, hyperparameters, metrics, and model artifacts. This enables reproducibility and auditability.

Reference

Informational N/A
444455556666 us-east-2 BR-02
Amazon Bedrock private connectivity check
Details and remediation
Details

No regional Bedrock resources found to assess private connectivity

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 BR-04
Bedrock Model Invocation Logging Check
Details and remediation
Details

No regional Bedrock resources found to monitor with invocation logging

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 BR-05
Bedrock Guardrails Check
Details and remediation
Details

No regional Bedrock resources found to protect with guardrails

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 BR-06
Bedrock CloudTrail Logging Check
Details and remediation
Details

No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 BR-07
Bedrock Prompt Management Check
Details and remediation
Details

Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses.

Resolution

Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates

Reference

Informational N/A
444455556666 us-east-2 BR-08
Bedrock Agent IAM Roles Check
Details and remediation
Details

No Bedrock agents found in the account

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 BR-09
Bedrock Knowledge Base Encryption Check
Details and remediation
Details

No Knowledge Bases found in the account

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 BR-10
Bedrock Guardrail IAM Enforcement Check
Details and remediation
Details

No guardrails configured - IAM enforcement check not applicable

Resolution

Configure Bedrock Guardrails first, then enforce their use via IAM policies

Reference

Informational N/A
444455556666 us-east-2 BR-11
Bedrock Custom Model Encryption Check
Details and remediation
Details

Custom model API not available in us-east-2

Resolution

Verify permissions to access Bedrock custom models

Reference

Low N/A
444455556666 us-east-2 BR-12
Bedrock Invocation Log Encryption Check
Details and remediation
Details

Model invocation logging to S3 is not configured

Resolution

If logging is enabled to CloudWatch only, ensure CloudWatch log group uses CMK encryption

Reference

Informational N/A
444455556666 us-east-2 BR-13
Bedrock Flows Guardrails Check
Details and remediation
Details

No Bedrock Flows found in the account

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 BR-16
Guardrail Tier Validation Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create Bedrock guardrails with Standard tier for enhanced content filtering and protection

Reference

Medium N/A
444455556666 us-east-2 BR-17
Custom Model Customer-Managed KMS Encryption Check
Details and remediation
Details

Could not assess this check in us-east-2. Assessment error: UnknownOperationException.

Resolution

No action required on the assessed workload. Resolve the assessment prerequisite or permission issue and rerun the assessment.

Reference

Informational N/A
444455556666 us-east-2 BR-18
Model Evaluation Implementation Check
Details and remediation
Details

No regional Bedrock resources found to assess with model evaluation jobs

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 BR-19
Prompt Flow Validation Check
Details and remediation
Details

No Bedrock prompt flows configured in this region

Resolution

When creating prompt flows, use the ValidateFlowDefinition API to validate flow definitions before deployment

Reference

Medium N/A
444455556666 us-east-2 BR-20
Knowledge Base Customer-Managed KMS Encryption Check
Details and remediation
Details

No Bedrock knowledge bases found in this region

Resolution

When creating knowledge bases, specify customer-managed KMS keys for both vector store and data source encryption

Reference

High N/A
444455556666 us-east-2 BR-21
Agent Action Group IAM Least Privilege Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents with action groups, ensure Lambda execution roles follow least privilege principles

Reference

High N/A
444455556666 us-east-2 BR-22
Model Invocation Throttling Limits Check
Details and remediation
Details

No regional Bedrock resources found to assess model invocation throttling quotas

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 BR-23
Guardrail Content Filter Coverage Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with all content filters enabled (hate, insults, sexual, violence) with appropriate thresholds

Reference

High N/A
444455556666 us-east-2 BR-24
Automated Reasoning Policy Implementation Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with Automated Reasoning policies for formal verification of model responses

Reference

Medium N/A
444455556666 us-east-2 BR-25
RAG Evaluation Jobs Check
Details and remediation
Details

No Bedrock knowledge bases found in this region

Resolution

When implementing RAG applications, configure evaluation jobs to assess context relevance, response correctness, and prevent hallucinations

Reference

Low N/A
444455556666 us-east-2 BR-26
Guardrail Sensitive Information Filter Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with sensitive-information filters (PII entities and/or regex patterns) to detect and redact sensitive data in prompts and model responses

Reference

High N/A
444455556666 us-east-2 BR-27
Guardrail Contextual Grounding Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with contextual grounding checks to detect hallucinations (ungrounded responses) and irrelevant answers, especially for RAG applications

Reference

Medium N/A
444455556666 us-east-2 BR-28
Agent Guardrail Association Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents, associate a Bedrock guardrail so agent inputs and responses are filtered for harmful content, PII, and denied topics

Reference

High N/A
444455556666 us-east-2 BR-29
Agent Idle Session TTL Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents, set a conservative idleSessionTTLInSeconds to limit how long an idle session remains resumable

Reference

Low N/A
444455556666 us-east-2 BR-30
Imported Model Customer-Managed KMS Encryption Check
Details and remediation
Details

No imported custom Bedrock models found in this region

Resolution

When importing models, specify a customer-managed KMS key for encryption to maintain control over encryption keys

Reference

High N/A
444455556666 us-east-2 BR-31
Batch Inference Output Encryption Check
Details and remediation
Details

No Bedrock batch inference (model invocation) jobs found in this region

Resolution

When creating batch inference jobs, set outputDataConfig.s3OutputDataConfig.s3EncryptionKeyId to a customer-managed KMS key to encrypt the job output

Reference

Medium N/A
444455556666 us-east-2 BR-32
Bedrock CloudWatch Alarm Check
Details and remediation
Details

No regional Bedrock resources found to monitor with CloudWatch alarms

Resolution

No action required

Reference

Informational N/A
444455556666 us-east-2 BR-33
Amazon Inspector Lambda Code Scanning Check
Details and remediation
Details

No Lambda functions with Bedrock indicators were found in us-east-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads.

Resolution

No action required. If Bedrock-calling Lambda functions exist, ensure their function name, ARN, description, handler, role, or environment variables contain a Bedrock identifier that the assessment can detect, or evaluate Inspector coverage manually.

Reference

Informational N/A
444455556666 us-east-2 AG-07
Agentic AI Model Invocation Logging
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging

Resolution

Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements.

Reference

Informational N/A
444455556666 us-east-2 AG-08
Agentic AI API Audit Trail
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage

Resolution

Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured.

Reference

Informational N/A
444455556666 us-east-2 AG-10
Agentic AI Adversarial Evaluation Coverage
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs

Resolution

Configure model or application evaluations that include adversarial, safety, and security-relevant test cases.

Reference

Informational N/A
444455556666 us-east-2 AG-11
Agentic AI Prompt Flow Validation
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region

Resolution

Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions.

Reference

Informational N/A
444455556666 us-east-2 AG-06
Agentic AI Tool Execution Least Privilege
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region

Resolution

Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required.

Reference

Informational N/A
444455556666 us-east-2 AG-12
Agentic AI Invocation Abuse Controls
Details and remediation
Details

Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas

Resolution

Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns.

Reference

Informational N/A
444455556666 us-east-2 AG-02
Agentic AI Harmful Content Guardrail Coverage
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: No Bedrock guardrails configured in this region

Resolution

Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads.

Reference

Informational N/A
444455556666 us-east-2 AG-04
Agentic AI Automated Reasoning Guardrails
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: No Bedrock guardrails configured in this region

Resolution

Configure automated reasoning policies on guardrails where formal response validation is required.

Reference

Informational N/A
444455556666 us-east-2 AG-03
Agentic AI Sensitive Information Protection
Details and remediation
Details

Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: No Bedrock guardrails configured in this region

Resolution

Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns.

Reference

Informational N/A
444455556666 us-east-2 AG-05
Agentic AI Grounding Controls
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows.

Reference

Informational N/A
444455556666 us-east-2 AG-01
Agentic AI Agent Guardrail Association
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region

Resolution

Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating.

Reference

Informational N/A
444455556666 us-east-2 AG-13
Agentic AI Session Boundary
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region

Resolution

Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements.

Reference

Informational N/A
444455556666 us-east-2 AG-14
Agentic AI Operational Abuse Alarms
Details and remediation
Details

Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms

Resolution

Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available.

Reference

Informational N/A
777788889999 eu-west-1 AC-01
AgentCore VPC Configuration Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 AC-04
AgentCore Observability Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 AC-05
AgentCore Encryption Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 AC-06
AgentCore Browser Tool Recording Check
Details and remediation
Details

No AgentCore Runtimes found to check browser tool configuration

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 AC-07
AgentCore Memory Configuration Check
Details and remediation
Details

No Memory resources found

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 AC-13
AgentCore Gateway Configuration Check
Details and remediation
Details

No Gateway resources found

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 AC-08
AgentCore VPC Endpoints Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 AC-10
AgentCore Resource-Based Policies Check
Details and remediation
Details

No AgentCore resources found to check for resource-based policies

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 AC-11
AgentCore Policy Engine Encryption Check
Details and remediation
Details

No Policy Engines found

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 AC-12
AgentCore Gateway Encryption Check
Details and remediation
Details

No Gateways found

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 AG-24
Agentic AI Gateway Inbound Authorization
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 AG-25
Agentic AI Gateway Tool Policy Enforcement
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 AG-26
Agentic AI Gateway Error Detail Exposure
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 AG-27
Agentic AI Gateway WAF Protection
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 AG-15
Agentic AI Runtime Network Boundary
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found

Resolution

Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services.

Reference

Informational N/A
777788889999 eu-west-1 AG-18
Agentic AI AgentCore Observability
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found

Resolution

Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported.

Reference

Informational N/A
777788889999 eu-west-1 AG-19
Agentic AI Memory Data Protection
Details and remediation
Details

Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found

Resolution

Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions.

Reference

Informational N/A
777788889999 eu-west-1 AG-20
Agentic AI Private AgentCore Connectivity
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found

Resolution

Create required VPC endpoints for AgentCore services and validate endpoint availability.

Reference

Informational N/A
777788889999 eu-west-1 AG-21
Agentic AI Resource Policy Boundary
Details and remediation
Details

Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies

Resolution

Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources.

Reference

Informational N/A
777788889999 eu-west-1 AG-22
Agentic AI Policy Engine Data Protection
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found

Resolution

Configure policy engines with customer-managed KMS keys where enhanced key control is required.

Reference

Informational N/A
777788889999 eu-west-1 AG-23
Agentic AI Gateway Data Protection
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found

Resolution

Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required.

Reference

Informational N/A
777788889999 us-east-1 OW-01
OWASP LLM01: Model Invocation Logging
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: Model invocation logging is not enabled. This limits your ability to track and audit model usage.

Resolution

Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis.

Reference

Medium Failed
777788889999 us-east-1 OW-07
OWASP LLM07: Model Invocation Logging
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-04: Model invocation logging is not enabled. This limits your ability to track and audit model usage.

Resolution

Enable Bedrock model invocation logging so prompt-extraction attempts against the system prompt are auditable after the fact.

Reference

Medium Failed
777788889999 us-east-1 OW-07
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management is being used with 1 prompts

Resolution

Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident.

Reference

Low Passed
777788889999 us-east-1 OW-07
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-16: Guardrail 'aiml-sec-test-test-guardrail' (ID: jkceg2tprvwh) could not be assessed because GetGuardrail returned AccessDeniedException.

Resolution

Set guardrail contentPolicy.tier.tierName to STANDARD; Standard tier additionally detects prompt-leakage attacks.

Reference

Informational N/A
777788889999 us-east-1 OW-09
OWASP LLM09: Model Evaluation Jobs
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-18: No Bedrock model evaluation jobs found. Model evaluation helps assess toxicity, accuracy, semantic robustness, and other safety metrics before production deployment.

Resolution

Run Bedrock model evaluation jobs that include correctness and safety datasets.

Reference

Medium Failed
777788889999 us-east-1 OW-08
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: Knowledge base 'knowledge-base-prowler-findings' (ID: 9K2QZLVCZW) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store.

Resolution

Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption.

Reference

Informational N/A
777788889999 us-east-1 OW-10
OWASP LLM10: Service Quota Throttling Limits
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-22: 9 custom throttling quotas are configured. Regular quota review helps maintain appropriate rate limits.

Resolution

Customise Bedrock TPM / RPM service quotas above the account default to establish an explicit consumption ceiling.

Reference

Low Passed
777788889999 us-east-1 OW-01
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: Guardrail 'aiml-sec-test-test-guardrail' (ID: jkceg2tprvwh) could not be assessed because GetGuardrail returned AccessDeniedException.

Resolution

Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier.

Reference

Informational N/A
777788889999 us-east-1 OW-04
OWASP LLM04: RAG Evaluation Coverage
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: Knowledge base 'knowledge-base-prowler-findings' (ID: 9K2QZLVCZW) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations.

Resolution

Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context.

Reference

Low Failed
777788889999 us-east-1 OW-09
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-25: Knowledge base 'knowledge-base-prowler-findings' (ID: 9K2QZLVCZW) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations.

Resolution

Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates.

Reference

Low Failed
777788889999 us-east-1 OW-02
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check BR-26: Guardrail 'aiml-sec-test-test-guardrail' (ID: jkceg2tprvwh) could not be assessed because GetGuardrail returned AccessDeniedException.

Resolution

Configure guardrail sensitiveInformationPolicy with PII entities and regex patterns; set outputAction=ANONYMIZE or BLOCK.

Reference

Informational N/A
777788889999 us-east-1 OW-01
OWASP LLM01: Contextual Grounding Guardrail
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-27: Guardrail 'aiml-sec-test-test-guardrail' (ID: jkceg2tprvwh) could not be assessed because GetGuardrail returned AccessDeniedException.

Resolution

Enable Bedrock guardrail contextual grounding checks to reduce the surface for indirect prompt injection through retrieved context.

Reference

Informational N/A
777788889999 us-east-1 OW-04
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-27: Guardrail 'aiml-sec-test-test-guardrail' (ID: jkceg2tprvwh) could not be assessed because GetGuardrail returned AccessDeniedException.

Resolution

Enable contextual grounding guardrail filters so retrieved context that diverges from ground truth is filtered before reaching the model.

Reference

Informational N/A
777788889999 us-east-1 OW-09
OWASP LLM09: Contextual Grounding for Faithfulness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-27: Guardrail 'aiml-sec-test-test-guardrail' (ID: jkceg2tprvwh) could not be assessed because GetGuardrail returned AccessDeniedException.

Resolution

Set the contextual grounding filter threshold to at least 0.70 to reduce hallucinated responses.

Reference

Informational N/A
777788889999 us-east-1 OW-06
OWASP LLM06: Bedrock Agent Guardrail Association
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-28: 1 agents have an associated guardrail

Resolution

Attach an approved Bedrock guardrail to every Bedrock agent so autonomous actions are filtered consistently.

Reference

Low Passed
777788889999 us-east-1 OW-03
OWASP LLM03: Imported-Model KMS Provenance
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check BR-30: No imported custom Bedrock models found in this region

Resolution

Encrypt imported Bedrock models with a customer-managed KMS key to preserve provenance and access control across model artefacts.

Reference

Informational N/A
777788889999 us-east-1 OW-10
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-32: No CloudWatch alarms are configured on Amazon Bedrock runtime metrics (AWS/Bedrock namespace). Without alarms, abuse, denial-of-wallet, sustained throttling, and content-filter spikes can go undetected.

Resolution

Create CloudWatch alarms on Bedrock InvocationThrottles, InputTokenCount, OutputTokenCount, and EstimatedTPMQuotaUsage.

Reference

Medium Failed
777788889999 us-east-1 OW-03
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check BR-33: Amazon Inspector Lambda standard scanning and Lambda code scanning are both ENABLED in us-east-1. Detected 1 Lambda function(s) with Bedrock indicators: aiml-security-aiml-security-mgmt-BedrockAssessment.

Resolution

Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain.

Reference

Medium Passed
777788889999 us-east-1 OW-03
OWASP LLM03: SageMaker Internet Exposure
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-01: SageMaker notebook instance 'aiml-sec-test-notebook-with-internet' has direct internet access enabled

Resolution

Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths.

Reference

High Failed
777788889999 us-east-1 OW-03
OWASP LLM03: SageMaker Internet Exposure
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-01: SageMaker domain 'd-ilmtsfeenavc' (aiml-sec-test-domain-fail-028e1010-52cbf970) is not configured for VPC-only access

Resolution

Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths.

Reference

High Failed
777788889999 us-east-1 OW-03
OWASP LLM03: SageMaker Internet Exposure
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-01: SageMaker domain 'd-cmz7ohkxxop3' (aiml-sec-test-domain-fail-fef4e7f0-bb429d11) is not configured for VPC-only access

Resolution

Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths.

Reference

High Failed
777788889999 us-east-1 OW-02
OWASP LLM02: SageMaker Data Encryption
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: Notebook Instance 'aiml-sec-test-notebook-with-internet' - No KMS key configured

Resolution

Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data.

Reference

High Failed
777788889999 us-east-1 OW-02
OWASP LLM02: SageMaker Data Encryption
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: Domain 'aiml-sec-test-domain-fail-028e1010-52cbf970' - No KMS key configured

Resolution

Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data.

Reference

High Failed
777788889999 us-east-1 OW-02
OWASP LLM02: SageMaker Data Encryption
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: Domain 'aiml-sec-test-domain-fail-fef4e7f0-bb429d11' - No KMS key configured

Resolution

Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data.

Reference

High Failed
777788889999 us-east-1 OW-02
OWASP LLM02: SageMaker Data Encryption
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: Training Job 'aiml-sec-test-training-no-encryption-028e1010-e2fb8765' - No output encryption configured

Resolution

Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data.

Reference

High Failed
777788889999 us-east-1 OW-02
OWASP LLM02: SageMaker Data Encryption
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: Training Job 'aiml-sec-test-training-no-encryption-028e1010-e2fb8765' - Inter-container traffic encryption not enabled

Resolution

Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data.

Reference

Medium Failed
777788889999 us-east-1 OW-09
OWASP LLM09: SageMaker Clarify Evaluation
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-06: No SageMaker Clarify jobs found

Resolution

Use SageMaker Clarify to evaluate bias and explainability for models whose generated outputs can influence user decisions.

Reference

Informational N/A
777788889999 us-east-1 OW-04
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-07: No Model Monitor schedules found

Resolution

Configure active SageMaker Model Monitor schedules so data-quality and model-quality regressions caused by poisoned inputs or drift are detected.

Reference

Informational N/A
777788889999 us-east-1 OW-09
OWASP LLM09: SageMaker Model Monitor Coverage
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-07: No Model Monitor schedules found

Resolution

Configure SageMaker Model Monitor schedules for production models so quality regressions that can produce incorrect outputs are detected.

Reference

Informational N/A
777788889999 us-east-1 OW-03
OWASP LLM03: SageMaker Notebook VPC Deployment
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-10: Notebook instance 'aiml-sec-test-notebook-with-internet' is not deployed in a custom VPC. This uses SageMaker's service VPC with reduced network isolation.

Resolution

Deploy SageMaker notebook instances inside a VPC so package, data, and model artifact access can be controlled through private network paths.

Reference

High Failed
777788889999 us-east-1 OW-03
OWASP LLM03: SageMaker Model Network Isolation
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-11: Model 'SageMakerModelNoIsolation-yQ7EpJeL7pgI' does not have network isolation enabled. Model containers can make outbound network calls, potentially exfiltrating data.

Resolution

Enable network isolation on SageMaker models so inference containers cannot make unmanaged outbound calls that alter dependencies or exfiltrate model artifacts.

Reference

High Failed
777788889999 us-east-1 OW-10
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check SM-11: Model 'SageMakerModelNoIsolation-yQ7EpJeL7pgI' does not have network isolation enabled. Model containers can make outbound network calls, potentially exfiltrating data.

Resolution

Enable SageMaker model network isolation to prevent deployed model containers from making uncontrolled outbound calls that can amplify consumption or abuse downstream services.

Reference

High Failed
777788889999 us-east-1 OW-03
OWASP LLM03: SageMaker Container Repository Access
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-14: Model 'SageMakerModelWithIsolation-JASFpUHjajdk' uses Platform repository access mode. Container images are pulled from public/external registries, exposing supply chain risks.

Resolution

Configure SageMaker models to pull container images from private ECR repositories through VPC repository access instead of platform or public registry paths.

Reference

Medium Failed
777788889999 us-east-1 OW-03
OWASP LLM03: SageMaker Container Repository Access
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-14: Model 'SageMakerModelNoIsolation-yQ7EpJeL7pgI' uses Platform repository access mode. Container images are pulled from public/external registries, exposing supply chain risks.

Resolution

Configure SageMaker models to pull container images from private ECR repositories through VPC repository access instead of platform or public registry paths.

Reference

Medium Failed
777788889999 us-east-1 OW-02
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-15: Feature group 'aiml-sec-test-feature-group' offline store does not have KMS encryption configured. Feature data in S3 may not be encrypted with customer-managed keys.

Resolution

Encrypt SageMaker Feature Store offline stores with customer-managed KMS keys so sensitive feature data is protected at rest.

Reference

Medium Failed
777788889999 us-east-1 OW-03
OWASP LLM03: SageMaker AutoML Network Isolation
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-21: No AutoML jobs found

Resolution

Enable network isolation on AutoML jobs so generated training containers cannot fetch unapproved dependencies or send data over unmanaged network paths.

Reference

Informational N/A
777788889999 us-east-1 OW-04
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: Checked 1 model package groups. Approval workflows appear to be properly configured.

Resolution

Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically.

Reference

Medium Passed
777788889999 us-east-1 OW-09
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-22: Checked 1 model package groups. Approval workflows appear to be properly configured.

Resolution

Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release.

Reference

Medium Passed
777788889999 us-east-1 OW-04
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-23: No InService endpoints found to monitor.

Resolution

Enable SageMaker Model Monitor drift detection for production endpoints so poisoning, data drift, and model-quality degradation are identified.

Reference

Medium Passed
777788889999 us-east-1 OW-09
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-23: No InService endpoints found to monitor.

Resolution

Configure data-quality and model-quality monitoring for SageMaker endpoints so degraded model behavior that can produce misinformation is detected.

Reference

Medium Passed
777788889999 us-east-1 OW-03
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain.

Reference

Informational N/A
777788889999 us-east-1 OW-04
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated.

Reference

Informational N/A
777788889999 Global OW-06
OWASP LLM06: AgentCore IAM Least Privilege
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check AC-02: The following roles have wildcard AgentCore permissions on all resources: aiml-sec-test-resources-AgentCoreOverlyPermissiveRo-IQso7VQN0jOV

Resolution

Remove AmazonBedrockAgentCoreFullAccess (or equivalents) from identities that only need read/execute permissions.

Reference

High Failed
777788889999 us-east-1 OW-06
OWASP LLM06: AgentCore Resource-Based Policies
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check AC-10: No AgentCore resources found to check for resource-based policies

Resolution

Attach resource-based policies to AgentCore runtimes and gateways so caller identities are constrained.

Reference

Informational N/A
777788889999 us-east-1 OW-10
OWASP LLM10: WAF Rate-Based & Shield Protection
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-01: AWS Shield Advanced is not subscribed. GenAI API endpoints are vulnerable to volumetric DDoS attacks that can exhaust token quotas and inflate costs.

Resolution

Add a WAF RateBasedStatement plus a SizeConstraintStatement on the GenAI ingress and subscribe to AWS Shield Advanced.

Reference

Low Failed
777788889999 us-east-1 OW-10
OWASP LLM10: WAF Rate-Based & Shield Protection
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-01: No AWS WAF regional Web ACLs found. Without WAF, GenAI endpoints lack rate-based rules to block abusive callers.

Resolution

Add a WAF RateBasedStatement plus a SizeConstraintStatement on the GenAI ingress and subscribe to AWS Shield Advanced.

Reference

Medium Failed
777788889999 us-east-1 OW-10
OWASP LLM10: API Gateway Usage Plans
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-02: No usage plans configured. GenAI API endpoints may have no rate limits.

Resolution

Attach API Gateway Usage Plans with non-zero rateLimit / burstLimit to any REST APIs that proxy Bedrock.

Reference

Informational N/A
777788889999 us-east-1 OW-10
OWASP LLM10: Bedrock TPM/RPM Quotas Customised
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-03: Found 240 Bedrock token-based quota(s); at least one applied value exceeds the AWS default, indicating quotas have been reviewed and raised.

Resolution

Customise Bedrock service quotas above the account default so consumption is explicitly bounded.

Reference

Medium Passed
777788889999 us-east-1 OW-10
OWASP LLM10: Cost Anomaly Detection
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-04: No AWS Cost Anomaly Detection monitors found. Unexpected spikes in Bedrock/SageMaker usage (e.g., from prompt injection loops) will go undetected.

Resolution

Configure AWS Cost Anomaly Detection monitors that include Bedrock and SageMaker.

Reference

Medium Failed
777788889999 us-east-1 OW-10
OWASP LLM10: Token / Throttle Alarms
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-05: No CloudWatch alarms found for Bedrock metrics. Token exhaustion and throttling events will not trigger operational alerts.

Resolution

Create CloudWatch alarms on the Bedrock namespace for InvocationThrottles and token counters.

Reference

Medium Failed
777788889999 us-east-1 OW-10
OWASP LLM10: AWS Budgets with Bedrock Filters
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-06: No AWS Budgets found scoped to Bedrock or SageMaker. Unbounded GenAI spend can go undetected until the monthly bill.

Resolution

Configure AWS Budgets with FilterExpression / CostFilters targeting Bedrock or SageMaker spend, with an alerting SNS action.

Reference

Medium Failed
777788889999 us-east-1 OW-06
OWASP LLM06: Agent Execution Role Least Privilege
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check FS-07: Reviewed 1 agent(s); no wildcard sensitive actions found.

Resolution

Remove wildcard sensitive actions from Bedrock Agent execution roles.

Reference

High Passed
777788889999 us-east-1 OW-06
OWASP LLM06: AgentCore Gateway Policy Engine
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check FS-08: No AgentCore runtimes found; policy engine check not applicable.

Resolution

Set AgentCore Gateway policyEngineConfiguration.mode to ENFORCE and require identity propagation on Runtimes.

Reference

Informational N/A
777788889999 us-east-1 OW-06
OWASP LLM06: Agent Tool Concurrency Limits
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check FS-09: Agent-related Lambda functions without reserved concurrency: aiml-security-aiml-security-mgmt-FinServAssessment, aiml-sec-test-resources-SageMakerJobCustomResource-ZA5QCAi0pN3d, AIMLSecurityAssessment-CodeBuildStartBuildLambda-VYOqtzWoNo3m, aiml-security-aiml-security-mgmt-CleanupBucket, aiml-security-aiml-security-mgmt-SagemakerAssessment, aiml-security-aiml-security-mgmt-GenerateReport, aiml-security-aiml-security-mgmt-OWASPAssessment, aiml-security-aiml-security-mgmt-IAMPermissionCaching, aiml-security-aiml-security-mgmt-AgentCoreAssessment, aiml-security-aiml-security-mgmt-BedrockAssessment. Unlimited concurrency allows runaway agent loops to exhaust account limits.

Resolution

Set reserved concurrency on agent action-group Lambdas so a runaway agent cannot exhaust downstream capacity.

Reference

Medium Failed
777788889999 us-east-1 OW-06
OWASP LLM06: Human-in-the-Loop Callback States
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check FS-10: No Step Functions state machines with agent/approval naming found. Verify that high-risk agent actions (e.g., fund transfers, account changes) have human approval gates.

Resolution

Insert Step Functions .waitForTaskToken callback states before any high-risk agent-triggered action.

Reference

Informational N/A
777788889999 us-east-1 OW-03
OWASP LLM03: SCP-Enforced Model Allowlist
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check FS-12: No Service Control Policies reference Bedrock. Without SCPs, any account in the organization can access any Bedrock model, including unapproved third-party models.

Resolution

Attach an Organizations SCP that denies bedrock:InvokeModel* except for allowlisted bedrock:ModelId values.

Reference

High Failed
777788889999 us-east-1 OW-03
OWASP LLM03: Custom-Model Provenance Tags
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check FS-13: 2 model(s) missing required provenance tags: - SageMaker model 'SageMakerModelWithIsolation-JASFpUHjajdk' missing tags: {'approval-date', 'source', 'version'} - SageMaker model 'SageMakerModelNoIsolation-yQ7EpJeL7pgI' missing tags: {'approval-date', 'source', 'version'}

Resolution

Tag every Bedrock custom model with model-source, model-version, approval-date, and risk-tier so provenance is auditable.

Reference

Medium Failed
777788889999 us-east-1 OW-03
OWASP LLM03: Config Rules for Model Onboarding
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check FS-14: Found 13 model-related Config rule(s).

Resolution

Deploy AWS Config rules that enforce required tags and configuration on AWS::Bedrock::* resources at creation time.

Reference

Medium Passed
777788889999 us-east-1 OW-03
OWASP LLM03: Adversarial Evaluation Coverage
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check FS-15: No Bedrock Model Evaluation jobs found. Models have not been evaluated for adversarial robustness. FinServ model-risk management (SR 11-7) expects documented model validation/evaluation.

Resolution

Run Bedrock evaluation jobs that include adversarial and safety datasets before promoting a model to production.

Reference

Medium Failed
777788889999 us-east-1 OW-03
OWASP LLM03: ECR Image Scanning
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check FS-16: 2 ECR repo(s) without scan-on-push: cdk-hnb659fds-container-assets-777788889999-us-east-1, aiml-sec-test-agentcore-no-encryption.

Resolution

Enable Amazon Inspector enhanced scanning or scan-on-push on ECR repositories that hold model / agent container images.

Reference

High Failed
777788889999 us-east-1 OW-04
OWASP LLM04: Feature Store Offline Recovery
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check FS-20: 1 feature group(s) lack an active offline store: aiml-sec-test-feature-group. Without offline store, historical feature data cannot be used for rollback.

Resolution

Enable OfflineStoreConfig on SageMaker Feature Groups so features have a durable, point-in-time record for rollback after a poisoning event.

Reference

Medium Failed
777788889999 us-east-1 OW-04
OWASP LLM04: Training-Data Versioning
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check FS-21: All 2 training bucket(s) have versioning enabled.

Resolution

Enable S3 versioning on training-data buckets so poisoned data can be reverted.

Reference

High Passed
777788889999 us-east-1 OW-08
OWASP LLM08: KB IAM Scope
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-22: 825 role(s) with wildcard KB permissions: - Role 'Admin' allows '*' - Role 'aiml-sec-test-resources-BedrockAgentRole-RScmoTZfp2sC' allows 'bedrock:InvokeModel' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-test-resources-BedrockAgentRole-RScmoTZfp2sC' allows 'bedrock:InvokeModelWithResponseStream' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-test-resources-BedrockAgentRoleWithoutGuar-Z3kN5ANhP89G' allows 'bedrock:InvokeModel' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-test-resources-BedrockAgentRoleWithoutGuar-Z3kN5ANhP89G' allows 'bedrock:InvokeModelWithResponseStream' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-test-resources-BedrockFullAccessRole-zAFkGLkWQ61a' allows 'bedrock:*' - Role 'aiml-security-mgmt-BedrockSecurityAssessmentFunctio-a7GKJ6O4151K' allows 'bedrock:ListGuardrails' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-mgmt-BedrockSecurityAssessmentFunctio-a7GKJ6O4151K' allows 'bedrock:GetGuardrail' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-mgmt-BedrockSecurityAssessmentFunctio-a7GKJ6O4151K' allows 'bedrock:ListModelInvocationJobs' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-mgmt-BedrockSecurityAssessmentFunctio-a7GKJ6O4151K' allows 'bedrock:GetModelInvocationLoggingConfiguration' on Resource '*' (no ARN scoping to specific Knowledge Bases)

Resolution

Scope Knowledge Base IAM roles to specific KB ARNs; remove wildcard bedrock:* on KB actions.

Reference

High Failed
777788889999 us-east-1 OW-08
OWASP LLM08: KB Metadata Filtering
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-24: Found 1 Knowledge Base(s). Tenant-isolation metadata filtering is a design pattern that cannot be verified via API — manual review required. Verify that metadata attributes (e.g., tenantId, classification) are indexed and that Retrieve calls include RetrievalFilter conditions for tenant isolation.

Resolution

Define Knowledge Base metadata fields so tenant / document-level filtering can be applied at retrieval time.

Reference

Informational N/A
777788889999 us-east-1 OW-08
OWASP LLM08: OpenSearch Serverless Encryption
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-25: Found 1 encryption policy(ies); 1 use a customer-managed KMS key.

Resolution

Use a customer-managed KMS key on the OpenSearch Serverless encryption policy for the vector collection.

Reference

High Passed
777788889999 us-east-1 OW-08
OWASP LLM08: OpenSearch Serverless Network Policy
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-26: Found 1 network policy(ies) but none restrict to VPC. Vector stores may be accessible from the public internet.

Resolution

Set AllowFromPublic=false on the OpenSearch Serverless network policy and restrict access to bedrock.amazonaws.com or a specific VPC endpoint.

Reference

High Failed
777788889999 us-east-1 OW-09
OWASP LLM09: Knowledge-Base Ingestion Freshness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check FS-31: 1 data source(s) not synced in >7 days (a configurable review threshold, NOT an AWS-mandated limit): - KB 'knowledge-base-prowler-findings' source 'knowledge-base-quick-start-9lb68-data-source' last synced 432 days ago Confirm this age is acceptable for each data source's currency requirement — slow-changing reference data may legitimately sync infrequently.

Resolution

Sync Knowledge Base data sources on a schedule (weekly at most); stale KB content increases hallucination risk.

Reference

Medium Failed
777788889999 us-east-1 OW-09
OWASP LLM09: Source Attribution
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check FS-32: Source attribution in GenAI responses cannot be verified via AWS APIs. Manual review required to confirm responses include citations.

Resolution

Return citations in RetrieveAndGenerate responses so end users can verify grounding.

Reference

Informational N/A
777788889999 us-east-1 OW-09
OWASP LLM09: KB S3 Data-Source Integrity
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check FS-33: All reviewed KB data source buckets have versioning enabled.

Resolution

Enable S3 versioning + notifications on Knowledge Base data-source buckets so ingest failures are visible.

Reference

Medium Passed
777788889999 us-east-1 OW-04
OWASP LLM04: SageMaker Model Card Documentation
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check FS-42: No SageMaker Model Cards found. Production AI models lack documented intended use, limitations, and bias evaluations.

Resolution

Create SageMaker Model Cards for production models that document intended use, training data provenance, and bias/fairness evaluations so poisoned or drifted models are detectable against a documented baseline.

Reference

Medium Failed
777788889999 us-east-1 OW-09
OWASP LLM09: SageMaker Model Card Documentation
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check FS-42: No SageMaker Model Cards found. Production AI models lack documented intended use, limitations, and bias evaluations.

Resolution

Document each production model's intended use, known limitations, and evaluation results in a SageMaker Model Card so misinformation risks tied to model behaviour are traceable to a reviewed system card.

Reference

Medium Failed
777788889999 us-east-1 OW-02
OWASP LLM02: CloudWatch Log Data Protection Policies
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-43: No CloudWatch Logs data protection policies found. PII (SSN, account numbers, credit card numbers) in Bedrock invocation logs may be stored in plaintext.

Resolution

Apply a CloudWatch Logs data protection policy to log groups that receive Bedrock invocation logs.

Reference

High Failed
777788889999 us-east-1 OW-02
OWASP LLM02: Macie Sensitive-Data Discovery
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-44: Amazon Macie is not enabled. S3 buckets containing training data and KB data sources are not being scanned for PII/sensitive data.

Resolution

Enable Amazon Macie with automated discovery on S3 buckets that hold training or knowledge-base data.

Reference

High Failed
777788889999 us-east-1 OW-02
OWASP LLM02: Guardrail PII Entities Coverage
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-45: This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved.

Resolution

Add the required PII entity types to the guardrail sensitiveInformationPolicy so PII in prompts/responses is filtered.

Reference

Informational N/A
777788889999 us-east-1 OW-02
OWASP LLM02: S3 Data-Classification Tagging
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-46: 3 AI/ML bucket(s) without data-classification tags: aiml-sec-test-resources-bedrockloggingbucket-wtuvpinrlpmd, aiml-sec-test-resources-sagemakerbucket-6zzmxxaxco6g, aiml-security-mgmt-aimlassessmentbucket-kbitsdgexylv.

Resolution

Tag training and knowledge-base S3 buckets with a data-classification tag so downstream automations enforce controls consistent with the sensitivity level.

Reference

Medium Failed
777788889999 us-east-1 OW-09
OWASP LLM09: Grounding Filter Threshold
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check FS-47: This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved.

Resolution

Set the contextual grounding filter threshold to at least 0.70 on guardrails used for RAG workflows.

Reference

Informational N/A
777788889999 us-east-1 OW-09
OWASP LLM09: Active Knowledge Base Present
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check FS-48: Found 1 active Knowledge Base(s) for RAG grounding.

Resolution

Deploy at least one ACTIVE Knowledge Base when Bedrock models are used, so grounded retrieval is available.

Reference

Medium Passed
777788889999 us-east-1 OW-01
OWASP LLM01: PROMPT_ATTACK Filter at Standard Tier
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check FS-51: This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved.

Resolution

Set guardrail PROMPT_ATTACK filter to Standard tier with inputStrength=HIGH.

Reference

Informational N/A
777788889999 us-east-1 OW-01
OWASP LLM01: Bedrock-Calling Lambda Runtimes
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check FS-52: All 11 Bedrock Lambda function(s) use current runtimes.

Resolution

Ensure Lambda functions that invoke Bedrock use a supported (non-deprecated) runtime to receive security patches.

Reference

Medium Passed
777788889999 us-east-1 OW-01
OWASP LLM01: WAF SQLi & KnownBadInputs Coverage
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check FS-53: No regional WAF Web ACLs found.

Resolution

Add AWS Managed Rule Groups AWSManagedRulesSQLiRuleSet and AWSManagedRulesKnownBadInputsRuleSet to the WAF Web ACL guarding GenAI ingress.

Reference

Informational N/A
777788889999 us-east-1 OW-01
OWASP LLM01: Adversarial Testing Evidence
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check FS-54: Penetration testing evidence cannot be verified via AWS APIs. Manual review required to confirm GenAI applications have been tested.

Resolution

Track adversarial / red-team penetration test evidence for the GenAI application via resource tags or an equivalent audit trail.

Reference

Informational N/A
777788889999 us-east-1 OW-05
OWASP LLM05: Output-Validation Lambda
Details and remediation
Details

OWASP category: LLM05:2025 Improper Output Handling. Source check FS-55: No Lambda functions with output validation/sanitization naming found. GenAI outputs may be passed directly to downstream systems without validation.

Resolution

Deploy an output-validation / sanitisation Lambda between the model response and any downstream consumer to filter injection payloads in generated output.

Reference

Medium Failed
777788889999 us-east-1 OW-05
OWASP LLM05: WAF XSS Protection
Details and remediation
Details

OWASP category: LLM05:2025 Improper Output Handling. Source check FS-56: No regional WAF Web ACLs found.

Resolution

Ensure the WAF Web ACL guarding GenAI ingress includes AWSManagedRulesCommonRuleSet (XSS) or an equivalent XssMatchStatement.

Reference

Informational N/A
777788889999 us-east-1 OW-05
OWASP LLM05: Output Encoding Libraries
Details and remediation
Details

OWASP category: LLM05:2025 Improper Output Handling. Source check FS-57: Output encoding practices cannot be verified via AWS APIs. Manual code review required.

Resolution

Ensure Lambdas that render model output use a well-known output-encoding library appropriate to the downstream sink (HTML, SQL, shell, etc.).

Reference

Informational N/A
777788889999 us-east-1 OW-05
OWASP LLM05: Step Functions Output Schema Validation
Details and remediation
Details

OWASP category: LLM05:2025 Improper Output Handling. Source check FS-58: Found 0 Lambda function(s) whose names suggest schema/validation handling. Structured-output / JSON-schema validation of GenAI responses is an application-layer control that cannot be verified automatically — manual review required.

Resolution

Add explicit schema-validation states in Step Functions workflows that consume model output.

Reference

Informational N/A
777788889999 us-east-1 OW-06
OWASP LLM06: Agent Transaction Thresholds
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check FS-67: The following agent action-group Lambda functions have no environment variables whose names suggest transaction-value threshold configuration (this is a best-effort heuristic — a threshold enforced in code or in an AgentCore Policy Engine rule would not be detected here, so treat this as a prompt for manual verification rather than a definitive gap). Without explicit limits, agents could initiate unbounded financial transactions: - aiml-security-aiml-security-mgmt-FinServAssessment - aiml-security-aiml-security-mgmt-AgentCoreAssessment - aiml-security-aiml-security-mgmt-BedrockAssessment

Resolution

Encode agent transaction thresholds in Cedar policies or Lambda configuration so per-action limits are enforced.

Reference

High Failed
777788889999 us-east-1 OW-10
OWASP LLM10: API Gateway Request Body Size Limits
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-68: No API Gateway REST APIs and no regional WAF Web ACLs were found in this region. There is no input-payload surface to assess for body-size limits.

Resolution

Configure API Gateway request validation or an equivalent ingress control so GenAI endpoints reject oversized request bodies before they can drive excessive model consumption.

Reference

Informational N/A
777788889999 us-east-1 OW-01
OWASP LLM01: Prompt-Input Validation Lambda
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check FS-69: Found 1 Lambda function(s) with input validation/sanitization naming patterns: aiml-security-aiml-security-mgmt-CleanupBucket.

Resolution

Deploy a prompt-input validation Lambda in front of Bedrock invocations to sanitise untrusted input before it reaches the model.

Reference

Medium Passed
777788889999 us-east-1 OW-11
OWASP LLM07: System Prompt Embedded in Lambda Env Var
Details and remediation
Details

No Lambda function env vars in us-east-1 match the embedded-system-prompt heuristic (>= 200 chars containing prompt-shaped tokens).

Resolution

No action required.

Reference

Medium Passed
777788889999 us-east-1 OW-12
OWASP LLM07: System-Prompt-Disclosure Denied Topic
Details and remediation
Details

Could not inspect 1 of 1 Bedrock guardrail(s) in us-east-1 for system-prompt-disclosure DENY topics. Readable guardrails inspected: 0. Sample unreadable guardrails: jkceg2tprvwh (AccessDeniedException).

Resolution

Grant bedrock:GetGuardrail for the listed guardrails or resolve the read errors, then rerun the assessment. Do not treat this as proof that a DENY topic is absent.

Reference

Informational N/A
777788889999 Global AC-02
AgentCore IAM Wildcard Permissions
Details and remediation
Details

The following roles have wildcard AgentCore permissions on all resources: aiml-sec-test-resources-AgentCoreOverlyPermissiveRo-IQso7VQN0jOV

Resolution

Scope permissions to specific AgentCore resources using resource ARNs

Reference

High Failed
777788889999 Global AC-03
AgentCore Unused Permissions
Details and remediation
Details

The following principals have AgentCore permissions but have never accessed the service: role 'aiml-sec-test-resources-AgentCoreOverlyPermissiveRo-IQso7VQN0jOV', role 'AIMLSecurityMemberRole', role 'CloudSeerTrustedServiceRole'

Resolution

Review and remove unused AgentCore permissions following least privilege principle

Reference

Informational N/A
777788889999 Global AC-09
AgentCore Service-Linked Role Missing
Details and remediation
Details

Service-linked role 'AWSServiceRoleForBedrockAgentCoreNetwork' does not exist. VPC configuration for AgentCore Runtimes will fail without this role.

Resolution

The service-linked role is automatically created when you configure VPC for an AgentCore Runtime. Ensure IAM permissions allow service-linked role creation.

Reference

Medium Failed
777788889999 us-east-1 AC-01
AgentCore VPC Configuration Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-1 AC-04
AgentCore Observability Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-1 AC-05
AgentCore ECR Repository AWS-Managed Keys
Details and remediation
Details

ECR repository 'aiml-sec-test-agentcore-no-encryption' uses AWS-managed keys instead of customer-managed KMS keys

Resolution

Consider using customer-managed KMS keys for better control and audit capabilities

Reference

Low Failed
777788889999 us-east-1 AC-06
AgentCore Browser Tool Recording Check
Details and remediation
Details

No AgentCore Runtimes found to check browser tool configuration

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-1 AC-07
AgentCore Memory Configuration Check
Details and remediation
Details

No Memory resources found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-1 AC-13
AgentCore Gateway Configuration Check
Details and remediation
Details

No Gateway resources found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-1 AC-08
AgentCore VPC Endpoints Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-1 AC-10
AgentCore Resource-Based Policies Check
Details and remediation
Details

No AgentCore resources found to check for resource-based policies

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-1 AC-11
AgentCore Policy Engine Encryption Check
Details and remediation
Details

No Policy Engines found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-1 AC-12
AgentCore Gateway Encryption Check
Details and remediation
Details

No Gateways found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-1 AG-24
Agentic AI Gateway Inbound Authorization
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-1 AG-25
Agentic AI Gateway Tool Policy Enforcement
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-1 AG-26
Agentic AI Gateway Error Detail Exposure
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-1 AG-27
Agentic AI Gateway WAF Protection
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
777788889999 Global AG-16
Agentic AI AgentCore Least Privilege
Details and remediation
Details

Agentic AI security domain: Agent Identity & Access. Over-permissive AgentCore principals can let agents or operators bypass intended autonomy and tool boundaries. Source check AC-02: The following roles have wildcard AgentCore permissions on all resources: aiml-sec-test-resources-AgentCoreOverlyPermissiveRo-IQso7VQN0jOV

Resolution

Replace full-access AgentCore permissions with least-privilege IAM policies scoped to required resources and actions.

Reference

High Failed
777788889999 Global AG-17
Agentic AI Stale AgentCore Access
Details and remediation
Details

Agentic AI security domain: Agent Identity & Access. Unused AgentCore permissions increase the blast radius of compromised principals. Source check AC-03: The following principals have AgentCore permissions but have never accessed the service: role 'aiml-sec-test-resources-AgentCoreOverlyPermissiveRo-IQso7VQN0jOV', role 'AIMLSecurityMemberRole', role 'CloudSeerTrustedServiceRole'

Resolution

Remove or restrict stale AgentCore permissions for principals that no longer need access.

Reference

Informational N/A
777788889999 us-east-1 AG-15
Agentic AI Runtime Network Boundary
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found

Resolution

Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services.

Reference

Informational N/A
777788889999 us-east-1 AG-18
Agentic AI AgentCore Observability
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found

Resolution

Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported.

Reference

Informational N/A
777788889999 us-east-1 AG-19
Agentic AI Memory Data Protection
Details and remediation
Details

Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found

Resolution

Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions.

Reference

Informational N/A
777788889999 us-east-1 AG-20
Agentic AI Private AgentCore Connectivity
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found

Resolution

Create required VPC endpoints for AgentCore services and validate endpoint availability.

Reference

Informational N/A
777788889999 us-east-1 AG-21
Agentic AI Resource Policy Boundary
Details and remediation
Details

Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies

Resolution

Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources.

Reference

Informational N/A
777788889999 us-east-1 AG-22
Agentic AI Policy Engine Data Protection
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found

Resolution

Configure policy engines with customer-managed KMS keys where enhanced key control is required.

Reference

Informational N/A
777788889999 us-east-1 AG-23
Agentic AI Gateway Data Protection
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found

Resolution

Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required.

Reference

Informational N/A
777788889999 us-west-2 BR-02
Amazon Bedrock private connectivity check
Details and remediation
Details

No regional Bedrock resources found to assess private connectivity

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 BR-04
Bedrock Model Invocation Logging Check
Details and remediation
Details

No regional Bedrock resources found to monitor with invocation logging

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 BR-05
Bedrock Guardrails Check
Details and remediation
Details

No regional Bedrock resources found to protect with guardrails

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 BR-06
Bedrock CloudTrail Logging Check
Details and remediation
Details

No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 BR-07
Bedrock Prompt Management Check
Details and remediation
Details

Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses.

Resolution

Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates

Reference

Informational N/A
777788889999 us-west-2 BR-08
Bedrock Agent IAM Roles Check
Details and remediation
Details

No Bedrock agents found in the account

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 BR-09
Bedrock Knowledge Base Encryption Check
Details and remediation
Details

No Knowledge Bases found in the account

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 BR-10
Bedrock Guardrail IAM Enforcement Check
Details and remediation
Details

No guardrails configured - IAM enforcement check not applicable

Resolution

Configure Bedrock Guardrails first, then enforce their use via IAM policies

Reference

Informational N/A
777788889999 us-west-2 BR-11
Bedrock Custom Model Encryption Check
Details and remediation
Details

No custom/fine-tuned models found in the account

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 BR-12
Bedrock Invocation Log Encryption Check
Details and remediation
Details

Model invocation logging to S3 is not configured

Resolution

If logging is enabled to CloudWatch only, ensure CloudWatch log group uses CMK encryption

Reference

Informational N/A
777788889999 us-west-2 BR-13
Bedrock Flows Guardrails Check
Details and remediation
Details

No Bedrock Flows found in the account

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 BR-16
Guardrail Tier Validation Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create Bedrock guardrails with Standard tier for enhanced content filtering and protection

Reference

Medium N/A
777788889999 us-west-2 BR-17
Custom Model Customer-Managed KMS Encryption Check
Details and remediation
Details

No custom (fine-tuned) Bedrock models found in this region

Resolution

When creating custom models, specify a customer-managed KMS key for encryption to maintain control over encryption keys

Reference

High N/A
777788889999 us-west-2 BR-18
Model Evaluation Implementation Check
Details and remediation
Details

No regional Bedrock resources found to assess with model evaluation jobs

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 BR-19
Prompt Flow Validation Check
Details and remediation
Details

No Bedrock prompt flows configured in this region

Resolution

When creating prompt flows, use the ValidateFlowDefinition API to validate flow definitions before deployment

Reference

Medium N/A
777788889999 us-west-2 BR-20
Knowledge Base Customer-Managed KMS Encryption Check
Details and remediation
Details

No Bedrock knowledge bases found in this region

Resolution

When creating knowledge bases, specify customer-managed KMS keys for both vector store and data source encryption

Reference

High N/A
777788889999 us-west-2 BR-21
Agent Action Group IAM Least Privilege Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents with action groups, ensure Lambda execution roles follow least privilege principles

Reference

High N/A
777788889999 us-west-2 BR-22
Model Invocation Throttling Limits Check
Details and remediation
Details

No regional Bedrock resources found to assess model invocation throttling quotas

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 BR-23
Guardrail Content Filter Coverage Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with all content filters enabled (hate, insults, sexual, violence) with appropriate thresholds

Reference

High N/A
777788889999 us-west-2 BR-24
Automated Reasoning Policy Implementation Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with Automated Reasoning policies for formal verification of model responses

Reference

Medium N/A
777788889999 us-west-2 BR-25
RAG Evaluation Jobs Check
Details and remediation
Details

No Bedrock knowledge bases found in this region

Resolution

When implementing RAG applications, configure evaluation jobs to assess context relevance, response correctness, and prevent hallucinations

Reference

Low N/A
777788889999 us-west-2 BR-26
Guardrail Sensitive Information Filter Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with sensitive-information filters (PII entities and/or regex patterns) to detect and redact sensitive data in prompts and model responses

Reference

High N/A
777788889999 us-west-2 BR-27
Guardrail Contextual Grounding Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with contextual grounding checks to detect hallucinations (ungrounded responses) and irrelevant answers, especially for RAG applications

Reference

Medium N/A
777788889999 us-west-2 BR-28
Agent Guardrail Association Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents, associate a Bedrock guardrail so agent inputs and responses are filtered for harmful content, PII, and denied topics

Reference

High N/A
777788889999 us-west-2 BR-29
Agent Idle Session TTL Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents, set a conservative idleSessionTTLInSeconds to limit how long an idle session remains resumable

Reference

Low N/A
777788889999 us-west-2 BR-30
Imported Model Customer-Managed KMS Encryption Check
Details and remediation
Details

No imported custom Bedrock models found in this region

Resolution

When importing models, specify a customer-managed KMS key for encryption to maintain control over encryption keys

Reference

High N/A
777788889999 us-west-2 BR-31
Batch Inference Output Encryption Check
Details and remediation
Details

No Bedrock batch inference (model invocation) jobs found in this region

Resolution

When creating batch inference jobs, set outputDataConfig.s3OutputDataConfig.s3EncryptionKeyId to a customer-managed KMS key to encrypt the job output

Reference

Medium N/A
777788889999 us-west-2 BR-32
Bedrock CloudWatch Alarm Check
Details and remediation
Details

No regional Bedrock resources found to monitor with CloudWatch alarms

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 BR-33
Amazon Inspector Lambda Code Scanning Check
Details and remediation
Details

No Lambda functions with Bedrock indicators were found in us-west-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads.

Resolution

No action required. If Bedrock-calling Lambda functions exist, ensure their function name, ARN, description, handler, role, or environment variables contain a Bedrock identifier that the assessment can detect, or evaluate Inspector coverage manually.

Reference

Informational N/A
777788889999 us-west-2 AG-07
Agentic AI Model Invocation Logging
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging

Resolution

Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements.

Reference

Informational N/A
777788889999 us-west-2 AG-08
Agentic AI API Audit Trail
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage

Resolution

Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured.

Reference

Informational N/A
777788889999 us-west-2 AG-10
Agentic AI Adversarial Evaluation Coverage
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs

Resolution

Configure model or application evaluations that include adversarial, safety, and security-relevant test cases.

Reference

Informational N/A
777788889999 us-west-2 AG-11
Agentic AI Prompt Flow Validation
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region

Resolution

Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions.

Reference

Informational N/A
777788889999 us-west-2 AG-06
Agentic AI Tool Execution Least Privilege
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region

Resolution

Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required.

Reference

Informational N/A
777788889999 us-west-2 AG-12
Agentic AI Invocation Abuse Controls
Details and remediation
Details

Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas

Resolution

Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns.

Reference

Informational N/A
777788889999 us-west-2 AG-02
Agentic AI Harmful Content Guardrail Coverage
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: No Bedrock guardrails configured in this region

Resolution

Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads.

Reference

Informational N/A
777788889999 us-west-2 AG-04
Agentic AI Automated Reasoning Guardrails
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: No Bedrock guardrails configured in this region

Resolution

Configure automated reasoning policies on guardrails where formal response validation is required.

Reference

Informational N/A
777788889999 us-west-2 AG-03
Agentic AI Sensitive Information Protection
Details and remediation
Details

Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: No Bedrock guardrails configured in this region

Resolution

Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns.

Reference

Informational N/A
777788889999 us-west-2 AG-05
Agentic AI Grounding Controls
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows.

Reference

Informational N/A
777788889999 us-west-2 AG-01
Agentic AI Agent Guardrail Association
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region

Resolution

Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating.

Reference

Informational N/A
777788889999 us-west-2 AG-13
Agentic AI Session Boundary
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region

Resolution

Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements.

Reference

Informational N/A
777788889999 us-west-2 AG-14
Agentic AI Operational Abuse Alarms
Details and remediation
Details

Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms

Resolution

Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available.

Reference

Informational N/A
777788889999 us-east-2 BR-02
Amazon Bedrock private connectivity check
Details and remediation
Details

No regional Bedrock resources found to assess private connectivity

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 BR-04
Bedrock Model Invocation Logging Check
Details and remediation
Details

No regional Bedrock resources found to monitor with invocation logging

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 BR-05
Bedrock Guardrails Check
Details and remediation
Details

No regional Bedrock resources found to protect with guardrails

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 BR-06
Bedrock CloudTrail Logging Check
Details and remediation
Details

No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 BR-07
Bedrock Prompt Management Check
Details and remediation
Details

Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses.

Resolution

Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates

Reference

Informational N/A
777788889999 us-east-2 BR-08
Bedrock Agent IAM Roles Check
Details and remediation
Details

No Bedrock agents found in the account

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 BR-09
Bedrock Knowledge Base Encryption Check
Details and remediation
Details

No Knowledge Bases found in the account

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 BR-10
Bedrock Guardrail IAM Enforcement Check
Details and remediation
Details

No guardrails configured - IAM enforcement check not applicable

Resolution

Configure Bedrock Guardrails first, then enforce their use via IAM policies

Reference

Informational N/A
777788889999 us-east-2 BR-11
Bedrock Custom Model Encryption Check
Details and remediation
Details

Custom model API not available in us-east-2

Resolution

Verify permissions to access Bedrock custom models

Reference

Low N/A
777788889999 us-east-2 BR-12
Bedrock Invocation Log Encryption Check
Details and remediation
Details

Model invocation logging to S3 is not configured

Resolution

If logging is enabled to CloudWatch only, ensure CloudWatch log group uses CMK encryption

Reference

Informational N/A
777788889999 us-east-2 BR-13
Bedrock Flows Guardrails Check
Details and remediation
Details

No Bedrock Flows found in the account

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 BR-16
Guardrail Tier Validation Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create Bedrock guardrails with Standard tier for enhanced content filtering and protection

Reference

Medium N/A
777788889999 us-east-2 BR-17
Custom Model Customer-Managed KMS Encryption Check
Details and remediation
Details

Could not assess this check in us-east-2. Assessment error: UnknownOperationException.

Resolution

No action required on the assessed workload. Resolve the assessment prerequisite or permission issue and rerun the assessment.

Reference

Informational N/A
777788889999 us-east-2 BR-18
Model Evaluation Implementation Check
Details and remediation
Details

No regional Bedrock resources found to assess with model evaluation jobs

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 BR-19
Prompt Flow Validation Check
Details and remediation
Details

No Bedrock prompt flows configured in this region

Resolution

When creating prompt flows, use the ValidateFlowDefinition API to validate flow definitions before deployment

Reference

Medium N/A
777788889999 us-east-2 BR-20
Knowledge Base Customer-Managed KMS Encryption Check
Details and remediation
Details

No Bedrock knowledge bases found in this region

Resolution

When creating knowledge bases, specify customer-managed KMS keys for both vector store and data source encryption

Reference

High N/A
777788889999 us-east-2 BR-21
Agent Action Group IAM Least Privilege Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents with action groups, ensure Lambda execution roles follow least privilege principles

Reference

High N/A
777788889999 us-east-2 BR-22
Model Invocation Throttling Limits Check
Details and remediation
Details

No regional Bedrock resources found to assess model invocation throttling quotas

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 BR-23
Guardrail Content Filter Coverage Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with all content filters enabled (hate, insults, sexual, violence) with appropriate thresholds

Reference

High N/A
777788889999 us-east-2 BR-24
Automated Reasoning Policy Implementation Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with Automated Reasoning policies for formal verification of model responses

Reference

Medium N/A
777788889999 us-east-2 BR-25
RAG Evaluation Jobs Check
Details and remediation
Details

No Bedrock knowledge bases found in this region

Resolution

When implementing RAG applications, configure evaluation jobs to assess context relevance, response correctness, and prevent hallucinations

Reference

Low N/A
777788889999 us-east-2 BR-26
Guardrail Sensitive Information Filter Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with sensitive-information filters (PII entities and/or regex patterns) to detect and redact sensitive data in prompts and model responses

Reference

High N/A
777788889999 us-east-2 BR-27
Guardrail Contextual Grounding Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with contextual grounding checks to detect hallucinations (ungrounded responses) and irrelevant answers, especially for RAG applications

Reference

Medium N/A
777788889999 us-east-2 BR-28
Agent Guardrail Association Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents, associate a Bedrock guardrail so agent inputs and responses are filtered for harmful content, PII, and denied topics

Reference

High N/A
777788889999 us-east-2 BR-29
Agent Idle Session TTL Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents, set a conservative idleSessionTTLInSeconds to limit how long an idle session remains resumable

Reference

Low N/A
777788889999 us-east-2 BR-30
Imported Model Customer-Managed KMS Encryption Check
Details and remediation
Details

No imported custom Bedrock models found in this region

Resolution

When importing models, specify a customer-managed KMS key for encryption to maintain control over encryption keys

Reference

High N/A
777788889999 us-east-2 BR-31
Batch Inference Output Encryption Check
Details and remediation
Details

No Bedrock batch inference (model invocation) jobs found in this region

Resolution

When creating batch inference jobs, set outputDataConfig.s3OutputDataConfig.s3EncryptionKeyId to a customer-managed KMS key to encrypt the job output

Reference

Medium N/A
777788889999 us-east-2 BR-32
Bedrock CloudWatch Alarm Check
Details and remediation
Details

No regional Bedrock resources found to monitor with CloudWatch alarms

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 BR-33
Amazon Inspector Lambda Code Scanning Check
Details and remediation
Details

No Lambda functions with Bedrock indicators were found in us-east-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads.

Resolution

No action required. If Bedrock-calling Lambda functions exist, ensure their function name, ARN, description, handler, role, or environment variables contain a Bedrock identifier that the assessment can detect, or evaluate Inspector coverage manually.

Reference

Informational N/A
777788889999 us-east-2 AG-07
Agentic AI Model Invocation Logging
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging

Resolution

Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements.

Reference

Informational N/A
777788889999 us-east-2 AG-08
Agentic AI API Audit Trail
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage

Resolution

Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured.

Reference

Informational N/A
777788889999 us-east-2 AG-10
Agentic AI Adversarial Evaluation Coverage
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs

Resolution

Configure model or application evaluations that include adversarial, safety, and security-relevant test cases.

Reference

Informational N/A
777788889999 us-east-2 AG-11
Agentic AI Prompt Flow Validation
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region

Resolution

Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions.

Reference

Informational N/A
777788889999 us-east-2 AG-06
Agentic AI Tool Execution Least Privilege
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region

Resolution

Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required.

Reference

Informational N/A
777788889999 us-east-2 AG-12
Agentic AI Invocation Abuse Controls
Details and remediation
Details

Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas

Resolution

Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns.

Reference

Informational N/A
777788889999 us-east-2 AG-02
Agentic AI Harmful Content Guardrail Coverage
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: No Bedrock guardrails configured in this region

Resolution

Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads.

Reference

Informational N/A
777788889999 us-east-2 AG-04
Agentic AI Automated Reasoning Guardrails
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: No Bedrock guardrails configured in this region

Resolution

Configure automated reasoning policies on guardrails where formal response validation is required.

Reference

Informational N/A
777788889999 us-east-2 AG-03
Agentic AI Sensitive Information Protection
Details and remediation
Details

Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: No Bedrock guardrails configured in this region

Resolution

Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns.

Reference

Informational N/A
777788889999 us-east-2 AG-05
Agentic AI Grounding Controls
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows.

Reference

Informational N/A
777788889999 us-east-2 AG-01
Agentic AI Agent Guardrail Association
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region

Resolution

Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating.

Reference

Informational N/A
777788889999 us-east-2 AG-13
Agentic AI Session Boundary
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region

Resolution

Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements.

Reference

Informational N/A
777788889999 us-east-2 AG-14
Agentic AI Operational Abuse Alarms
Details and remediation
Details

Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms

Resolution

Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available.

Reference

Informational N/A
777788889999 us-east-2 AC-01
AgentCore VPC Configuration Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 AC-04
AgentCore Observability Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 AC-05
AgentCore Encryption Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 AC-06
AgentCore Browser Tool Recording Check
Details and remediation
Details

No AgentCore Runtimes found to check browser tool configuration

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 AC-07
AgentCore Memory Configuration Check
Details and remediation
Details

No Memory resources found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 AC-13
AgentCore Gateway Configuration Check
Details and remediation
Details

No Gateway resources found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 AC-08
AgentCore VPC Endpoints Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 AC-10
AgentCore Resource-Based Policies Check
Details and remediation
Details

No AgentCore resources found to check for resource-based policies

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 AC-11
AgentCore Policy Engine Encryption Check
Details and remediation
Details

No Policy Engines found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 AC-12
AgentCore Gateway Encryption Check
Details and remediation
Details

No Gateways found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 AG-24
Agentic AI Gateway Inbound Authorization
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 AG-25
Agentic AI Gateway Tool Policy Enforcement
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 AG-26
Agentic AI Gateway Error Detail Exposure
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 AG-27
Agentic AI Gateway WAF Protection
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 AG-15
Agentic AI Runtime Network Boundary
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found

Resolution

Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services.

Reference

Informational N/A
777788889999 us-east-2 AG-18
Agentic AI AgentCore Observability
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found

Resolution

Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported.

Reference

Informational N/A
777788889999 us-east-2 AG-19
Agentic AI Memory Data Protection
Details and remediation
Details

Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found

Resolution

Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions.

Reference

Informational N/A
777788889999 us-east-2 AG-20
Agentic AI Private AgentCore Connectivity
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found

Resolution

Create required VPC endpoints for AgentCore services and validate endpoint availability.

Reference

Informational N/A
777788889999 us-east-2 AG-21
Agentic AI Resource Policy Boundary
Details and remediation
Details

Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies

Resolution

Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources.

Reference

Informational N/A
777788889999 us-east-2 AG-22
Agentic AI Policy Engine Data Protection
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found

Resolution

Configure policy engines with customer-managed KMS keys where enhanced key control is required.

Reference

Informational N/A
777788889999 us-east-2 AG-23
Agentic AI Gateway Data Protection
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found

Resolution

Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required.

Reference

Informational N/A
777788889999 us-west-2 OW-01
OWASP LLM01: Model Invocation Logging
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging

Resolution

Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis.

Reference

Informational N/A
777788889999 us-west-2 OW-07
OWASP LLM07: Model Invocation Logging
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging

Resolution

Enable Bedrock model invocation logging so prompt-extraction attempts against the system prompt are auditable after the fact.

Reference

Informational N/A
777788889999 us-west-2 OW-07
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses.

Resolution

Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident.

Reference

Informational N/A
777788889999 us-west-2 OW-07
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-16: No Bedrock guardrails configured in this region

Resolution

Set guardrail contentPolicy.tier.tierName to STANDARD; Standard tier additionally detects prompt-leakage attacks.

Reference

Informational N/A
777788889999 us-west-2 OW-09
OWASP LLM09: Model Evaluation Jobs
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs

Resolution

Run Bedrock model evaluation jobs that include correctness and safety datasets.

Reference

Informational N/A
777788889999 us-west-2 OW-08
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: No Bedrock knowledge bases found in this region

Resolution

Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption.

Reference

Informational N/A
777788889999 us-west-2 OW-06
OWASP LLM06: Agent Action-Group Least Privilege
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-21: No Bedrock agents configured in this region

Resolution

Restrict agent action-group Lambda roles to only the specific actions and resources needed for each tool.

Reference

Informational N/A
777788889999 us-west-2 OW-10
OWASP LLM10: Service Quota Throttling Limits
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas

Resolution

Customise Bedrock TPM / RPM service quotas above the account default to establish an explicit consumption ceiling.

Reference

Informational N/A
777788889999 us-west-2 OW-01
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: No Bedrock guardrails configured in this region

Resolution

Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier.

Reference

Informational N/A
777788889999 us-west-2 OW-04
OWASP LLM04: RAG Evaluation Coverage
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: No Bedrock knowledge bases found in this region

Resolution

Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context.

Reference

Informational N/A
777788889999 us-west-2 OW-09
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-25: No Bedrock knowledge bases found in this region

Resolution

Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates.

Reference

Informational N/A
777788889999 us-west-2 OW-02
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check BR-26: No Bedrock guardrails configured in this region

Resolution

Configure guardrail sensitiveInformationPolicy with PII entities and regex patterns; set outputAction=ANONYMIZE or BLOCK.

Reference

Informational N/A
777788889999 us-west-2 OW-01
OWASP LLM01: Contextual Grounding Guardrail
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Enable Bedrock guardrail contextual grounding checks to reduce the surface for indirect prompt injection through retrieved context.

Reference

Informational N/A
777788889999 us-west-2 OW-04
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Enable contextual grounding guardrail filters so retrieved context that diverges from ground truth is filtered before reaching the model.

Reference

Informational N/A
777788889999 us-west-2 OW-09
OWASP LLM09: Contextual Grounding for Faithfulness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Set the contextual grounding filter threshold to at least 0.70 to reduce hallucinated responses.

Reference

Informational N/A
777788889999 us-west-2 OW-06
OWASP LLM06: Bedrock Agent Guardrail Association
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-28: No Bedrock agents configured in this region

Resolution

Attach an approved Bedrock guardrail to every Bedrock agent so autonomous actions are filtered consistently.

Reference

Informational N/A
777788889999 us-west-2 OW-06
OWASP LLM06: Agent Idle Session TTL
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-29: No Bedrock agents configured in this region

Resolution

Set idleSessionTTLInSeconds to a conservative value (e.g., <= 3600) so long-lived agent sessions cannot be reused.

Reference

Informational N/A
777788889999 us-west-2 OW-03
OWASP LLM03: Imported-Model KMS Provenance
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check BR-30: No imported custom Bedrock models found in this region

Resolution

Encrypt imported Bedrock models with a customer-managed KMS key to preserve provenance and access control across model artefacts.

Reference

Informational N/A
777788889999 us-west-2 OW-10
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms

Resolution

Create CloudWatch alarms on Bedrock InvocationThrottles, InputTokenCount, OutputTokenCount, and EstimatedTPMQuotaUsage.

Reference

Informational N/A
777788889999 us-west-2 OW-03
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check BR-33: No Lambda functions with Bedrock indicators were found in us-west-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads.

Resolution

Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain.

Reference

Informational N/A
777788889999 us-west-2 OW-03
OWASP LLM03: SageMaker Internet Exposure
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-01: No SageMaker notebook instances or domains found to check

Resolution

Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths.

Reference

Informational N/A
777788889999 us-west-2 OW-02
OWASP LLM02: SageMaker Data Encryption
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: No SageMaker resources found to check for data protection

Resolution

Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data.

Reference

Informational N/A
777788889999 us-west-2 OW-09
OWASP LLM09: SageMaker Clarify Evaluation
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-06: No SageMaker Clarify jobs found

Resolution

Use SageMaker Clarify to evaluate bias and explainability for models whose generated outputs can influence user decisions.

Reference

Informational N/A
777788889999 us-west-2 OW-04
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-07: No Model Monitor schedules found

Resolution

Configure active SageMaker Model Monitor schedules so data-quality and model-quality regressions caused by poisoned inputs or drift are detected.

Reference

Informational N/A
777788889999 us-west-2 OW-09
OWASP LLM09: SageMaker Model Monitor Coverage
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-07: No Model Monitor schedules found

Resolution

Configure SageMaker Model Monitor schedules for production models so quality regressions that can produce incorrect outputs are detected.

Reference

Informational N/A
777788889999 us-west-2 OW-03
OWASP LLM03: SageMaker Notebook VPC Deployment
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-10: No notebook instances found

Resolution

Deploy SageMaker notebook instances inside a VPC so package, data, and model artifact access can be controlled through private network paths.

Reference

Informational N/A
777788889999 us-west-2 OW-03
OWASP LLM03: SageMaker Model Network Isolation
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-11: No models found

Resolution

Enable network isolation on SageMaker models so inference containers cannot make unmanaged outbound calls that alter dependencies or exfiltrate model artifacts.

Reference

Informational N/A
777788889999 us-west-2 OW-10
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check SM-11: No models found

Resolution

Enable SageMaker model network isolation to prevent deployed model containers from making uncontrolled outbound calls that can amplify consumption or abuse downstream services.

Reference

Informational N/A
777788889999 us-west-2 OW-03
OWASP LLM03: SageMaker Container Repository Access
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-14: No models found or all use default Platform access

Resolution

Configure SageMaker models to pull container images from private ECR repositories through VPC repository access instead of platform or public registry paths.

Reference

Informational N/A
777788889999 us-west-2 OW-02
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-15: No feature groups with offline stores found

Resolution

Encrypt SageMaker Feature Store offline stores with customer-managed KMS keys so sensitive feature data is protected at rest.

Reference

Informational N/A
777788889999 us-west-2 OW-03
OWASP LLM03: SageMaker AutoML Network Isolation
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-21: No AutoML jobs found

Resolution

Enable network isolation on AutoML jobs so generated training containers cannot fetch unapproved dependencies or send data over unmanaged network paths.

Reference

Informational N/A
777788889999 us-west-2 OW-04
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance.

Resolution

Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically.

Reference

Informational N/A
777788889999 us-west-2 OW-09
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance.

Resolution

Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release.

Reference

Informational N/A
777788889999 us-west-2 OW-04
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-23: No InService endpoints found to monitor.

Resolution

Enable SageMaker Model Monitor drift detection for production endpoints so poisoning, data drift, and model-quality degradation are identified.

Reference

Medium Passed
777788889999 us-west-2 OW-09
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-23: No InService endpoints found to monitor.

Resolution

Configure data-quality and model-quality monitoring for SageMaker endpoints so degraded model behavior that can produce misinformation is detected.

Reference

Medium Passed
777788889999 us-west-2 OW-03
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain.

Reference

Informational N/A
777788889999 us-west-2 OW-04
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated.

Reference

Informational N/A
777788889999 us-west-2 OW-06
OWASP LLM06: AgentCore Resource-Based Policies
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check AC-10: No AgentCore resources found to check for resource-based policies

Resolution

Attach resource-based policies to AgentCore runtimes and gateways so caller identities are constrained.

Reference

Informational N/A
777788889999 us-west-2 OW-11
OWASP LLM07: System Prompt Embedded in Lambda Env Var
Details and remediation
Details

No Lambda function env vars in us-west-2 match the embedded-system-prompt heuristic (>= 200 chars containing prompt-shaped tokens).

Resolution

No action required.

Reference

Medium Passed
777788889999 us-west-2 OW-12
OWASP LLM07: System-Prompt-Disclosure Denied Topic
Details and remediation
Details

No Bedrock guardrails configured in us-west-2; nothing to inspect.

Resolution

No action required.

Reference

Informational N/A
777788889999 eu-west-1 OW-01
OWASP LLM01: Model Invocation Logging
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging

Resolution

Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis.

Reference

Informational N/A
777788889999 eu-west-1 OW-07
OWASP LLM07: Model Invocation Logging
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging

Resolution

Enable Bedrock model invocation logging so prompt-extraction attempts against the system prompt are auditable after the fact.

Reference

Informational N/A
777788889999 eu-west-1 OW-07
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses.

Resolution

Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident.

Reference

Informational N/A
777788889999 eu-west-1 OW-07
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-16: No Bedrock guardrails configured in this region

Resolution

Set guardrail contentPolicy.tier.tierName to STANDARD; Standard tier additionally detects prompt-leakage attacks.

Reference

Informational N/A
777788889999 eu-west-1 OW-09
OWASP LLM09: Model Evaluation Jobs
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs

Resolution

Run Bedrock model evaluation jobs that include correctness and safety datasets.

Reference

Informational N/A
777788889999 eu-west-1 OW-08
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: No Bedrock knowledge bases found in this region

Resolution

Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption.

Reference

Informational N/A
777788889999 eu-west-1 OW-06
OWASP LLM06: Agent Action-Group Least Privilege
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-21: No Bedrock agents configured in this region

Resolution

Restrict agent action-group Lambda roles to only the specific actions and resources needed for each tool.

Reference

Informational N/A
777788889999 eu-west-1 OW-10
OWASP LLM10: Service Quota Throttling Limits
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas

Resolution

Customise Bedrock TPM / RPM service quotas above the account default to establish an explicit consumption ceiling.

Reference

Informational N/A
777788889999 eu-west-1 OW-01
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: No Bedrock guardrails configured in this region

Resolution

Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier.

Reference

Informational N/A
777788889999 eu-west-1 OW-04
OWASP LLM04: RAG Evaluation Coverage
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: No Bedrock knowledge bases found in this region

Resolution

Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context.

Reference

Informational N/A
777788889999 eu-west-1 OW-09
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-25: No Bedrock knowledge bases found in this region

Resolution

Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates.

Reference

Informational N/A
777788889999 eu-west-1 OW-02
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check BR-26: No Bedrock guardrails configured in this region

Resolution

Configure guardrail sensitiveInformationPolicy with PII entities and regex patterns; set outputAction=ANONYMIZE or BLOCK.

Reference

Informational N/A
777788889999 eu-west-1 OW-01
OWASP LLM01: Contextual Grounding Guardrail
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Enable Bedrock guardrail contextual grounding checks to reduce the surface for indirect prompt injection through retrieved context.

Reference

Informational N/A
777788889999 eu-west-1 OW-04
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Enable contextual grounding guardrail filters so retrieved context that diverges from ground truth is filtered before reaching the model.

Reference

Informational N/A
777788889999 eu-west-1 OW-09
OWASP LLM09: Contextual Grounding for Faithfulness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Set the contextual grounding filter threshold to at least 0.70 to reduce hallucinated responses.

Reference

Informational N/A
777788889999 eu-west-1 OW-06
OWASP LLM06: Bedrock Agent Guardrail Association
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-28: No Bedrock agents configured in this region

Resolution

Attach an approved Bedrock guardrail to every Bedrock agent so autonomous actions are filtered consistently.

Reference

Informational N/A
777788889999 eu-west-1 OW-06
OWASP LLM06: Agent Idle Session TTL
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-29: No Bedrock agents configured in this region

Resolution

Set idleSessionTTLInSeconds to a conservative value (e.g., <= 3600) so long-lived agent sessions cannot be reused.

Reference

Informational N/A
777788889999 eu-west-1 OW-03
OWASP LLM03: Imported-Model KMS Provenance
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check BR-30: Unable to check Imported model encryption check: An error occurred (AccessDeniedException) when calling the ListImportedModels operation: Your account is not authorized to invoke this API operation.

Resolution

Encrypt imported Bedrock models with a customer-managed KMS key to preserve provenance and access control across model artefacts.

Reference

Informational N/A
777788889999 eu-west-1 OW-10
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms

Resolution

Create CloudWatch alarms on Bedrock InvocationThrottles, InputTokenCount, OutputTokenCount, and EstimatedTPMQuotaUsage.

Reference

Informational N/A
777788889999 eu-west-1 OW-03
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check BR-33: No Lambda functions with Bedrock indicators were found in eu-west-1; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads.

Resolution

Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain.

Reference

Informational N/A
777788889999 eu-west-1 OW-03
OWASP LLM03: SageMaker Internet Exposure
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-01: No SageMaker notebook instances or domains found to check

Resolution

Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths.

Reference

Informational N/A
777788889999 eu-west-1 OW-02
OWASP LLM02: SageMaker Data Encryption
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: No SageMaker resources found to check for data protection

Resolution

Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data.

Reference

Informational N/A
777788889999 eu-west-1 OW-09
OWASP LLM09: SageMaker Clarify Evaluation
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-06: No SageMaker Clarify jobs found

Resolution

Use SageMaker Clarify to evaluate bias and explainability for models whose generated outputs can influence user decisions.

Reference

Informational N/A
777788889999 eu-west-1 OW-04
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-07: No Model Monitor schedules found

Resolution

Configure active SageMaker Model Monitor schedules so data-quality and model-quality regressions caused by poisoned inputs or drift are detected.

Reference

Informational N/A
777788889999 eu-west-1 OW-09
OWASP LLM09: SageMaker Model Monitor Coverage
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-07: No Model Monitor schedules found

Resolution

Configure SageMaker Model Monitor schedules for production models so quality regressions that can produce incorrect outputs are detected.

Reference

Informational N/A
777788889999 eu-west-1 OW-03
OWASP LLM03: SageMaker Notebook VPC Deployment
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-10: No notebook instances found

Resolution

Deploy SageMaker notebook instances inside a VPC so package, data, and model artifact access can be controlled through private network paths.

Reference

Informational N/A
777788889999 eu-west-1 OW-03
OWASP LLM03: SageMaker Model Network Isolation
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-11: No models found

Resolution

Enable network isolation on SageMaker models so inference containers cannot make unmanaged outbound calls that alter dependencies or exfiltrate model artifacts.

Reference

Informational N/A
777788889999 eu-west-1 OW-10
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check SM-11: No models found

Resolution

Enable SageMaker model network isolation to prevent deployed model containers from making uncontrolled outbound calls that can amplify consumption or abuse downstream services.

Reference

Informational N/A
777788889999 eu-west-1 OW-03
OWASP LLM03: SageMaker Container Repository Access
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-14: No models found or all use default Platform access

Resolution

Configure SageMaker models to pull container images from private ECR repositories through VPC repository access instead of platform or public registry paths.

Reference

Informational N/A
777788889999 eu-west-1 OW-02
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-15: No feature groups with offline stores found

Resolution

Encrypt SageMaker Feature Store offline stores with customer-managed KMS keys so sensitive feature data is protected at rest.

Reference

Informational N/A
777788889999 eu-west-1 OW-03
OWASP LLM03: SageMaker AutoML Network Isolation
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-21: No AutoML jobs found

Resolution

Enable network isolation on AutoML jobs so generated training containers cannot fetch unapproved dependencies or send data over unmanaged network paths.

Reference

Informational N/A
777788889999 eu-west-1 OW-04
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance.

Resolution

Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically.

Reference

Informational N/A
777788889999 eu-west-1 OW-09
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance.

Resolution

Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release.

Reference

Informational N/A
777788889999 eu-west-1 OW-04
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-23: No InService endpoints found to monitor.

Resolution

Enable SageMaker Model Monitor drift detection for production endpoints so poisoning, data drift, and model-quality degradation are identified.

Reference

Medium Passed
777788889999 eu-west-1 OW-09
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-23: No InService endpoints found to monitor.

Resolution

Configure data-quality and model-quality monitoring for SageMaker endpoints so degraded model behavior that can produce misinformation is detected.

Reference

Medium Passed
777788889999 eu-west-1 OW-03
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain.

Reference

Informational N/A
777788889999 eu-west-1 OW-04
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated.

Reference

Informational N/A
777788889999 eu-west-1 OW-06
OWASP LLM06: AgentCore Resource-Based Policies
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check AC-10: No AgentCore resources found to check for resource-based policies

Resolution

Attach resource-based policies to AgentCore runtimes and gateways so caller identities are constrained.

Reference

Informational N/A
777788889999 eu-west-1 OW-11
OWASP LLM07: System Prompt Embedded in Lambda Env Var
Details and remediation
Details

No Lambda function env vars in eu-west-1 match the embedded-system-prompt heuristic (>= 200 chars containing prompt-shaped tokens).

Resolution

No action required.

Reference

Medium Passed
777788889999 eu-west-1 OW-12
OWASP LLM07: System-Prompt-Disclosure Denied Topic
Details and remediation
Details

No Bedrock guardrails configured in eu-west-1; nothing to inspect.

Resolution

No action required.

Reference

Informational N/A
777788889999 us-west-2 AC-01
AgentCore VPC Configuration Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 AC-04
AgentCore Observability Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 AC-05
AgentCore Encryption Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 AC-06
AgentCore Browser Tool Recording Check
Details and remediation
Details

No AgentCore Runtimes found to check browser tool configuration

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 AC-07
AgentCore Memory Configuration Check
Details and remediation
Details

No Memory resources found

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 AC-13
AgentCore Gateway Configuration Check
Details and remediation
Details

No Gateway resources found

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 AC-08
AgentCore VPC Endpoints Check
Details and remediation
Details

No AgentCore resources found

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 AC-10
AgentCore Resource-Based Policies Check
Details and remediation
Details

No AgentCore resources found to check for resource-based policies

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 AC-11
AgentCore Policy Engine Encryption Check
Details and remediation
Details

No Policy Engines found

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 AC-12
AgentCore Gateway Encryption Check
Details and remediation
Details

No Gateways found

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 AG-24
Agentic AI Gateway Inbound Authorization
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 AG-25
Agentic AI Gateway Tool Policy Enforcement
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 AG-26
Agentic AI Gateway Error Detail Exposure
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 AG-27
Agentic AI Gateway WAF Protection
Details and remediation
Details

No AgentCore Gateways found

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 AG-15
Agentic AI Runtime Network Boundary
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found

Resolution

Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services.

Reference

Informational N/A
777788889999 us-west-2 AG-18
Agentic AI AgentCore Observability
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found

Resolution

Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported.

Reference

Informational N/A
777788889999 us-west-2 AG-19
Agentic AI Memory Data Protection
Details and remediation
Details

Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found

Resolution

Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions.

Reference

Informational N/A
777788889999 us-west-2 AG-20
Agentic AI Private AgentCore Connectivity
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found

Resolution

Create required VPC endpoints for AgentCore services and validate endpoint availability.

Reference

Informational N/A
777788889999 us-west-2 AG-21
Agentic AI Resource Policy Boundary
Details and remediation
Details

Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies

Resolution

Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources.

Reference

Informational N/A
777788889999 us-west-2 AG-22
Agentic AI Policy Engine Data Protection
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found

Resolution

Configure policy engines with customer-managed KMS keys where enhanced key control is required.

Reference

Informational N/A
777788889999 us-west-2 AG-23
Agentic AI Gateway Data Protection
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found

Resolution

Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required.

Reference

Informational N/A
777788889999 us-east-1 FS-01
AWS Shield Advanced Not Enabled
Details and remediation
Details

AWS Shield Advanced is not subscribed. GenAI API endpoints are vulnerable to volumetric DDoS attacks that can exhaust token quotas and inflate costs.

Resolution

1. Subscribe to AWS Shield Advanced for DDoS protection. 2. After subscribing, explicitly add resource protections in the Shield Advanced console for each Bedrock-facing resource (API Gateway stages, ALBs, CloudFront distributions, Route 53 hosted zones). Shield Advanced subscription alone does NOT automatically protect resources — each resource must be individually added to receive protection. 3. Enable Shield Response Team (SRT) access and configure proactive engagement. 4. Alternatively, use AWS Firewall Manager with a Shield Advanced policy to automate resource protection based on tags or resource types.

Reference

Low Failed
777788889999 us-east-1 FS-01
No Regional WAF Web ACLs Found
Details and remediation
Details

No AWS WAF regional Web ACLs found. Without WAF, GenAI endpoints lack rate-based rules to block abusive callers.

Resolution

1. Create a WAF Web ACL with rate-based rules (e.g., 1000 req/5 min per IP). 2. Associate the ACL with API Gateway stages or ALBs fronting Bedrock. 3. Add AWS Managed Rules for known bad inputs.

Reference

Medium Failed
777788889999 us-east-1 FS-02
No API Gateway Usage Plans Found
Details and remediation
Details

No usage plans configured. GenAI API endpoints may have no rate limits.

Resolution

Create API Gateway usage plans with throttle settings (rateLimit and burstLimit) for all Bedrock-facing APIs.

Reference

Informational N/A
777788889999 us-east-1 FS-03
Bedrock Token Quotas Customized
Details and remediation
Details

Found 240 Bedrock token-based quota(s); at least one applied value exceeds the AWS default, indicating quotas have been reviewed and raised.

Resolution

No action required. Periodically re-review quotas against expected peak load.

Reference

Medium Passed
777788889999 us-east-1 FS-04
No Cost Anomaly Detection Monitors
Details and remediation
Details

No AWS Cost Anomaly Detection monitors found. Unexpected spikes in Bedrock/SageMaker usage (e.g., from prompt injection loops) will go undetected.

Resolution

1. Create a Cost Anomaly Detection monitor scoped to AWS/Bedrock and AWS/SageMaker. 2. Configure alert subscriptions (SNS/email) for anomalies above threshold. 3. Set daily spend budgets with AWS Budgets as a secondary control.

Reference

Medium Failed
777788889999 us-east-1 FS-05
No Bedrock CloudWatch Alarms Found
Details and remediation
Details

No CloudWatch alarms found for Bedrock metrics. Token exhaustion and throttling events will not trigger operational alerts.

Resolution

Create CloudWatch alarms for: - AWS/Bedrock InvocationThrottles (threshold > 0) - AWS/Bedrock TokensProcessed (threshold based on quota) - Custom application-level token counters via EMF

Reference

Medium Failed
777788889999 us-east-1 FS-06
No AI/ML Service Budgets Configured
Details and remediation
Details

No AWS Budgets found scoped to Bedrock or SageMaker. Unbounded GenAI spend can go undetected until the monthly bill.

Resolution

1. Create cost budgets for AWS Bedrock and SageMaker with 80%/100% alert thresholds. 2. Add SNS notifications to on-call channels. 3. Consider budget actions to apply IAM deny policies when thresholds are breached.

Reference

Medium Failed
777788889999 us-east-1 FS-07
Agent Action Boundaries Look Appropriate
Details and remediation
Details

Reviewed 1 agent(s); no wildcard sensitive actions found.

Resolution

No action required.

Reference

High Passed
777788889999 us-east-1 FS-08
No AgentCore Runtimes Found
Details and remediation
Details

No AgentCore runtimes found; policy engine check not applicable.

Resolution

If using AgentCore, configure the Policy Engine to authorize tool calls.

Reference

Informational N/A
777788889999 us-east-1 FS-09
Agent Lambda Functions Without Concurrency Limits
Details and remediation
Details

Agent-related Lambda functions without reserved concurrency: aiml-security-aiml-security-mgmt-FinServAssessment, aiml-sec-test-resources-SageMakerJobCustomResource-ZA5QCAi0pN3d, AIMLSecurityAssessment-CodeBuildStartBuildLambda-VYOqtzWoNo3m, aiml-security-aiml-security-mgmt-CleanupBucket, aiml-security-aiml-security-mgmt-SagemakerAssessment, aiml-security-aiml-security-mgmt-GenerateReport, aiml-security-aiml-security-mgmt-OWASPAssessment, aiml-security-aiml-security-mgmt-IAMPermissionCaching, aiml-security-aiml-security-mgmt-AgentCoreAssessment, aiml-security-aiml-security-mgmt-BedrockAssessment. Unlimited concurrency allows runaway agent loops to exhaust account limits.

Resolution

1. Set reserved concurrency on agent Lambda functions. 2. Implement maximum iteration counts in agent orchestration logic. 3. Use Step Functions with MaxConcurrency and timeout states. 4. Add circuit-breaker patterns to agent tool invocations.

Reference

Medium Failed
777788889999 us-east-1 FS-10
Human-in-the-Loop Check — No Agent Workflows Found
Details and remediation
Details

No Step Functions state machines with agent/approval naming found. Verify that high-risk agent actions (e.g., fund transfers, account changes) have human approval gates.

Resolution

Implement Step Functions .waitForTaskToken patterns for high-risk agent actions. Route approval requests to human reviewers via SNS/SES/Slack.

Reference

Informational N/A
777788889999 us-east-1 FS-11
No Agent Rate Alarms Found
Details and remediation
Details

No CloudWatch alarms found for agent invocation rates. Looping or runaway agents will not trigger operational alerts.

Resolution

Create CloudWatch alarms on: - Bedrock agent invocation counts (threshold based on expected max) - Lambda invocation errors for agent functions - Step Functions execution failures and timeouts

Reference

Medium Failed
777788889999 us-east-1 FS-12
No Bedrock-Scoped SCPs Found
Details and remediation
Details

No Service Control Policies reference Bedrock. Without SCPs, any account in the organization can access any Bedrock model, including unapproved third-party models.

Resolution

1. Create an SCP that denies bedrock:InvokeModel for model IDs not on the approved list. 2. Use bedrock:ModelId condition key to allowlist approved models. 3. Maintain a model inventory and update the SCP when models are approved/retired.

Reference

High Failed
777788889999 us-east-1 FS-13
Models Missing Provenance Tags
Details and remediation
Details

2 model(s) missing required provenance tags: - SageMaker model 'SageMakerModelWithIsolation-JASFpUHjajdk' missing tags: {'approval-date', 'source', 'version'} - SageMaker model 'SageMakerModelNoIsolation-yQ7EpJeL7pgI' missing tags: {'approval-date', 'source', 'version'}

Resolution

Tag all models with: source (e.g., 'aws-marketplace', 'internal'), version, and approval-date. Enforce tagging via SCP or AWS Config rule.

Reference

Medium Failed
777788889999 us-east-1 FS-14
Model Governance Config Rules Present
Details and remediation
Details

Found 13 model-related Config rule(s).

Resolution

No action required.

Reference

Medium Passed
777788889999 us-east-1 FS-15
No Bedrock Evaluation Jobs Found
Details and remediation
Details

No Bedrock Model Evaluation jobs found. Models have not been evaluated for adversarial robustness. FinServ model-risk management (SR 11-7) expects documented model validation/evaluation.

Resolution

1. Run Bedrock Model Evaluation with adversarial/red-team datasets. 2. Use FMEval library for automated robustness testing. 3. Schedule periodic re-evaluation after model updates.

Reference

Medium Failed
777788889999 us-east-1 FS-16
ECR Repositories Without Image Scanning
Details and remediation
Details

2 ECR repo(s) without scan-on-push: cdk-hnb659fds-container-assets-777788889999-us-east-1, aiml-sec-test-agentcore-no-encryption.

Resolution

Enable scan-on-push for all ECR repositories containing model containers. Consider enabling Enhanced Scanning (Inspector) for CVE detection.

Reference

High Failed
777788889999 us-east-1 FS-20
Feature Groups Without Offline Store
Details and remediation
Details

1 feature group(s) lack an active offline store: aiml-sec-test-feature-group. Without offline store, historical feature data cannot be used for rollback.

Resolution

1. Enable offline store (S3-backed) for all production feature groups. 2. Enable S3 versioning on the offline store bucket. 3. Document rollback procedures for poisoned feature data.

Reference

Medium Failed
777788889999 us-east-1 FS-21
Training Data Buckets Have Versioning
Details and remediation
Details

All 2 training bucket(s) have versioning enabled.

Resolution

No action required.

Reference

High Passed
777788889999 us-east-1 FS-22
Overly Permissive Knowledge Base IAM Roles
Details and remediation
Details

825 role(s) with wildcard KB permissions: - Role 'Admin' allows '*' - Role 'aiml-sec-test-resources-BedrockAgentRole-RScmoTZfp2sC' allows 'bedrock:InvokeModel' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-test-resources-BedrockAgentRole-RScmoTZfp2sC' allows 'bedrock:InvokeModelWithResponseStream' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-test-resources-BedrockAgentRoleWithoutGuar-Z3kN5ANhP89G' allows 'bedrock:InvokeModel' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-test-resources-BedrockAgentRoleWithoutGuar-Z3kN5ANhP89G' allows 'bedrock:InvokeModelWithResponseStream' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-test-resources-BedrockFullAccessRole-zAFkGLkWQ61a' allows 'bedrock:*' - Role 'aiml-security-mgmt-BedrockSecurityAssessmentFunctio-a7GKJ6O4151K' allows 'bedrock:ListGuardrails' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-mgmt-BedrockSecurityAssessmentFunctio-a7GKJ6O4151K' allows 'bedrock:GetGuardrail' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-mgmt-BedrockSecurityAssessmentFunctio-a7GKJ6O4151K' allows 'bedrock:ListModelInvocationJobs' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-security-mgmt-BedrockSecurityAssessmentFunctio-a7GKJ6O4151K' allows 'bedrock:GetModelInvocationLoggingConfiguration' on Resource '*' (no ARN scoping to specific Knowledge Bases)

Resolution

Replace wildcard bedrock:* with specific actions such as bedrock:Retrieve, bedrock:RetrieveAndGenerate. Scope resources to specific Knowledge Base ARNs.

Reference

High Failed
777788889999 us-east-1 FS-24
ADVISORY: Knowledge Base Metadata Filtering — Manual Review Required
Details and remediation
Details

Found 1 Knowledge Base(s). Tenant-isolation metadata filtering is a design pattern that cannot be verified via API — manual review required. Verify that metadata attributes (e.g., tenantId, classification) are indexed and that Retrieve calls include RetrievalFilter conditions for tenant isolation.

Resolution

1. Add metadata fields (tenantId, dataClassification) to KB data sources. 2. Pass RetrievalFilter in all Retrieve/RetrieveAndGenerate calls. 3. Validate filters in integration tests to prevent cross-tenant data leakage.

Reference

Informational N/A
777788889999 us-east-1 FS-25
OpenSearch Serverless Encryption Policies Present
Details and remediation
Details

Found 1 encryption policy(ies); 1 use a customer-managed KMS key.

Resolution

Verify all vector store collections use customer-managed KMS keys.

Reference

High Passed
777788889999 us-east-1 FS-26
OpenSearch Serverless Collections Not VPC-Restricted
Details and remediation
Details

Found 1 network policy(ies) but none restrict to VPC. Vector stores may be accessible from the public internet.

Resolution

Update network policies to allow access only from VPC endpoints. Create an OpenSearch Serverless VPC endpoint in your VPC.

Reference

High Failed
777788889999 us-east-1 FS-27
COULD NOT ASSESS: Guardrail Contextual Grounding Check
Details and remediation
Details

This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved.

Resolution

1. Confirm the assessment role grants the actions this check requires (see the documented IAM permission set in the README). 2. Confirm the service/feature is supported in the assessed region. 3. Ensure botocore meets the version floor in requirements.txt. 4. Re-run the assessment; assess this control manually until it succeeds.

Reference

Low N/A
777788889999 us-east-1 FS-27
No Automated Reasoning Policies Found
Details and remediation
Details

No Bedrock Automated Reasoning policies have been created. ARC (GA August 2025) uses formal verification to guarantee that GenAI outputs comply with authored business rules — e.g., loan criteria, regulatory thresholds, policy constraints. Without ARC policies, factual accuracy of outputs is not formally verified, only heuristically filtered by contextual grounding thresholds.

Resolution

1. In the Amazon Bedrock console → Guardrails → Automated Reasoning, create a policy document encoding your FinServ business rules (e.g., eligibility criteria, rate limits, regulatory thresholds). 2. Associate the ARC policy with your guardrail (automatedReasoningPolicy.policies field in CreateGuardrail/UpdateGuardrail). 3. Set confidenceThreshold on the policy to control strictness. 4. ARC requires cross-Region inference — ensure your guardrail has a guardrailProfileArn configured (crossRegionDetails in GetGuardrail response). 5. Reference: AWS Announcement — Automated Reasoning checks GA (August 2025).

Reference

Medium Failed
777788889999 us-east-1 FS-28
COULD NOT ASSESS: Financial Denied Topics Check
Details and remediation
Details

This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved.

Resolution

1. Confirm the assessment role grants the actions this check requires (see the documented IAM permission set in the README). 2. Confirm the service/feature is supported in the assessed region. 3. Ensure botocore meets the version floor in requirements.txt. 4. Re-run the assessment; assess this control manually until it succeeds.

Reference

Low N/A
777788889999 us-east-1 FS-29
ADVISORY: Compliance Disclaimer — Manual Review Required
Details and remediation
Details

Application-level compliance disclaimers cannot be verified via AWS APIs. Manual review required to confirm GenAI outputs include required regulatory disclosures.

Resolution

1. Implement post-processing to append required disclaimers to GenAI outputs. 2. Use Bedrock Guardrails word filters to block outputs that omit required disclosures. 3. Document disclaimer requirements in the AI use case register. 4. Test disclaimer presence in QA/UAT before production deployment.

Reference

Informational N/A
777788889999 us-east-1 FS-30
ADVISORY: Compliance Dataset Coverage — Manual Review Required
Details and remediation
Details

Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation jobs include compliance-specific datasets (fair lending/ECOA, Fair Housing Act, UDAP/UDAAP, AML/KYC edge cases). Whether any evaluation jobs exist at all is assessed by FS-15.

Resolution

Run Bedrock Model Evaluation with compliance-specific datasets: - Fair lending test cases (ECOA, Fair Housing Act) - UDAP/UDAAP unfair/deceptive practice scenarios - AML/KYC edge cases

Reference

Informational N/A
777788889999 us-east-1 FS-31
Knowledge Base Data Sources Past Review Threshold
Details and remediation
Details

1 data source(s) not synced in >7 days (a configurable review threshold, NOT an AWS-mandated limit): - KB 'knowledge-base-prowler-findings' source 'knowledge-base-quick-start-9lb68-data-source' last synced 432 days ago Confirm this age is acceptable for each data source's currency requirement — slow-changing reference data may legitimately sync infrequently.

Resolution

1. Define the maximum acceptable data age per use case (e.g., intraday for market data, daily for product terms, weekly/monthly for regulatory guidance) and adjust the review threshold to match. 2. Configure automated sync (EventBridge Scheduler → StartIngestionJob) at that cadence — see FS-61. 3. Set CloudWatch alarms on sync job failures.

Reference

Medium Failed
777788889999 us-east-1 FS-32
ADVISORY: Source Attribution — Manual Review Required
Details and remediation
Details

Source attribution in GenAI responses cannot be verified via AWS APIs. Manual review required to confirm responses include citations.

Resolution

1. Use Bedrock RetrieveAndGenerate with citations enabled. 2. Include source document references in response post-processing. 3. Test citation accuracy in QA before production deployment. 4. Consider Bedrock Guardrails grounding checks to validate response accuracy.

Reference

Informational N/A
777788889999 us-east-1 FS-33
KB Data Source Buckets Have Versioning
Details and remediation
Details

All reviewed KB data source buckets have versioning enabled.

Resolution

No action required.

Reference

Medium Passed
777788889999 us-east-1 FS-34
Legacy Foundation Models Available in Region
Details and remediation
Details

Legacy/deprecated foundation models are available in this account/region: anthropic.claude-sonnet-4-20250514-v1:0, twelvelabs.marengo-embed-2-7-v1:0, anthropic.claude-opus-4-1-20250805-v1:0, amazon.nova-premier-v1:0:8k, amazon.nova-premier-v1:0:20k, amazon.nova-premier-v1:0:1000k, amazon.nova-premier-v1:0:mm, amazon.nova-premier-v1:0, amazon.nova-canvas-v1:0, amazon.nova-reel-v1:0. This API reports model *availability*, not actual usage — it cannot determine which models your applications invoke. Legacy models have older training-data cutoffs and may produce outdated information if used. Review whether any are in active use.

Resolution

1. Identify which (if any) of these legacy models your applications invoke (e.g., via CloudTrail InvokeModel events or application config). 2. Migrate active usage to current model versions. 3. Document training-data cutoff dates for all models in use. 4. Add data-currency disclaimers to outputs from models with old cutoffs.

Reference

Informational N/A
777788889999 us-east-1 FS-35
ADVISORY: Harmful-Content Test Coverage — Manual Review Required
Details and remediation
Details

Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation/FMEval jobs include harmful-content datasets (toxicity, hate speech, violence/self-harm). Whether any evaluation jobs exist at all is assessed by FS-15.

Resolution

Run Bedrock Model Evaluation or FMEval with harmful content datasets: - Toxicity detection - Hate speech classification - Violence/self-harm content

Reference

Informational N/A
777788889999 us-east-1 FS-36
COULD NOT ASSESS: Guardrail Content Filters Check
Details and remediation
Details

This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved.

Resolution

1. Confirm the assessment role grants the actions this check requires (see the documented IAM permission set in the README). 2. Confirm the service/feature is supported in the assessed region. 3. Ensure botocore meets the version floor in requirements.txt. 4. Re-run the assessment; assess this control manually until it succeeds.

Reference

Low N/A
777788889999 us-east-1 FS-37
ADVISORY: User Feedback Mechanism — Manual Review Required
Details and remediation
Details

User feedback mechanisms for harmful outputs cannot be verified via AWS APIs. Manual review required.

Resolution

1. Implement thumbs-up/down or flag-for-review UI in GenAI applications. 2. Route flagged outputs to human reviewers via SQS/SNS. 3. Log feedback to DynamoDB/S3 for model improvement. 4. Define SLAs for reviewing flagged content.

Reference

Informational N/A
777788889999 us-east-1 FS-38
COULD NOT ASSESS: Guardrail Word Filters Check
Details and remediation
Details

This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved.

Resolution

1. Confirm the assessment role grants the actions this check requires (see the documented IAM permission set in the README). 2. Confirm the service/feature is supported in the assessed region. 3. Ensure botocore meets the version floor in requirements.txt. 4. Re-run the assessment; assess this control manually until it succeeds.

Reference

Low N/A
777788889999 us-east-1 FS-39
No SageMaker Clarify Bias Monitoring
Details and remediation
Details

No SageMaker Clarify model bias monitoring schedules found. Models making financial decisions (credit, insurance) may exhibit discriminatory bias without detection.

Resolution

1. Configure SageMaker Clarify bias detection for all models making credit, insurance, or employment decisions. 2. Define protected attributes (age, gender, race proxies). 3. Set bias metric thresholds and alert on violations. 4. Document bias testing results for regulatory examination.

Reference

High Failed
777788889999 us-east-1 FS-40
ADVISORY: Bias Dataset Coverage — Manual Review Required
Details and remediation
Details

Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation jobs include bias/fairness datasets (demographic parity, equal-opportunity, counterfactual fairness) for any GenAI models used in financial decisions (ECOA/Fair Housing). Whether any evaluation jobs exist at all is assessed by FS-15.

Resolution

Run Bedrock Model Evaluation with bias test datasets: - Demographic parity test cases - Equal opportunity scenarios - Counterfactual fairness tests

Reference

Informational N/A
777788889999 us-east-1 FS-41
No SageMaker Clarify Explainability Monitoring
Details and remediation
Details

No SageMaker Clarify explainability monitoring found. Models making adverse financial decisions may not provide required explanations (ECOA adverse action notices).

Resolution

1. Configure SageMaker Clarify explainability for credit/lending models. 2. Generate SHAP values for feature importance. 3. Map top features to human-readable adverse action reason codes. 4. Store explanations for regulatory examination.

Reference

High Failed
777788889999 us-east-1 FS-42
No SageMaker Model Cards Found
Details and remediation
Details

No SageMaker Model Cards found. Production AI models lack documented intended use, limitations, and bias evaluations.

Resolution

1. Create SageMaker Model Cards for all production models. 2. Document: intended use, out-of-scope uses, training data, bias evaluations. 3. Include regulatory compliance attestations. 4. Review and update cards at each model version release.

Reference

Medium Failed
777788889999 us-east-1 FS-43
No CloudWatch Logs Data Protection Policies
Details and remediation
Details

No CloudWatch Logs data protection policies found. PII (SSN, account numbers, credit card numbers) in Bedrock invocation logs may be stored in plaintext.

Resolution

1. Create CloudWatch Logs data protection policies to mask PII. 2. Enable masking for: SSN, credit card numbers, bank account numbers, email. 3. Apply policies to Bedrock invocation log groups. 4. Test masking with synthetic PII before production deployment.

Reference

High Failed
777788889999 us-east-1 FS-44
Amazon Macie Not Enabled
Details and remediation
Details

Amazon Macie is not enabled. S3 buckets containing training data and KB data sources are not being scanned for PII/sensitive data.

Resolution

1. Enable Amazon Macie in all regions where AI/ML data is stored. 2. Create Macie classification jobs for training data and KB buckets. 3. Configure Macie findings to route to Security Hub and SNS. 4. Remediate PII findings before using data for model training.

Reference

High Failed
777788889999 us-east-1 FS-45
COULD NOT ASSESS: Guardrail PII Filters Check
Details and remediation
Details

This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved.

Resolution

1. Confirm the assessment role grants the actions this check requires (see the documented IAM permission set in the README). 2. Confirm the service/feature is supported in the assessed region. 3. Ensure botocore meets the version floor in requirements.txt. 4. Re-run the assessment; assess this control manually until it succeeds.

Reference

Low N/A
777788889999 us-east-1 FS-46
AI/ML Buckets Without Data Classification Tags
Details and remediation
Details

3 AI/ML bucket(s) without data-classification tags: aiml-sec-test-resources-bedrockloggingbucket-wtuvpinrlpmd, aiml-sec-test-resources-sagemakerbucket-6zzmxxaxco6g, aiml-security-mgmt-aimlassessmentbucket-kbitsdgexylv.

Resolution

Tag all AI/ML data buckets with 'data-classification' key. Values: Public, Internal, Confidential, Restricted. Enforce via SCP or AWS Config rule.

Reference

Medium Failed
777788889999 us-east-1 FS-47
COULD NOT ASSESS: Guardrail Grounding Threshold Check
Details and remediation
Details

This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved.

Resolution

1. Confirm the assessment role grants the actions this check requires (see the documented IAM permission set in the README). 2. Confirm the service/feature is supported in the assessed region. 3. Ensure botocore meets the version floor in requirements.txt. 4. Re-run the assessment; assess this control manually until it succeeds.

Reference

Low N/A
777788889999 us-east-1 FS-48
Active Knowledge Bases for RAG Present
Details and remediation
Details

Found 1 active Knowledge Base(s) for RAG grounding.

Resolution

No action required.

Reference

Medium Passed
777788889999 us-east-1 FS-49
ADVISORY: Hallucination Disclaimer — Manual Review Required
Details and remediation
Details

Application-level hallucination disclaimers cannot be verified via AWS APIs. Manual review required.

Resolution

1. Add disclaimers to GenAI outputs: 'AI-generated content may contain errors. Verify with authoritative sources before acting.' 2. Implement post-processing to append disclaimers. 3. Test disclaimer presence in QA before production.

Reference

Informational N/A
777788889999 us-east-1 FS-50
COULD NOT ASSESS: Guardrail Relevance Grounding Check
Details and remediation
Details

This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved.

Resolution

1. Confirm the assessment role grants the actions this check requires (see the documented IAM permission set in the README). 2. Confirm the service/feature is supported in the assessed region. 3. Ensure botocore meets the version floor in requirements.txt. 4. Re-run the assessment; assess this control manually until it succeeds.

Reference

Low N/A
777788889999 us-east-1 FS-51
COULD NOT ASSESS: Prompt Injection Input Validation Check
Details and remediation
Details

This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved.

Resolution

1. Confirm the assessment role grants the actions this check requires (see the documented IAM permission set in the README). 2. Confirm the service/feature is supported in the assessed region. 3. Ensure botocore meets the version floor in requirements.txt. 4. Re-run the assessment; assess this control manually until it succeeds.

Reference

Low N/A
777788889999 us-east-1 FS-52
Bedrock Lambda Functions on Current Runtimes
Details and remediation
Details

All 11 Bedrock Lambda function(s) use current runtimes.

Resolution

No action required.

Reference

Medium Passed
777788889999 us-east-1 FS-53
No WAF Web ACLs — Injection Rules Not Applicable
Details and remediation
Details

No regional WAF Web ACLs found.

Resolution

Create WAF Web ACLs with injection protection rules (see FS-01).

Reference

Informational N/A
777788889999 us-east-1 FS-54
ADVISORY: Penetration Testing — Manual Review Required
Details and remediation
Details

Penetration testing evidence cannot be verified via AWS APIs. Manual review required to confirm GenAI applications have been tested.

Resolution

1. Conduct penetration testing of GenAI applications at least annually and before major releases. 2. Include AI-specific test cases: prompt injection, jailbreak, indirect (cross-domain) injection, system-prompt leakage, and data-extraction attempts. 3. Consider AWS Security Agent for on-demand, AI-driven penetration testing (GA March 2026; available in US East N. Virginia, US West Oregon, Europe Ireland, Europe Frankfurt, Asia Pacific Sydney, Asia Pacific Tokyo, with cross-account shared-VPC testing via AWS RAM). Open-source tools such as Garak or PyRIT and manual red-teaming are complementary options. Verify current regional availability on the AWS Security Agent page before relying on it. 4. Document findings and remediation for regulatory examination, and tag tested resources with a last-pentest-date for audit trail. 5. For DORA compliance, include GenAI in TLPT (Threat-Led Penetration Testing) scope.

Reference

Informational N/A
777788889999 us-east-1 FS-55
No Output Validation Functions Found
Details and remediation
Details

No Lambda functions with output validation/sanitization naming found. GenAI outputs may be passed directly to downstream systems without validation.

Resolution

1. Implement output validation Lambda functions in GenAI pipelines. 2. Validate output schema, length, and content before downstream use. 3. Sanitize outputs before rendering in web UIs (XSS prevention). 4. Encode outputs appropriately for the target context (HTML, SQL, JSON).

Reference

Medium Failed
777788889999 us-east-1 FS-56
No WAF ACLs — XSS Prevention Not Applicable
Details and remediation
Details

No regional WAF Web ACLs found.

Resolution

Create WAF ACLs with XSS prevention rules.

Reference

Informational N/A
777788889999 us-east-1 FS-57
ADVISORY: Output Encoding — Manual Review Required
Details and remediation
Details

Output encoding practices cannot be verified via AWS APIs. Manual code review required.

Resolution

1. HTML-encode GenAI outputs before rendering in web UIs. 2. Use parameterized queries when GenAI output is used in database operations. 3. JSON-encode outputs before embedding in JavaScript contexts. 4. Validate output length and format before passing to downstream APIs.

Reference

Informational N/A
777788889999 us-east-1 FS-58
ADVISORY: Output Schema Validation — Manual Review Required
Details and remediation
Details

Found 0 Lambda function(s) whose names suggest schema/validation handling. Structured-output / JSON-schema validation of GenAI responses is an application-layer control that cannot be verified automatically — manual review required.

Resolution

1. Use Bedrock structured output (response schemas) where supported. 2. Implement JSON schema validation on Lambda output processors. 3. Reject malformed outputs and return safe error responses. 4. Log schema validation failures to CloudWatch for monitoring.

Reference

Informational N/A
777788889999 us-east-1 FS-59
COULD NOT ASSESS: Guardrail Topic Allowlist Check
Details and remediation
Details

This check could not be completed (error: An error occurred (AccessDeniedException) when calling the GetGuardrail operation: You don't have sufficient permissions to access this guardrail.). The most common cause is a missing IAM permission for the assessment role; it may also indicate an unsupported region or an outdated botocore. This control was NOT assessed — verify the role's permissions and re-run, and assess this control manually until resolved.

Resolution

1. Confirm the assessment role grants the actions this check requires (see the documented IAM permission set in the README). 2. Confirm the service/feature is supported in the assessed region. 3. Ensure botocore meets the version floor in requirements.txt. 4. Re-run the assessment; assess this control manually until it succeeds.

Reference

Low N/A
777788889999 us-east-1 FS-60
ADVISORY: Contextual Grounding for Off-Topic Prevention
Details and remediation
Details

Contextual grounding for off-topic prevention is covered by guardrail grounding checks (FS-47) and RAG configuration (FS-48). Additionally verify system prompts explicitly scope the assistant's role.

Resolution

1. Include explicit scope instructions in system prompts. 2. Use Bedrock Guardrails relevance grounding filter. 3. Test with off-topic prompts in QA to verify rejection behavior.

Reference

Informational N/A
777788889999 us-east-1 FS-61
No Automated KB Sync Schedules Detected
Details and remediation
Details

Found 1 Knowledge Base(s) but no EventBridge Scheduler schedules or EventBridge rules with 'bedrock'/'knowledge' naming were found. Note: this check uses a name/target heuristic — sync automation with other naming conventions, AWS Step Functions-based orchestration, or native Bedrock API-triggered syncs (StartIngestionJob called directly) will not be detected. Verify sync automation manually if applicable.

Resolution

1. Use EventBridge Scheduler (the AWS-recommended approach) to create a recurring schedule (e.g., rate(1 day) or a cron expression) that triggers a Lambda function calling the Bedrock StartIngestionJob API for each data source. Classic EventBridge scheduled rules also work but are a legacy feature. 2. As of December 2024, Bedrock Knowledge Bases supports custom connectors and streaming data ingestion — use direct document ingestion (KnowledgeBaseDocuments API) for real-time updates without a full S3 sync. 3. Set sync frequency based on data currency requirements (e.g., hourly for market data, daily for regulatory guidance). 4. Configure CloudWatch alarms or SNS notifications on IngestionJob FAILED status for sync failure alerting.

Reference

Medium Failed
777788889999 us-east-1 FS-62
ADVISORY: Data Currency Disclaimer — Manual Review Required
Details and remediation
Details

Data currency disclaimers cannot be verified via AWS APIs. Manual review required.

Resolution

1. Add data currency disclaimers to GenAI outputs: 'Information based on data current as of [KB last sync date].' 2. Expose KB last sync timestamp in application responses. 3. Alert users when KB data is older than defined threshold.

Reference

Informational N/A
777788889999 us-east-1 FS-63
Foundation Model Lifecycle Management
Details and remediation
Details

No legacy models detected. 11 lifecycle-related Config rule(s) found.

Resolution

No action required.

Reference

Medium Passed
777788889999 us-east-1 FS-65
KB Data Source Buckets Missing S3 Event Notifications
Details and remediation
Details

The following KB data-source S3 buckets have no event notifications configured. Unauthorized document modifications will not be detected in real time: - sat2-prowler-2025-prowlerfindingsbucket-wc1k0mza7lpk

Resolution

1. Enable Amazon EventBridge notifications on each KB data-source S3 bucket. 2. Create an EventBridge rule to route s3:ObjectCreated, s3:ObjectRemoved, and s3:ObjectModified events to an SNS topic or Lambda for alerting. 3. Integrate alerts into your security incident response workflow.

Reference

Medium Failed
777788889999 us-east-1 FS-66
No AgentCore Runtimes Found
Details and remediation
Details

No AgentCore runtimes found; identity propagation check not applicable.

Resolution

If using AgentCore, configure token propagation so end-user identities are forwarded to tool services.

Reference

Informational N/A
777788889999 us-east-1 FS-67
Agent Action-Group Lambdas May Lack Transaction Thresholds
Details and remediation
Details

The following agent action-group Lambda functions have no environment variables whose names suggest transaction-value threshold configuration (this is a best-effort heuristic — a threshold enforced in code or in an AgentCore Policy Engine rule would not be detected here, so treat this as a prompt for manual verification rather than a definitive gap). Without explicit limits, agents could initiate unbounded financial transactions: - aiml-security-aiml-security-mgmt-FinServAssessment - aiml-security-aiml-security-mgmt-AgentCoreAssessment - aiml-security-aiml-security-mgmt-BedrockAssessment

Resolution

1. Add transaction-value threshold environment variables (e.g., MAX_TRANSACTION_AMOUNT) to each agent action-group Lambda. 2. Implement threshold enforcement logic in the Lambda handler. 3. Configure AgentCore Policy Engine rules to cap financial transaction amounts. 4. Route transactions exceeding thresholds to a human-in-the-loop approval step.

Reference

High Failed
777788889999 us-east-1 FS-68
API Gateway Request Body Size Limits — Not Applicable
Details and remediation
Details

No API Gateway REST APIs and no regional WAF Web ACLs were found in this region. There is no input-payload surface to assess for body-size limits.

Resolution

If GenAI endpoints are fronted by API Gateway or WAF in another region, run the assessment there. Otherwise no action is required.

Reference

Informational N/A
777788889999 us-east-1 FS-69
Prompt Input Validation Functions Present
Details and remediation
Details

Found 1 Lambda function(s) with input validation/sanitization naming patterns: aiml-security-aiml-security-mgmt-CleanupBucket.

Resolution

Review these functions to confirm they cover: special-character stripping, format validation, size limits, and injection-sequence detection.

Reference

Medium Passed
777788889999 us-east-2 FS-00
FinServ Regional Scope Not Applicable
Details and remediation
Details

No regional Bedrock, AgentCore, or SageMaker resources were found in us-east-2; FinServ GenAI risk checks were not applied to this region.

Resolution

No action required unless GenAI workloads are expected in this region.

Reference

Informational N/A
777788889999 us-west-2 FS-00
FinServ Regional Scope Not Applicable
Details and remediation
Details

No regional Bedrock, AgentCore, or SageMaker resources were found in us-west-2; FinServ GenAI risk checks were not applied to this region.

Resolution

No action required unless GenAI workloads are expected in this region.

Reference

Informational N/A
777788889999 eu-west-1 FS-00
FinServ Regional Scope Not Applicable
Details and remediation
Details

No regional Bedrock, AgentCore, or SageMaker resources were found in eu-west-1; FinServ GenAI risk checks were not applied to this region.

Resolution

No action required unless GenAI workloads are expected in this region.

Reference

Informational N/A
777788889999 eu-west-1 BR-02
Amazon Bedrock private connectivity check
Details and remediation
Details

No regional Bedrock resources found to assess private connectivity

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 BR-04
Bedrock Model Invocation Logging Check
Details and remediation
Details

No regional Bedrock resources found to monitor with invocation logging

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 BR-05
Bedrock Guardrails Check
Details and remediation
Details

No regional Bedrock resources found to protect with guardrails

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 BR-06
Bedrock CloudTrail Logging Check
Details and remediation
Details

No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 BR-07
Bedrock Prompt Management Check
Details and remediation
Details

Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses.

Resolution

Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates

Reference

Informational N/A
777788889999 eu-west-1 BR-08
Bedrock Agent IAM Roles Check
Details and remediation
Details

No Bedrock agents found in the account

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 BR-09
Bedrock Knowledge Base Encryption Check
Details and remediation
Details

No Knowledge Bases found in the account

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 BR-10
Bedrock Guardrail IAM Enforcement Check
Details and remediation
Details

No guardrails configured - IAM enforcement check not applicable

Resolution

Configure Bedrock Guardrails first, then enforce their use via IAM policies

Reference

Informational N/A
777788889999 eu-west-1 BR-11
Bedrock Custom Model Encryption Check
Details and remediation
Details

No custom/fine-tuned models found in the account

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 BR-12
Bedrock Invocation Log Encryption Check
Details and remediation
Details

Model invocation logging to S3 is not configured

Resolution

If logging is enabled to CloudWatch only, ensure CloudWatch log group uses CMK encryption

Reference

Informational N/A
777788889999 eu-west-1 BR-13
Bedrock Flows Guardrails Check
Details and remediation
Details

No Bedrock Flows found in the account

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 BR-16
Guardrail Tier Validation Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create Bedrock guardrails with Standard tier for enhanced content filtering and protection

Reference

Medium N/A
777788889999 eu-west-1 BR-17
Custom Model Customer-Managed KMS Encryption Check
Details and remediation
Details

No custom (fine-tuned) Bedrock models found in this region

Resolution

When creating custom models, specify a customer-managed KMS key for encryption to maintain control over encryption keys

Reference

High N/A
777788889999 eu-west-1 BR-18
Model Evaluation Implementation Check
Details and remediation
Details

No regional Bedrock resources found to assess with model evaluation jobs

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 BR-19
Prompt Flow Validation Check
Details and remediation
Details

No Bedrock prompt flows configured in this region

Resolution

When creating prompt flows, use the ValidateFlowDefinition API to validate flow definitions before deployment

Reference

Medium N/A
777788889999 eu-west-1 BR-20
Knowledge Base Customer-Managed KMS Encryption Check
Details and remediation
Details

No Bedrock knowledge bases found in this region

Resolution

When creating knowledge bases, specify customer-managed KMS keys for both vector store and data source encryption

Reference

High N/A
777788889999 eu-west-1 BR-21
Agent Action Group IAM Least Privilege Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents with action groups, ensure Lambda execution roles follow least privilege principles

Reference

High N/A
777788889999 eu-west-1 BR-22
Model Invocation Throttling Limits Check
Details and remediation
Details

No regional Bedrock resources found to assess model invocation throttling quotas

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 BR-23
Guardrail Content Filter Coverage Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with all content filters enabled (hate, insults, sexual, violence) with appropriate thresholds

Reference

High N/A
777788889999 eu-west-1 BR-24
Automated Reasoning Policy Implementation Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with Automated Reasoning policies for formal verification of model responses

Reference

Medium N/A
777788889999 eu-west-1 BR-25
RAG Evaluation Jobs Check
Details and remediation
Details

No Bedrock knowledge bases found in this region

Resolution

When implementing RAG applications, configure evaluation jobs to assess context relevance, response correctness, and prevent hallucinations

Reference

Low N/A
777788889999 eu-west-1 BR-26
Guardrail Sensitive Information Filter Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with sensitive-information filters (PII entities and/or regex patterns) to detect and redact sensitive data in prompts and model responses

Reference

High N/A
777788889999 eu-west-1 BR-27
Guardrail Contextual Grounding Check
Details and remediation
Details

No Bedrock guardrails configured in this region

Resolution

Create guardrails with contextual grounding checks to detect hallucinations (ungrounded responses) and irrelevant answers, especially for RAG applications

Reference

Medium N/A
777788889999 eu-west-1 BR-28
Agent Guardrail Association Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents, associate a Bedrock guardrail so agent inputs and responses are filtered for harmful content, PII, and denied topics

Reference

High N/A
777788889999 eu-west-1 BR-29
Agent Idle Session TTL Check
Details and remediation
Details

No Bedrock agents configured in this region

Resolution

When creating agents, set a conservative idleSessionTTLInSeconds to limit how long an idle session remains resumable

Reference

Low N/A
777788889999 eu-west-1 BR-30
Imported Model Customer-Managed KMS Encryption Check
Details and remediation
Details

Unable to check Imported model encryption check: An error occurred (AccessDeniedException) when calling the ListImportedModels operation: Your account is not authorized to invoke this API operation.

Resolution

Amazon Bedrock Custom Model Import is not enabled or available for this account in this region. No IAM change is required; the check applies only once model import is in use.

Reference

Low N/A
777788889999 eu-west-1 BR-31
Batch Inference Output Encryption Check
Details and remediation
Details

No Bedrock batch inference (model invocation) jobs found in this region

Resolution

When creating batch inference jobs, set outputDataConfig.s3OutputDataConfig.s3EncryptionKeyId to a customer-managed KMS key to encrypt the job output

Reference

Medium N/A
777788889999 eu-west-1 BR-32
Bedrock CloudWatch Alarm Check
Details and remediation
Details

No regional Bedrock resources found to monitor with CloudWatch alarms

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 BR-33
Amazon Inspector Lambda Code Scanning Check
Details and remediation
Details

No Lambda functions with Bedrock indicators were found in eu-west-1; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads.

Resolution

No action required. If Bedrock-calling Lambda functions exist, ensure their function name, ARN, description, handler, role, or environment variables contain a Bedrock identifier that the assessment can detect, or evaluate Inspector coverage manually.

Reference

Informational N/A
777788889999 eu-west-1 AG-07
Agentic AI Model Invocation Logging
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging

Resolution

Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements.

Reference

Informational N/A
777788889999 eu-west-1 AG-08
Agentic AI API Audit Trail
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage

Resolution

Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured.

Reference

Informational N/A
777788889999 eu-west-1 AG-10
Agentic AI Adversarial Evaluation Coverage
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs

Resolution

Configure model or application evaluations that include adversarial, safety, and security-relevant test cases.

Reference

Informational N/A
777788889999 eu-west-1 AG-11
Agentic AI Prompt Flow Validation
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region

Resolution

Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions.

Reference

Informational N/A
777788889999 eu-west-1 AG-06
Agentic AI Tool Execution Least Privilege
Details and remediation
Details

Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region

Resolution

Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required.

Reference

Informational N/A
777788889999 eu-west-1 AG-12
Agentic AI Invocation Abuse Controls
Details and remediation
Details

Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas

Resolution

Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns.

Reference

Informational N/A
777788889999 eu-west-1 AG-02
Agentic AI Harmful Content Guardrail Coverage
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: No Bedrock guardrails configured in this region

Resolution

Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads.

Reference

Informational N/A
777788889999 eu-west-1 AG-04
Agentic AI Automated Reasoning Guardrails
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: No Bedrock guardrails configured in this region

Resolution

Configure automated reasoning policies on guardrails where formal response validation is required.

Reference

Informational N/A
777788889999 eu-west-1 AG-03
Agentic AI Sensitive Information Protection
Details and remediation
Details

Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: No Bedrock guardrails configured in this region

Resolution

Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns.

Reference

Informational N/A
777788889999 eu-west-1 AG-05
Agentic AI Grounding Controls
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows.

Reference

Informational N/A
777788889999 eu-west-1 AG-01
Agentic AI Agent Guardrail Association
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region

Resolution

Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating.

Reference

Informational N/A
777788889999 eu-west-1 AG-13
Agentic AI Session Boundary
Details and remediation
Details

Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region

Resolution

Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements.

Reference

Informational N/A
777788889999 eu-west-1 AG-14
Agentic AI Operational Abuse Alarms
Details and remediation
Details

Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms

Resolution

Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available.

Reference

Informational N/A
777788889999 Global BR-01
AmazonBedrockFullAccess role check
Details and remediation
Details

Role 'aiml-sec-test-resources-BedrockFullAccessRole-zAFkGLkWQ61a' has AmazonBedrockFullAccess policy attached

Resolution

Limit the AmazonBedrockFullAccess policy only to required access

Reference

High Failed
777788889999 Global BR-03
Marketplace Subscription Access Check
Details and remediation
Details

Role 'aiml-sec-test-resources-BedrockFullAccessRole-zAFkGLkWQ61a' has overly permissive marketplace subscription access through policy 'AmazonBedrockFullAccess'

Resolution

Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check.

Reference

High Failed
777788889999 Global BR-03
Marketplace Subscription Access Check
Details and remediation
Details

Role 'aiml-sec-test-resources-MarketplaceOverlyPermissive-igL3hGIapee1' has overly permissive marketplace subscription access through policy 'OverlyPermissiveMarketplace'

Resolution

Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check.

Reference

High Failed
777788889999 Global BR-03
Marketplace Subscription Access Check
Details and remediation
Details

Role 'ProwlerApp-EC2-Role' has overly permissive marketplace subscription access through policy 'AWSElasticBeanstalkMulticontainerDocker'

Resolution

Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check.

Reference

High Failed
777788889999 us-east-1 BR-02
Amazon Bedrock private connectivity
Details and remediation
Details

Bedrock VPC endpoints found: VPC vpc-089a9d593e34658c6 has endpoint com.amazonaws.us-east-1.bedrock-runtime

Resolution

No action required

Reference

High Passed
777788889999 us-east-1 BR-04
Bedrock Model Invocation Logging Check
Details and remediation
Details

Model invocation logging is not enabled. This limits your ability to track and audit model usage.

Resolution

Enable model invocation logging to collect invocation logs, model input data, and model output data. Configure logging to deliver to Amazon S3, CloudWatch Logs, or both for comprehensive monitoring.

Reference

Medium Failed
777788889999 us-east-1 BR-05
Bedrock Guardrails Check
Details and remediation
Details

Amazon Bedrock Guardrails are properly configured with 1 guardrails

Resolution

No action required. Continue monitoring and updating guardrails as needed.

Reference

High Passed
777788889999 us-east-1 BR-06
Bedrock CloudTrail Logging Check
Details and remediation
Details

CloudTrail is properly configured to log Bedrock API activity in trails: IsengardTrail-DO-NOT-DELETE

Resolution

No action required. Continue monitoring CloudTrail logs for Bedrock activity.

Reference

Medium Passed
777788889999 us-east-1 BR-07
Bedrock Prompt Management Check
Details and remediation
Details

Prompt Management is being used with 1 prompts

Resolution

No action required. Continue using Prompt Management for consistent and optimized prompts.

Reference

Low Passed
777788889999 us-east-1 BR-08
Bedrock Agent IAM Roles Check
Details and remediation
Details

Could not assess this check in us-east-1. Assessment error: AccessDeniedException.

Resolution

No action required on the assessed workload. Resolve the assessment prerequisite or permission issue and rerun the assessment.

Reference

Informational N/A
777788889999 us-east-1 BR-09
Bedrock Knowledge Base Encryption Review
Details and remediation
Details

Knowledge Base 'knowledge-base-prowler-findings' (9K2QZLVCZW) uses 'OPENSEARCH_SERVERLESS' storage. Encryption is managed at the storage layer and cannot be validated from the KB API. Verify encryption configuration on the underlying storage resource.

Resolution

1. For OpenSearch Serverless: Verify encryption with CMK at collection level 2. For S3 data sources: Verify CMK-encrypted S3 buckets 3. For RDS: Verify KMS encryption on the database 4. Consider using CMK for transient data during ingestion

Reference

Informational N/A
777788889999 us-east-1 BR-10
Bedrock Guardrail IAM Enforcement Missing
Details and remediation
Details

The following roles can invoke Bedrock models without enforced guardrails: aiml-sec-test-resources-BedrockAgentRoleWithoutGuar-Z3kN5ANhP89G, aiml-sec-test-resources-BedrockFullAccessRole-zAFkGLkWQ61a, aiml-sec-test-resources-BedrockKnowledgeBaseRole-6NNC1i9FuTbM, AmazonBedrockExecutionRoleForKnowledgeBase_7erx6, ProwlerApp-EC2-Role

Resolution

Add IAM policy conditions to enforce guardrail usage: 1. Use 'bedrock:GuardrailIdentifier' condition key 2. Specify required guardrail ARN or ID 3. Example: "Condition": {"StringEquals": {"bedrock:GuardrailIdentifier": "arn:aws:bedrock:region:account:guardrail/guardrail-id"}}

Reference

High Failed
777788889999 us-east-1 BR-11
Bedrock Custom Model Encryption Check
Details and remediation
Details

No custom/fine-tuned models found in the account

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-1 BR-12
Bedrock Invocation Log Encryption Check
Details and remediation
Details

Model invocation logging to S3 is not configured

Resolution

If logging is enabled to CloudWatch only, ensure CloudWatch log group uses CMK encryption

Reference

Informational N/A
777788889999 us-east-1 BR-13
Bedrock Flows Guardrails Check
Details and remediation
Details

No Bedrock Flows found in the account

Resolution

No action required

Reference

Informational N/A
777788889999 Global BR-15
Cross-Account Guardrails Enforcement Check
Details and remediation
Details

Check must run in AWS Organizations management account to evaluate organizational policies

Resolution

Run assessment in management account to check cross-account guardrails enforcement

Reference

Medium N/A
777788889999 us-east-1 BR-16
Guardrail Tier Validation Check
Details and remediation
Details

Guardrail 'aiml-sec-test-test-guardrail' (ID: jkceg2tprvwh) could not be assessed because GetGuardrail returned AccessDeniedException.

Resolution

Retry the assessment. If the error persists, grant bedrock:GetGuardrail and verify the guardrail still exists.

Reference

Informational N/A
777788889999 us-east-1 BR-17
Custom Model Customer-Managed KMS Encryption Check
Details and remediation
Details

No custom (fine-tuned) Bedrock models found in this region

Resolution

When creating custom models, specify a customer-managed KMS key for encryption to maintain control over encryption keys

Reference

High N/A
777788889999 us-east-1 BR-18
Model Evaluation Implementation Check
Details and remediation
Details

No Bedrock model evaluation jobs found. Model evaluation helps assess toxicity, accuracy, semantic robustness, and other safety metrics before production deployment.

Resolution

Create model evaluation jobs using Amazon Bedrock Evaluations to assess foundation model performance against safety and quality metrics. Use built-in datasets or custom test sets. Enable LLM-as-a-judge evaluation for comprehensive assessment.

Reference

Medium Failed
777788889999 us-east-1 BR-19
Prompt Flow Validation Check
Details and remediation
Details

No Bedrock prompt flows configured in this region

Resolution

When creating prompt flows, use the ValidateFlowDefinition API to validate flow definitions before deployment

Reference

Medium N/A
777788889999 us-east-1 BR-20
Knowledge Base Customer-Managed KMS Encryption Review
Details and remediation
Details

Knowledge base 'knowledge-base-prowler-findings' (ID: 9K2QZLVCZW) uses 'OPENSEARCH_SERVERLESS' storage. The vector-store encryption key is managed at the storage layer and cannot be validated from the Knowledge Base API. Verify customer-managed KMS encryption on the underlying store.

Resolution

1. For OpenSearch Serverless: verify the collection uses a customer-managed KMS key 2. For Amazon RDS/Aurora: verify KMS encryption on the database 3. For third-party stores (Pinecone, Redis, MongoDB): verify the provider's encryption configuration 4. Verify the customer-managed KMS key used for transient data during ingestion

Reference

Informational N/A
777788889999 us-east-1 BR-22
Model Invocation Throttling Limits Check
Details and remediation
Details

9 custom throttling quotas are configured. Regular quota review helps maintain appropriate rate limits.

Resolution

Continue monitoring quota utilization. Review and adjust quotas as application requirements change.

Reference

Low Passed
777788889999 us-east-1 BR-23
Guardrail Content Filter Coverage Check
Details and remediation
Details

Guardrail 'aiml-sec-test-test-guardrail' (ID: jkceg2tprvwh) could not be assessed because GetGuardrail returned AccessDeniedException.

Resolution

Retry the assessment. If the error persists, grant bedrock:GetGuardrail and verify the guardrail still exists.

Reference

Informational N/A
777788889999 us-east-1 BR-25
RAG Evaluation Jobs Check
Details and remediation
Details

Knowledge base 'knowledge-base-prowler-findings' (ID: 9K2QZLVCZW) does not have recent RAG evaluation jobs. RAG evaluations assess context relevance, response correctness, faithfulness, and harmfulness to prevent hallucinations.

Resolution

Create RAG evaluation jobs for knowledge bases using Amazon Bedrock Model Evaluation. Configure evaluations to test context relevance, answer correctness, and faithfulness metrics. Run evaluations regularly (monthly or after significant KB updates) to maintain quality.

Reference

Low Failed
777788889999 us-east-1 BR-26
Guardrail Sensitive Information Filter Check
Details and remediation
Details

Guardrail 'aiml-sec-test-test-guardrail' (ID: jkceg2tprvwh) could not be assessed because GetGuardrail returned AccessDeniedException.

Resolution

Retry the assessment. If the error persists, grant bedrock:GetGuardrail and verify the guardrail still exists.

Reference

Informational N/A
777788889999 us-east-1 BR-27
Guardrail Contextual Grounding Check
Details and remediation
Details

Guardrail 'aiml-sec-test-test-guardrail' (ID: jkceg2tprvwh) could not be assessed because GetGuardrail returned AccessDeniedException.

Resolution

Retry the assessment. If the error persists, grant bedrock:GetGuardrail and verify the guardrail still exists.

Reference

Informational N/A
777788889999 us-east-1 BR-28
Agent Guardrail Association Check
Details and remediation
Details

1 agents have an associated guardrail

Resolution

No action required. Continue associating guardrails with new agents.

Reference

Low Passed
777788889999 us-east-1 BR-30
Imported Model Customer-Managed KMS Encryption Check
Details and remediation
Details

No imported custom Bedrock models found in this region

Resolution

When importing models, specify a customer-managed KMS key for encryption to maintain control over encryption keys

Reference

High N/A
777788889999 us-east-1 BR-31
Batch Inference Output Encryption Check
Details and remediation
Details

No Bedrock batch inference (model invocation) jobs found in this region

Resolution

When creating batch inference jobs, set outputDataConfig.s3OutputDataConfig.s3EncryptionKeyId to a customer-managed KMS key to encrypt the job output

Reference

Medium N/A
777788889999 us-east-1 BR-32
Bedrock CloudWatch Alarm Check
Details and remediation
Details

No CloudWatch alarms are configured on Amazon Bedrock runtime metrics (AWS/Bedrock namespace). Without alarms, abuse, denial-of-wallet, sustained throttling, and content-filter spikes can go undetected.

Resolution

Create CloudWatch alarms on AWS/Bedrock runtime metrics such as Invocations, InvocationThrottles, InputTokenCount, OutputTokenCount, and ContentFilteredCount, and route them to an Amazon SNS topic for notification.

Reference

Medium Failed
777788889999 us-east-1 BR-33
Amazon Inspector Lambda Code Scanning Check
Details and remediation
Details

Amazon Inspector Lambda standard scanning and Lambda code scanning are both ENABLED in us-east-1. Detected 1 Lambda function(s) with Bedrock indicators: aiml-security-aiml-security-mgmt-BedrockAssessment.

Resolution

No action required.

Reference

Medium Passed
777788889999 us-east-1 AG-07
Agentic AI Model Invocation Logging
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: Model invocation logging is not enabled. This limits your ability to track and audit model usage.

Resolution

Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements.

Reference

Medium Failed
777788889999 us-east-1 AG-08
Agentic AI API Audit Trail
Details and remediation
Details

Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: CloudTrail is properly configured to log Bedrock API activity in trails: IsengardTrail-DO-NOT-DELETE

Resolution

Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured.

Reference

Medium Passed
777788889999 Global AG-09
Agentic AI Guardrail Enforcement Boundary
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Organization-level guardrail enforcement helps prevent agents from bypassing required safety controls across accounts. Source check BR-15: Check must run in AWS Organizations management account to evaluate organizational policies

Resolution

Use IAM and organization controls to require approved guardrails for model and agent invocations where supported.

Reference

Informational N/A
777788889999 us-east-1 AG-10
Agentic AI Adversarial Evaluation Coverage
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No Bedrock model evaluation jobs found. Model evaluation helps assess toxicity, accuracy, semantic robustness, and other safety metrics before production deployment.

Resolution

Configure model or application evaluations that include adversarial, safety, and security-relevant test cases.

Reference

Medium Failed
777788889999 us-east-1 AG-11
Agentic AI Prompt Flow Validation
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region

Resolution

Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions.

Reference

Informational N/A
777788889999 us-east-1 AG-12
Agentic AI Invocation Abuse Controls
Details and remediation
Details

Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: 9 custom throttling quotas are configured. Regular quota review helps maintain appropriate rate limits.

Resolution

Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns.

Reference

Low Passed
777788889999 us-east-1 AG-02
Agentic AI Harmful Content Guardrail Coverage
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: Guardrail 'aiml-sec-test-test-guardrail' (ID: jkceg2tprvwh) could not be assessed because GetGuardrail returned AccessDeniedException.

Resolution

Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads.

Reference

Informational N/A
777788889999 us-east-1 AG-03
Agentic AI Sensitive Information Protection
Details and remediation
Details

Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: Guardrail 'aiml-sec-test-test-guardrail' (ID: jkceg2tprvwh) could not be assessed because GetGuardrail returned AccessDeniedException.

Resolution

Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns.

Reference

Informational N/A
777788889999 us-east-1 AG-05
Agentic AI Grounding Controls
Details and remediation
Details

Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: Guardrail 'aiml-sec-test-test-guardrail' (ID: jkceg2tprvwh) could not be assessed because GetGuardrail returned AccessDeniedException.

Resolution

Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows.

Reference

Informational N/A
777788889999 us-east-1 AG-01
Agentic AI Agent Guardrail Association
Details and remediation
Details

Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: 1 agents have an associated guardrail

Resolution

Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating.

Reference

Low Passed
777788889999 us-east-1 AG-14
Agentic AI Operational Abuse Alarms
Details and remediation
Details

Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No CloudWatch alarms are configured on Amazon Bedrock runtime metrics (AWS/Bedrock namespace). Without alarms, abuse, denial-of-wallet, sustained throttling, and content-filter spikes can go undetected.

Resolution

Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available.

Reference

Medium Failed
777788889999 us-east-2 OW-01
OWASP LLM01: Model Invocation Logging
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging

Resolution

Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis.

Reference

Informational N/A
777788889999 us-east-2 OW-07
OWASP LLM07: Model Invocation Logging
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging

Resolution

Enable Bedrock model invocation logging so prompt-extraction attempts against the system prompt are auditable after the fact.

Reference

Informational N/A
777788889999 us-east-2 OW-07
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses.

Resolution

Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident.

Reference

Informational N/A
777788889999 us-east-2 OW-07
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
Details and remediation
Details

OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-16: No Bedrock guardrails configured in this region

Resolution

Set guardrail contentPolicy.tier.tierName to STANDARD; Standard tier additionally detects prompt-leakage attacks.

Reference

Informational N/A
777788889999 us-east-2 OW-09
OWASP LLM09: Model Evaluation Jobs
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs

Resolution

Run Bedrock model evaluation jobs that include correctness and safety datasets.

Reference

Informational N/A
777788889999 us-east-2 OW-08
OWASP LLM08: Managed Knowledge-Base CMK Encryption
Details and remediation
Details

OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check BR-20: No Bedrock knowledge bases found in this region

Resolution

Configure the Bedrock Managed Knowledge Base to use a customer-managed KMS key for storage encryption.

Reference

Informational N/A
777788889999 us-east-2 OW-06
OWASP LLM06: Agent Action-Group Least Privilege
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-21: No Bedrock agents configured in this region

Resolution

Restrict agent action-group Lambda roles to only the specific actions and resources needed for each tool.

Reference

Informational N/A
777788889999 us-east-2 OW-10
OWASP LLM10: Service Quota Throttling Limits
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas

Resolution

Customise Bedrock TPM / RPM service quotas above the account default to establish an explicit consumption ceiling.

Reference

Informational N/A
777788889999 us-east-2 OW-01
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: No Bedrock guardrails configured in this region

Resolution

Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier.

Reference

Informational N/A
777788889999 us-east-2 OW-04
OWASP LLM04: RAG Evaluation Coverage
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-25: No Bedrock knowledge bases found in this region

Resolution

Run Bedrock RAG evaluation jobs against knowledge bases regularly to detect degraded retrieval or poisoned context.

Reference

Informational N/A
777788889999 us-east-2 OW-09
OWASP LLM09: RAG Evaluation for Faithfulness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-25: No Bedrock knowledge bases found in this region

Resolution

Include faithfulness and correctness metrics in RAG evaluation jobs to catch misinformation before deploying knowledge-base updates.

Reference

Informational N/A
777788889999 us-east-2 OW-02
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check BR-26: No Bedrock guardrails configured in this region

Resolution

Configure guardrail sensitiveInformationPolicy with PII entities and regex patterns; set outputAction=ANONYMIZE or BLOCK.

Reference

Informational N/A
777788889999 us-east-2 OW-01
OWASP LLM01: Contextual Grounding Guardrail
Details and remediation
Details

OWASP category: LLM01:2025 Prompt Injection. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Enable Bedrock guardrail contextual grounding checks to reduce the surface for indirect prompt injection through retrieved context.

Reference

Informational N/A
777788889999 us-east-2 OW-04
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Enable contextual grounding guardrail filters so retrieved context that diverges from ground truth is filtered before reaching the model.

Reference

Informational N/A
777788889999 us-east-2 OW-09
OWASP LLM09: Contextual Grounding for Faithfulness
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check BR-27: No Bedrock guardrails configured in this region

Resolution

Set the contextual grounding filter threshold to at least 0.70 to reduce hallucinated responses.

Reference

Informational N/A
777788889999 us-east-2 OW-06
OWASP LLM06: Bedrock Agent Guardrail Association
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-28: No Bedrock agents configured in this region

Resolution

Attach an approved Bedrock guardrail to every Bedrock agent so autonomous actions are filtered consistently.

Reference

Informational N/A
777788889999 us-east-2 OW-06
OWASP LLM06: Agent Idle Session TTL
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check BR-29: No Bedrock agents configured in this region

Resolution

Set idleSessionTTLInSeconds to a conservative value (e.g., <= 3600) so long-lived agent sessions cannot be reused.

Reference

Informational N/A
777788889999 us-east-2 OW-03
OWASP LLM03: Imported-Model KMS Provenance
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check BR-30: No imported custom Bedrock models found in this region

Resolution

Encrypt imported Bedrock models with a customer-managed KMS key to preserve provenance and access control across model artefacts.

Reference

Informational N/A
777788889999 us-east-2 OW-10
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms

Resolution

Create CloudWatch alarms on Bedrock InvocationThrottles, InputTokenCount, OutputTokenCount, and EstimatedTPMQuotaUsage.

Reference

Informational N/A
777788889999 us-east-2 OW-03
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check BR-33: No Lambda functions with Bedrock indicators were found in us-east-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads.

Resolution

Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain.

Reference

Informational N/A
777788889999 us-east-2 OW-03
OWASP LLM03: SageMaker Internet Exposure
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-01: No SageMaker notebook instances or domains found to check

Resolution

Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths.

Reference

Informational N/A
777788889999 us-east-2 OW-02
OWASP LLM02: SageMaker Data Encryption
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: No SageMaker resources found to check for data protection

Resolution

Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data.

Reference

Informational N/A
777788889999 us-east-2 OW-09
OWASP LLM09: SageMaker Clarify Evaluation
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-06: No SageMaker Clarify jobs found

Resolution

Use SageMaker Clarify to evaluate bias and explainability for models whose generated outputs can influence user decisions.

Reference

Informational N/A
777788889999 us-east-2 OW-04
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-07: No Model Monitor schedules found

Resolution

Configure active SageMaker Model Monitor schedules so data-quality and model-quality regressions caused by poisoned inputs or drift are detected.

Reference

Informational N/A
777788889999 us-east-2 OW-09
OWASP LLM09: SageMaker Model Monitor Coverage
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-07: No Model Monitor schedules found

Resolution

Configure SageMaker Model Monitor schedules for production models so quality regressions that can produce incorrect outputs are detected.

Reference

Informational N/A
777788889999 us-east-2 OW-03
OWASP LLM03: SageMaker Notebook VPC Deployment
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-10: No notebook instances found

Resolution

Deploy SageMaker notebook instances inside a VPC so package, data, and model artifact access can be controlled through private network paths.

Reference

Informational N/A
777788889999 us-east-2 OW-03
OWASP LLM03: SageMaker Model Network Isolation
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-11: No models found

Resolution

Enable network isolation on SageMaker models so inference containers cannot make unmanaged outbound calls that alter dependencies or exfiltrate model artifacts.

Reference

Informational N/A
777788889999 us-east-2 OW-10
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation
Details

OWASP category: LLM10:2025 Unbounded Consumption. Source check SM-11: No models found

Resolution

Enable SageMaker model network isolation to prevent deployed model containers from making uncontrolled outbound calls that can amplify consumption or abuse downstream services.

Reference

Informational N/A
777788889999 us-east-2 OW-03
OWASP LLM03: SageMaker Container Repository Access
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-14: No models found or all use default Platform access

Resolution

Configure SageMaker models to pull container images from private ECR repositories through VPC repository access instead of platform or public registry paths.

Reference

Informational N/A
777788889999 us-east-2 OW-02
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation
Details

OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-15: No feature groups with offline stores found

Resolution

Encrypt SageMaker Feature Store offline stores with customer-managed KMS keys so sensitive feature data is protected at rest.

Reference

Informational N/A
777788889999 us-east-2 OW-03
OWASP LLM03: SageMaker AutoML Network Isolation
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-21: No AutoML jobs found

Resolution

Enable network isolation on AutoML jobs so generated training containers cannot fetch unapproved dependencies or send data over unmanaged network paths.

Reference

Informational N/A
777788889999 us-east-2 OW-04
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance.

Resolution

Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically.

Reference

Informational N/A
777788889999 us-east-2 OW-09
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance.

Resolution

Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release.

Reference

Informational N/A
777788889999 us-east-2 OW-04
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-23: No InService endpoints found to monitor.

Resolution

Enable SageMaker Model Monitor drift detection for production endpoints so poisoning, data drift, and model-quality degradation are identified.

Reference

Medium Passed
777788889999 us-east-2 OW-09
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation
Details

OWASP category: LLM09:2025 Misinformation. Source check SM-23: No InService endpoints found to monitor.

Resolution

Configure data-quality and model-quality monitoring for SageMaker endpoints so degraded model behavior that can produce misinformation is detected.

Reference

Medium Passed
777788889999 us-east-2 OW-03
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediation
Details

OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain.

Reference

Informational N/A
777788889999 us-east-2 OW-04
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediation
Details

OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated.

Reference

Informational N/A
777788889999 us-east-2 OW-06
OWASP LLM06: AgentCore Resource-Based Policies
Details and remediation
Details

OWASP category: LLM06:2025 Excessive Agency. Source check AC-10: No AgentCore resources found to check for resource-based policies

Resolution

Attach resource-based policies to AgentCore runtimes and gateways so caller identities are constrained.

Reference

Informational N/A
777788889999 us-east-2 OW-11
OWASP LLM07: System Prompt Embedded in Lambda Env Var
Details and remediation
Details

No Lambda function env vars in us-east-2 match the embedded-system-prompt heuristic (>= 200 chars containing prompt-shaped tokens).

Resolution

No action required.

Reference

Medium Passed
777788889999 us-east-2 OW-12
OWASP LLM07: System-Prompt-Disclosure Denied Topic
Details and remediation
Details

No Bedrock guardrails configured in us-east-2; nothing to inspect.

Resolution

No action required.

Reference

Informational N/A
777788889999 eu-west-1 SM-01
SageMaker Internet Access Check
Details and remediation
Details

No SageMaker notebook instances or domains found to check

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 SM-02
SageMaker SSO Configuration Check
Details and remediation
Details

No SageMaker domains found, or all domains use SSO with IAM Identity Center configured

Resolution

No action required

Reference

Medium Passed
777788889999 eu-west-1 SM-03
Data Protection Check
Details and remediation
Details

No SageMaker resources found to check for data protection

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 SM-04
GuardDuty Enabled
Details and remediation
Details

Amazon GuardDuty is properly enabled and monitoring for security threats in SageMaker workloads.

Resolution

No action required

Reference

Medium Passed
777788889999 eu-west-1 SM-05
SageMaker Model Registry Issue
Details and remediation
Details

No model package groups found

Resolution

Implement model versioning using SageMaker Model Registry to track model lineage, approve model versions, and manage model deployment

Reference

Informational N/A
777788889999 eu-west-1 SM-05
SageMaker Feature Store Issue
Details and remediation
Details

No feature groups found

Resolution

Utilize SageMaker Feature Store to create, share, and manage features for machine learning development and production

Reference

Informational N/A
777788889999 eu-west-1 SM-05
SageMaker Pipelines Issue
Details and remediation
Details

No ML pipelines found

Resolution

Implement SageMaker Pipelines to automate and manage ML workflows, including data preparation, training, and model deployment

Reference

Informational N/A
777788889999 eu-west-1 SM-06
SageMaker Clarify No Clarify Usage
Details and remediation
Details

No SageMaker Clarify jobs found

Resolution

Implement SageMaker Clarify for model explainability and bias detection

Reference

Informational N/A
777788889999 eu-west-1 SM-07
SageMaker Model Monitor No Model Monitoring
Details and remediation
Details

No Model Monitor schedules found

Resolution

Configure comprehensive model monitoring schedules

Reference

Informational N/A
777788889999 eu-west-1 SM-08
Model Registry Registry Not Used
Details and remediation
Details

Model Registry is not being utilized

Resolution

Implement proper model versioning and approval workflows

Reference

Informational N/A
777788889999 eu-west-1 SM-09
SageMaker Notebook Root Access Check
Details and remediation
Details

No notebook instances found

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 SM-10
SageMaker Notebook VPC Deployment Check
Details and remediation
Details

No notebook instances found

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 SM-11
SageMaker Model Network Isolation Check
Details and remediation
Details

No models found

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 SM-12
SageMaker Endpoint Instance Count Check
Details and remediation
Details

No InService endpoints found

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 SM-13
SageMaker Monitoring Network Isolation Check
Details and remediation
Details

No monitoring schedules found

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 SM-14
SageMaker Model Repository Access Check
Details and remediation
Details

No models found or all use default Platform access

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 SM-15
SageMaker Feature Store Encryption Check
Details and remediation
Details

No feature groups with offline stores found

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 SM-16
SageMaker Data Quality Job Encryption Check
Details and remediation
Details

No data quality job definitions found

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 SM-17
SageMaker Processing Job Encryption Check
Details and remediation
Details

No processing jobs found

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 SM-18
SageMaker Transform Job Encryption Check
Details and remediation
Details

No transform jobs found

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 SM-19
SageMaker Hyperparameter Tuning Job Encryption Check
Details and remediation
Details

No hyperparameter tuning jobs found

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 SM-20
SageMaker Compilation Job Encryption Check
Details and remediation
Details

No compilation jobs found

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 SM-21
SageMaker AutoML Job Network Isolation Check
Details and remediation
Details

No AutoML jobs found

Resolution

No action required

Reference

Informational N/A
777788889999 eu-west-1 SM-22
Model Approval Workflow Check
Details and remediation
Details

No model package groups found. Model Registry is not being used for model governance.

Resolution

Implement Model Registry to track model versions and enforce approval workflows before production deployment.

Reference

Informational N/A
777788889999 eu-west-1 SM-23
Model Drift Detection Check
Details and remediation
Details

No InService endpoints found to monitor.

Resolution

No action required

Reference

Medium Passed
777788889999 eu-west-1 SM-24
A/B Testing and Shadow Deployment Check
Details and remediation
Details

No InService endpoints found.

Resolution

No action required

Reference

Low Passed
777788889999 eu-west-1 SM-25
ML Lineage Tracking - Experiments Not Used
Details and remediation
Details

No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Implement SageMaker Experiments to track ML training runs, hyperparameters, metrics, and model artifacts. This enables reproducibility and auditability.

Reference

Informational N/A
777788889999 us-east-2 SM-01
SageMaker Internet Access Check
Details and remediation
Details

No SageMaker notebook instances or domains found to check

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 SM-02
SageMaker SSO Configuration Check
Details and remediation
Details

No SageMaker domains found, or all domains use SSO with IAM Identity Center configured

Resolution

No action required

Reference

Medium Passed
777788889999 us-east-2 SM-03
Data Protection Check
Details and remediation
Details

No SageMaker resources found to check for data protection

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 SM-04
GuardDuty Enabled
Details and remediation
Details

Amazon GuardDuty is properly enabled and monitoring for security threats in SageMaker workloads.

Resolution

No action required

Reference

Medium Passed
777788889999 us-east-2 SM-05
SageMaker Model Registry Issue
Details and remediation
Details

No model package groups found

Resolution

Implement model versioning using SageMaker Model Registry to track model lineage, approve model versions, and manage model deployment

Reference

Informational N/A
777788889999 us-east-2 SM-05
SageMaker Feature Store Issue
Details and remediation
Details

No feature groups found

Resolution

Utilize SageMaker Feature Store to create, share, and manage features for machine learning development and production

Reference

Informational N/A
777788889999 us-east-2 SM-05
SageMaker Pipelines Issue
Details and remediation
Details

No ML pipelines found

Resolution

Implement SageMaker Pipelines to automate and manage ML workflows, including data preparation, training, and model deployment

Reference

Informational N/A
777788889999 us-east-2 SM-06
SageMaker Clarify No Clarify Usage
Details and remediation
Details

No SageMaker Clarify jobs found

Resolution

Implement SageMaker Clarify for model explainability and bias detection

Reference

Informational N/A
777788889999 us-east-2 SM-07
SageMaker Model Monitor No Model Monitoring
Details and remediation
Details

No Model Monitor schedules found

Resolution

Configure comprehensive model monitoring schedules

Reference

Informational N/A
777788889999 us-east-2 SM-08
Model Registry Registry Not Used
Details and remediation
Details

Model Registry is not being utilized

Resolution

Implement proper model versioning and approval workflows

Reference

Informational N/A
777788889999 us-east-2 SM-09
SageMaker Notebook Root Access Check
Details and remediation
Details

No notebook instances found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 SM-10
SageMaker Notebook VPC Deployment Check
Details and remediation
Details

No notebook instances found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 SM-11
SageMaker Model Network Isolation Check
Details and remediation
Details

No models found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 SM-12
SageMaker Endpoint Instance Count Check
Details and remediation
Details

No InService endpoints found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 SM-13
SageMaker Monitoring Network Isolation Check
Details and remediation
Details

No monitoring schedules found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 SM-14
SageMaker Model Repository Access Check
Details and remediation
Details

No models found or all use default Platform access

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 SM-15
SageMaker Feature Store Encryption Check
Details and remediation
Details

No feature groups with offline stores found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 SM-16
SageMaker Data Quality Job Encryption Check
Details and remediation
Details

No data quality job definitions found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 SM-17
SageMaker Processing Job Encryption Check
Details and remediation
Details

No processing jobs found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 SM-18
SageMaker Transform Job Encryption Check
Details and remediation
Details

No transform jobs found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 SM-19
SageMaker Hyperparameter Tuning Job Encryption Check
Details and remediation
Details

No hyperparameter tuning jobs found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 SM-20
SageMaker Compilation Job Encryption Check
Details and remediation
Details

No compilation jobs found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 SM-21
SageMaker AutoML Job Network Isolation Check
Details and remediation
Details

No AutoML jobs found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-2 SM-22
Model Approval Workflow Check
Details and remediation
Details

No model package groups found. Model Registry is not being used for model governance.

Resolution

Implement Model Registry to track model versions and enforce approval workflows before production deployment.

Reference

Informational N/A
777788889999 us-east-2 SM-23
Model Drift Detection Check
Details and remediation
Details

No InService endpoints found to monitor.

Resolution

No action required

Reference

Medium Passed
777788889999 us-east-2 SM-24
A/B Testing and Shadow Deployment Check
Details and remediation
Details

No InService endpoints found.

Resolution

No action required

Reference

Low Passed
777788889999 us-east-2 SM-25
ML Lineage Tracking - Experiments Not Used
Details and remediation
Details

No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Implement SageMaker Experiments to track ML training runs, hyperparameters, metrics, and model artifacts. This enables reproducibility and auditability.

Reference

Informational N/A
777788889999 Global SM-02
SageMaker Full Access Policy Used
Details and remediation
Details

Role 'aiml-sec-test-resources-SageMakerFullAccessRole-ZREdSNCErx2S' has AmazonSageMakerFullAccess policy attached

Resolution

Replace AmazonSageMakerFullAccess with more restrictive custom policies that follow the principle of least privilege

Reference

High Failed
777788889999 us-east-1 SM-01
Direct Internet Access Enabled
Details and remediation
Details

SageMaker notebook instance 'aiml-sec-test-notebook-with-internet' has direct internet access enabled

Resolution

Configure the notebook instance to use VPC connectivity and disable direct internet access

Reference

High Failed
777788889999 us-east-1 SM-01
Non-VPC Only Network Access
Details and remediation
Details

SageMaker domain 'd-ilmtsfeenavc' (aiml-sec-test-domain-fail-028e1010-52cbf970) is not configured for VPC-only access

Resolution

Configure the SageMaker domain to use VPC-only network access type

Reference

High Failed
777788889999 us-east-1 SM-01
Non-VPC Only Network Access
Details and remediation
Details

SageMaker domain 'd-cmz7ohkxxop3' (aiml-sec-test-domain-fail-fef4e7f0-bb429d11) is not configured for VPC-only access

Resolution

Configure the SageMaker domain to use VPC-only network access type

Reference

High Failed
777788889999 us-east-1 SM-02
SSO Not Properly Configured
Details and remediation
Details

SageMaker domain 'd-7zl8skw96ppk' (aiml-sec-test-domain-pass-028e1010-3dba8b08) is using authentication mode: IAM

Resolution

Enable and properly configure AWS IAM Identity Center (successor to AWS SSO) for centralized access management. Ensure Identity Store ID is configured.

Reference

Medium Failed
777788889999 us-east-1 SM-02
SSO Not Properly Configured
Details and remediation
Details

SageMaker domain 'd-ilmtsfeenavc' (aiml-sec-test-domain-fail-028e1010-52cbf970) is using authentication mode: IAM

Resolution

Enable and properly configure AWS IAM Identity Center (successor to AWS SSO) for centralized access management. Ensure Identity Store ID is configured.

Reference

Medium Failed
777788889999 us-east-1 SM-02
SSO Not Properly Configured
Details and remediation
Details

SageMaker domain 'd-uqjoi05f0zzp' (aiml-sec-test-domain-pass-fef4e7f0-51d1e898) is using authentication mode: IAM

Resolution

Enable and properly configure AWS IAM Identity Center (successor to AWS SSO) for centralized access management. Ensure Identity Store ID is configured.

Reference

Medium Failed
777788889999 us-east-1 SM-02
SSO Not Properly Configured
Details and remediation
Details

SageMaker domain 'd-cmz7ohkxxop3' (aiml-sec-test-domain-fail-fef4e7f0-bb429d11) is using authentication mode: IAM

Resolution

Enable and properly configure AWS IAM Identity Center (successor to AWS SSO) for centralized access management. Ensure Identity Store ID is configured.

Reference

Medium Failed
777788889999 us-east-1 SM-03
Missing Encryption Configuration
Details and remediation
Details

Notebook Instance 'aiml-sec-test-notebook-with-internet' - No KMS key configured

Resolution

Configure encryption using AWS KMS customer managed keys for enhanced security

Reference

High Failed
777788889999 us-east-1 SM-03
Missing Encryption Configuration
Details and remediation
Details

Domain 'aiml-sec-test-domain-fail-028e1010-52cbf970' - No KMS key configured

Resolution

Configure encryption using AWS KMS customer managed keys for enhanced security

Reference

High Failed
777788889999 us-east-1 SM-03
Missing Encryption Configuration
Details and remediation
Details

Domain 'aiml-sec-test-domain-fail-fef4e7f0-bb429d11' - No KMS key configured

Resolution

Configure encryption using AWS KMS customer managed keys for enhanced security

Reference

High Failed
777788889999 us-east-1 SM-03
Missing Encryption Configuration
Details and remediation
Details

Training Job 'aiml-sec-test-training-no-encryption-028e1010-e2fb8765' - No output encryption configured

Resolution

Configure encryption using AWS KMS customer managed keys for enhanced security

Reference

High Failed
777788889999 us-east-1 SM-03
Missing VPC Encryption
Details and remediation
Details

Training Job 'aiml-sec-test-training-no-encryption-028e1010-e2fb8765' - Inter-container traffic encryption not enabled

Resolution

Enable encryption for inter-container traffic and VPC communication

Reference

Medium Failed
777788889999 us-east-1 SM-04
GuardDuty Enabled
Details and remediation
Details

Amazon GuardDuty is properly enabled and monitoring for security threats in SageMaker workloads.

Resolution

No action required

Reference

Medium Passed
777788889999 us-east-1 SM-05
SageMaker Model Registry Issue
Details and remediation
Details

Model group 'aiml-sec-test-model-package-group' has minimal versioning

Resolution

Implement model versioning using SageMaker Model Registry to track model lineage, approve model versions, and manage model deployment

Reference

Low Failed
777788889999 us-east-1 SM-05
SageMaker Pipelines Issue
Details and remediation
Details

No ML pipelines found

Resolution

Implement SageMaker Pipelines to automate and manage ML workflows, including data preparation, training, and model deployment

Reference

Informational N/A
777788889999 us-east-1 SM-06
SageMaker Clarify No Clarify Usage
Details and remediation
Details

No SageMaker Clarify jobs found

Resolution

Implement SageMaker Clarify for model explainability and bias detection

Reference

Informational N/A
777788889999 us-east-1 SM-07
SageMaker Model Monitor No Model Monitoring
Details and remediation
Details

No Model Monitor schedules found

Resolution

Configure comprehensive model monitoring schedules

Reference

Informational N/A
777788889999 us-east-1 SM-08
Model Registry Empty Model Group
Details and remediation
Details

Model group aiml-sec-test-model-package-group has no registered models

Resolution

Implement proper model versioning and approval workflows

Reference

Low Failed
777788889999 us-east-1 SM-09
SageMaker Notebook Root Access Enabled
Details and remediation
Details

Notebook instance 'aiml-sec-test-notebook-with-internet' has root access enabled. Root access allows users to install arbitrary software, modify system configurations, and potentially escalate privileges.

Resolution

Disable root access by updating the notebook instance with RootAccess=Disabled. Note: Lifecycle configurations will still run with root access.

Reference

High Failed
777788889999 us-east-1 SM-10
SageMaker Notebook Not in VPC
Details and remediation
Details

Notebook instance 'aiml-sec-test-notebook-with-internet' is not deployed in a custom VPC. This uses SageMaker's service VPC with reduced network isolation.

Resolution

Create the notebook instance within a custom VPC by specifying SubnetId and SecurityGroupIds. This provides network isolation and allows use of VPC endpoints.

Reference

High Failed
777788889999 us-east-1 SM-11
SageMaker Model Network Isolation Disabled
Details and remediation
Details

Model 'SageMakerModelNoIsolation-yQ7EpJeL7pgI' does not have network isolation enabled. Model containers can make outbound network calls, potentially exfiltrating data.

Resolution

Enable network isolation by setting EnableNetworkIsolation=True when creating models. This prevents containers from making outbound network calls.

Reference

High Failed
777788889999 us-east-1 SM-12
SageMaker Endpoint Instance Count Check
Details and remediation
Details

No InService endpoints found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-1 SM-13
SageMaker Monitoring Network Isolation Check
Details and remediation
Details

No monitoring schedules found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-1 SM-14
SageMaker Model Platform Repository Access
Details and remediation
Details

Model 'SageMakerModelWithIsolation-JASFpUHjajdk' uses Platform repository access mode. Container images are pulled from public/external registries, exposing supply chain risks.

Resolution

Configure RepositoryAccessMode=Vpc in ImageConfig to pull images from private ECR repositories through VPC. This provides supply chain security.

Reference

Medium Failed
777788889999 us-east-1 SM-14
SageMaker Model Platform Repository Access
Details and remediation
Details

Model 'SageMakerModelNoIsolation-yQ7EpJeL7pgI' uses Platform repository access mode. Container images are pulled from public/external registries, exposing supply chain risks.

Resolution

Configure RepositoryAccessMode=Vpc in ImageConfig to pull images from private ECR repositories through VPC. This provides supply chain security.

Reference

Medium Failed
777788889999 us-east-1 SM-15
SageMaker Feature Store Offline Encryption Missing
Details and remediation
Details

Feature group 'aiml-sec-test-feature-group' offline store does not have KMS encryption configured. Feature data in S3 may not be encrypted with customer-managed keys.

Resolution

Configure KmsKeyId in OfflineStoreConfig.S3StorageConfig when creating feature groups to encrypt offline store data with customer-managed KMS keys.

Reference

Medium Failed
777788889999 us-east-1 SM-16
SageMaker Data Quality Job Encryption Check
Details and remediation
Details

No data quality job definitions found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-1 SM-17
SageMaker Processing Job Encryption Check
Details and remediation
Details

All 1 processing jobs have volume encryption configured

Resolution

No action required

Reference

Medium Passed
777788889999 us-east-1 SM-18
SageMaker Transform Job Encryption Check
Details and remediation
Details

All 1 transform jobs have volume encryption configured

Resolution

No action required

Reference

Medium Passed
777788889999 us-east-1 SM-19
SageMaker Hyperparameter Tuning Job Encryption Check
Details and remediation
Details

No hyperparameter tuning jobs found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-1 SM-20
SageMaker Compilation Job Encryption Check
Details and remediation
Details

No compilation jobs found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-1 SM-21
SageMaker AutoML Job Network Isolation Check
Details and remediation
Details

No AutoML jobs found

Resolution

No action required

Reference

Informational N/A
777788889999 us-east-1 SM-22
Model Approval Workflow Check
Details and remediation
Details

Checked 1 model package groups. Approval workflows appear to be properly configured.

Resolution

No action required

Reference

Medium Passed
777788889999 us-east-1 SM-23
Model Drift Detection Check
Details and remediation
Details

No InService endpoints found to monitor.

Resolution

No action required

Reference

Medium Passed
777788889999 us-east-1 SM-24
A/B Testing and Shadow Deployment Check
Details and remediation
Details

No InService endpoints found.

Resolution

No action required

Reference

Low Passed
777788889999 us-east-1 SM-25
ML Lineage Tracking - Experiments Not Used
Details and remediation
Details

No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Implement SageMaker Experiments to track ML training runs, hyperparameters, metrics, and model artifacts. This enables reproducibility and auditability.

Reference

Informational N/A
777788889999 us-west-2 SM-01
SageMaker Internet Access Check
Details and remediation
Details

No SageMaker notebook instances or domains found to check

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 SM-02
SageMaker SSO Configuration Check
Details and remediation
Details

No SageMaker domains found, or all domains use SSO with IAM Identity Center configured

Resolution

No action required

Reference

Medium Passed
777788889999 us-west-2 SM-03
Data Protection Check
Details and remediation
Details

No SageMaker resources found to check for data protection

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 SM-04
GuardDuty Enabled
Details and remediation
Details

Amazon GuardDuty is properly enabled and monitoring for security threats in SageMaker workloads.

Resolution

No action required

Reference

Medium Passed
777788889999 us-west-2 SM-05
SageMaker Model Registry Issue
Details and remediation
Details

No model package groups found

Resolution

Implement model versioning using SageMaker Model Registry to track model lineage, approve model versions, and manage model deployment

Reference

Informational N/A
777788889999 us-west-2 SM-05
SageMaker Feature Store Issue
Details and remediation
Details

No feature groups found

Resolution

Utilize SageMaker Feature Store to create, share, and manage features for machine learning development and production

Reference

Informational N/A
777788889999 us-west-2 SM-05
SageMaker Pipelines Issue
Details and remediation
Details

No ML pipelines found

Resolution

Implement SageMaker Pipelines to automate and manage ML workflows, including data preparation, training, and model deployment

Reference

Informational N/A
777788889999 us-west-2 SM-06
SageMaker Clarify No Clarify Usage
Details and remediation
Details

No SageMaker Clarify jobs found

Resolution

Implement SageMaker Clarify for model explainability and bias detection

Reference

Informational N/A
777788889999 us-west-2 SM-07
SageMaker Model Monitor No Model Monitoring
Details and remediation
Details

No Model Monitor schedules found

Resolution

Configure comprehensive model monitoring schedules

Reference

Informational N/A
777788889999 us-west-2 SM-08
Model Registry Registry Not Used
Details and remediation
Details

Model Registry is not being utilized

Resolution

Implement proper model versioning and approval workflows

Reference

Informational N/A
777788889999 us-west-2 SM-09
SageMaker Notebook Root Access Check
Details and remediation
Details

No notebook instances found

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 SM-10
SageMaker Notebook VPC Deployment Check
Details and remediation
Details

No notebook instances found

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 SM-11
SageMaker Model Network Isolation Check
Details and remediation
Details

No models found

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 SM-12
SageMaker Endpoint Instance Count Check
Details and remediation
Details

No InService endpoints found

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 SM-13
SageMaker Monitoring Network Isolation Check
Details and remediation
Details

No monitoring schedules found

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 SM-14
SageMaker Model Repository Access Check
Details and remediation
Details

No models found or all use default Platform access

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 SM-15
SageMaker Feature Store Encryption Check
Details and remediation
Details

No feature groups with offline stores found

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 SM-16
SageMaker Data Quality Job Encryption Check
Details and remediation
Details

No data quality job definitions found

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 SM-17
SageMaker Processing Job Encryption Check
Details and remediation
Details

No processing jobs found

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 SM-18
SageMaker Transform Job Encryption Check
Details and remediation
Details

No transform jobs found

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 SM-19
SageMaker Hyperparameter Tuning Job Encryption Check
Details and remediation
Details

No hyperparameter tuning jobs found

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 SM-20
SageMaker Compilation Job Encryption Check
Details and remediation
Details

No compilation jobs found

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 SM-21
SageMaker AutoML Job Network Isolation Check
Details and remediation
Details

No AutoML jobs found

Resolution

No action required

Reference

Informational N/A
777788889999 us-west-2 SM-22
Model Approval Workflow Check
Details and remediation
Details

No model package groups found. Model Registry is not being used for model governance.

Resolution

Implement Model Registry to track model versions and enforce approval workflows before production deployment.

Reference

Informational N/A
777788889999 us-west-2 SM-23
Model Drift Detection Check
Details and remediation
Details

No InService endpoints found to monitor.

Resolution

No action required

Reference

Medium Passed
777788889999 us-west-2 SM-24
A/B Testing and Shadow Deployment Check
Details and remediation
Details

No InService endpoints found.

Resolution

No action required

Reference

Low Passed
777788889999 us-west-2 SM-25
ML Lineage Tracking - Experiments Not Used
Details and remediation
Details

No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized.

Resolution

Implement SageMaker Experiments to track ML training runs, hyperparameters, metrics, and model artifacts. This enables reproducibility and auditability.

Reference

Informational N/A
Amazon Bedrock Findings
Failed
51
Open findings
Passed
20
Controls met
N/A
318
Not applicable
Total
389
Rows in report
Amazon SageMaker Findings
Failed
42
Open findings
Passed
50
Controls met
N/A
251
Not applicable
Total
343
Rows in report
Amazon Bedrock AgentCore Findings
Failed
39
Open findings
Passed
3
Controls met
N/A
110
Not applicable
Total
152
Rows in report
Agentic AI Security Findings

Scope: API-provable Agentic AI security controls mapped to the AWS Well-Architected Agentic AI Lens security guidance. Human-in-the-loop governance is referenced in methodology but not scored automatically unless an AWS API can prove the control.

Failed
47
Open findings
Passed
18
Controls met
N/A
251
Not applicable
Total
316
Rows in report
Financial Services GenAI Risk Findings

Scope: this assessment records findings against each resolved CloudFormation TargetRegions entry. These checks are based on the AWS User Guide to Governance, Risk, and Compliance for Responsible AI Adoption. Severities follow a documented Likelihood × Impact methodology.

Failed
122
Open findings
Passed
55
Controls met
N/A
95
Not applicable
Total
272
Rows in report
OWASP Top 10 for LLM Findings

Scope: mapping-based derivation from existing BR/SM/AC/AG/FS checks plus two net-new checks for LLM07 (System Prompt Leakage). Each finding's OWASP category (LLM01–LLM10) is encoded in the Finding_Details text. Preliminary and illustrative — validate mappings with your Security/Compliance team before using as evidence.

Failed
167
Open findings
Passed
87
Controls met
N/A
433
Not applicable
Total
687
Rows in report
Assessment Methodology

Assessment Notes

Point-in-time: Security posture changes as resources are modified. Scope limited: Passed checks verify tested controls only. Context matters: Adjust severity for compliance requirements and environment type.

Assessment Scope

Amazon Bedrock
Amazon SageMaker
Amazon Bedrock AgentCore
Agentic AI Security
Agentic AI Security Lens Mapping
Industry
Financial Services GenAI Risk
By Compliance Standard
OWASP Top 10 LLM

Bedrock, SageMaker, and AgentCore checks are based on the AWS Well-Architected Framework Generative AI Lens. Agentic AI Security references the AWS Well-Architected Agentic AI Lens. Controls that cannot be proven using AWS APIs, including semantic human-in-the-loop workflow quality, are not automatically scored. Financial Services GenAI Risk checks are based on the AWS User Guide to Governance, Risk, and Compliance for Responsible AI Adoption. OWASP Top 10 LLM references OWASP Top 10 LLM.