Security Assessment Overview
Priority Recommendations
Severity Legend
View full methodology| Severity | Meaning | Recommended Action |
|---|---|---|
| High | Direct security risk - IAM/access control gaps, missing audit trails, guardrail bypasses that could lead to unauthorized access or data exposure | Remediate within 7 days |
| Medium | Defense-in-depth gaps - encryption, logging, or configuration issues that reduce security posture | Remediate within 30 days |
| Low | Best practice deviations - optimization opportunities that improve security hygiene | Remediate within 90 days |
| Informational | Not applicable, unavailable, no resources found, or advisory-only rows | No action required |
Direct Service Scored Control Results by Severity
Direct Failed Rows by Region / Scope
Findings by Assessment Area
| Account ID | Region | Check ID | Finding | Severity | Status |
|---|---|---|---|---|---|
123456789012 |
Global |
BR-01 |
AmazonBedrockFullAccess role check
|
High | Passed |
123456789012 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
Role 'aws-elasticbeanstalk-ec2-role' has overly permissive marketplace subscription access through policy 'AWSElasticBeanstalkMulticontainerDocker' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | Failed |
123456789012 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
Role 'RescoAppStack-Ec2Role2FD9A272-UB7xzDXt03Lg' has overly permissive marketplace subscription access through policy 'AWSElasticBeanstalkWebTier' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | Failed |
123456789012 |
Global |
BR-03 |
Marketplace Subscription Access Check
Details and remediationDetails
Role 'xray-sample-SampleInstanceProfileRole-1WB21O2X8T7ZV' has overly permissive marketplace subscription access through policy 'AWSElasticBeanstalkWebTier' Resolution
Ensure that users have access to only the models that you want user to be able to subscribe to based on your organizational policies. For example, you may want users to have access to only text based models and not image and video generation model. This can also help to keep cost in check. |
High | Failed |
123456789012 |
us-east-1 |
BR-02 |
Amazon Bedrock private connectivity check
|
Informational | N/A |
123456789012 |
us-east-1 |
BR-04 |
Bedrock Model Invocation Logging Check
|
Informational | N/A |
123456789012 |
us-east-1 |
BR-05 |
Bedrock Guardrails Check
|
Informational | N/A |
123456789012 |
us-east-1 |
BR-06 |
Bedrock CloudTrail Logging Check
|
Informational | N/A |
123456789012 |
us-east-1 |
BR-07 |
Bedrock Prompt Management Check
Details and remediationDetails
Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates |
Informational | N/A |
123456789012 |
us-east-1 |
BR-08 |
Bedrock Agent IAM Roles Check
|
Informational | N/A |
123456789012 |
us-east-1 |
BR-09 |
Bedrock Knowledge Base Encryption Check
|
Informational | N/A |
123456789012 |
us-east-1 |
BR-10 |
Bedrock Guardrail IAM Enforcement Check
|
Informational | N/A |
123456789012 |
us-east-1 |
BR-11 |
Bedrock Custom Model Encryption Check
|
Informational | N/A |
123456789012 |
us-east-1 |
BR-12 |
Bedrock Invocation Log Encryption Check
|
Informational | N/A |
123456789012 |
us-east-1 |
BR-13 |
Bedrock Flows Guardrails Check
|
Informational | N/A |
123456789012 |
Global |
BR-15 |
Cross-Account Guardrails Enforcement Check
|
High | Failed |
123456789012 |
us-east-1 |
BR-16 |
Guardrail Tier Validation Check
|
Medium | N/A |
123456789012 |
us-east-1 |
BR-17 |
Custom Model Customer-Managed KMS Encryption Check
|
High | N/A |
123456789012 |
us-east-1 |
BR-18 |
Model Evaluation Implementation Check
|
Informational | N/A |
123456789012 |
us-east-1 |
BR-19 |
Prompt Flow Validation Check
|
Medium | N/A |
123456789012 |
us-east-1 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Check
|
High | N/A |
123456789012 |
us-east-1 |
BR-21 |
Agent Action Group IAM Least Privilege Check
|
High | N/A |
123456789012 |
us-east-1 |
BR-22 |
Model Invocation Throttling Limits Check
|
Informational | N/A |
123456789012 |
us-east-1 |
BR-23 |
Guardrail Content Filter Coverage Check
|
Informational | N/A |
123456789012 |
us-east-1 |
BR-24 |
Automated Reasoning Policy Implementation Check
|
Medium | N/A |
123456789012 |
us-east-1 |
BR-25 |
RAG Evaluation Jobs Check
|
Low | N/A |
123456789012 |
us-east-1 |
BR-26 |
Guardrail Sensitive Information Filter Check
|
High | N/A |
123456789012 |
us-east-1 |
BR-27 |
Guardrail Contextual Grounding Check
|
Medium | N/A |
123456789012 |
us-east-1 |
BR-28 |
Agent Guardrail Association Check
|
High | N/A |
123456789012 |
us-east-1 |
BR-29 |
Agent Idle Session TTL Check
|
Low | N/A |
123456789012 |
us-east-1 |
BR-30 |
Imported Model Customer-Managed KMS Encryption Check
|
High | N/A |
123456789012 |
us-east-1 |
BR-31 |
Batch Inference Output Encryption Check
|
Medium | N/A |
123456789012 |
us-east-1 |
BR-32 |
Bedrock CloudWatch Alarm Check
|
Informational | N/A |
123456789012 |
us-east-1 |
BR-33 |
Amazon Inspector Lambda Code Scanning Check
|
Medium | Passed |
123456789012 |
us-east-1 |
BR-34 |
Guardrail Prompt Attack Filter
|
Informational | N/A |
123456789012 |
us-east-1 |
BR-35 |
Guardrail Image Content Filter Coverage
|
Informational | N/A |
123456789012 |
us-east-1 |
BR-36 |
Application Inference Profile Governance
|
Informational | N/A |
123456789012 |
us-east-1 |
BR-37 |
Bedrock Account Data Retention
|
High | Failed |
123456789012 |
us-east-1 |
BR-38 |
Automated Reasoning Policy CMK Encryption
|
Informational | N/A |
123456789012 |
us-east-1 |
BR-39 |
Marketplace Model Endpoint VPC Configuration
|
Informational | N/A |
123456789012 |
us-east-1 |
BR-40 |
Marketplace Model Endpoint CMK Encryption
|
Informational | N/A |
123456789012 |
us-east-1 |
AG-07 |
Agentic AI Model Invocation Logging
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements. |
Informational | N/A |
123456789012 |
us-east-1 |
AG-08 |
Agentic AI API Audit Trail
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage Resolution
Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured. |
Informational | N/A |
123456789012 |
Global |
AG-09 |
Agentic AI Guardrail Enforcement Boundary
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Organization-level guardrail enforcement helps prevent agents from bypassing required safety controls across accounts. Source check BR-15: The Organizations Bedrock policy type is not enabled and no account-level enforced guardrail configuration was observed. Resolution
Use IAM and organization controls to require approved guardrails for model and agent invocations where supported. |
High | Failed |
123456789012 |
us-east-1 |
AG-10 |
Agentic AI Adversarial Evaluation Coverage
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs Resolution
Configure model or application evaluations that include adversarial, safety, and security-relevant test cases. |
Informational | N/A |
123456789012 |
us-east-1 |
AG-11 |
Agentic AI Prompt Flow Validation
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region Resolution
Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions. |
Informational | N/A |
123456789012 |
us-east-1 |
AG-06 |
Agentic AI Tool Execution Least Privilege
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region Resolution
Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required. |
Informational | N/A |
123456789012 |
us-east-1 |
AG-12 |
Agentic AI Invocation Abuse Controls
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas Resolution
Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns. |
Informational | N/A |
123456789012 |
us-east-1 |
AG-02 |
Agentic AI Harmful Content Guardrail Coverage
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads. |
Informational | N/A |
123456789012 |
us-east-1 |
AG-04 |
Agentic AI Automated Reasoning Guardrails
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: No Bedrock guardrails configured in this region Resolution
Configure automated reasoning policies on guardrails where formal response validation is required. |
Informational | N/A |
123456789012 |
us-east-1 |
AG-03 |
Agentic AI Sensitive Information Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: No Bedrock guardrails configured in this region Resolution
Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns. |
Informational | N/A |
123456789012 |
us-east-1 |
AG-05 |
Agentic AI Grounding Controls
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: No Bedrock guardrails configured in this region Resolution
Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows. |
Informational | N/A |
123456789012 |
us-east-1 |
AG-01 |
Agentic AI Agent Guardrail Association
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region Resolution
Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating. |
Informational | N/A |
123456789012 |
us-east-1 |
AG-13 |
Agentic AI Session Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region Resolution
Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements. |
Informational | N/A |
123456789012 |
us-east-1 |
AG-14 |
Agentic AI Operational Abuse Alarms
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms Resolution
Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available. |
Informational | N/A |
123456789012 |
us-east-1 |
AG-30 |
Agentic AI Prompt Attack Protection
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agents should prevent prompt attacks before untrusted input can redirect planning or tool use. Source check BR-34: No Bedrock guardrails configured in this region Resolution
Enable a preventive PROMPT_ATTACK input filter on each guardrail and use Standard tier where prompt-leakage protection is required. |
Informational | N/A |
123456789012 |
us-east-2 |
BR-02 |
Amazon Bedrock private connectivity check
|
Informational | N/A |
123456789012 |
us-east-2 |
BR-04 |
Bedrock Model Invocation Logging Check
|
Informational | N/A |
123456789012 |
us-east-2 |
BR-05 |
Bedrock Guardrails Check
|
Informational | N/A |
123456789012 |
us-east-2 |
BR-06 |
Bedrock CloudTrail Logging Check
|
Informational | N/A |
123456789012 |
us-east-2 |
BR-07 |
Bedrock Prompt Management Check
Details and remediationDetails
Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates |
Informational | N/A |
123456789012 |
us-east-2 |
BR-08 |
Bedrock Agent IAM Roles Check
|
Informational | N/A |
123456789012 |
us-east-2 |
BR-09 |
Bedrock Knowledge Base Encryption Check
|
Informational | N/A |
123456789012 |
us-east-2 |
BR-10 |
Bedrock Guardrail IAM Enforcement Check
|
Informational | N/A |
123456789012 |
us-east-2 |
BR-11 |
Bedrock Custom Model Encryption Check
|
Low | N/A |
123456789012 |
us-east-2 |
BR-12 |
Bedrock Invocation Log Encryption Check
|
Informational | N/A |
123456789012 |
us-east-2 |
BR-13 |
Bedrock Flows Guardrails Check
|
Informational | N/A |
123456789012 |
us-east-2 |
BR-16 |
Guardrail Tier Validation Check
|
Medium | N/A |
123456789012 |
us-east-2 |
BR-17 |
Custom Model Customer-Managed KMS Encryption Check
|
Informational | N/A |
123456789012 |
us-east-2 |
BR-18 |
Model Evaluation Implementation Check
|
Informational | N/A |
123456789012 |
us-east-2 |
BR-19 |
Prompt Flow Validation Check
|
Medium | N/A |
123456789012 |
us-east-2 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Check
|
High | N/A |
123456789012 |
us-east-2 |
BR-21 |
Agent Action Group IAM Least Privilege Check
|
High | N/A |
123456789012 |
us-east-2 |
BR-22 |
Model Invocation Throttling Limits Check
|
Informational | N/A |
123456789012 |
us-east-2 |
BR-23 |
Guardrail Content Filter Coverage Check
|
Informational | N/A |
123456789012 |
us-east-2 |
BR-24 |
Automated Reasoning Policy Implementation Check
|
Medium | N/A |
123456789012 |
us-east-2 |
BR-25 |
RAG Evaluation Jobs Check
|
Low | N/A |
123456789012 |
us-east-2 |
BR-26 |
Guardrail Sensitive Information Filter Check
|
High | N/A |
123456789012 |
us-east-2 |
BR-27 |
Guardrail Contextual Grounding Check
|
Medium | N/A |
123456789012 |
us-east-2 |
BR-28 |
Agent Guardrail Association Check
|
High | N/A |
123456789012 |
us-east-2 |
BR-29 |
Agent Idle Session TTL Check
|
Low | N/A |
123456789012 |
us-east-2 |
BR-30 |
Imported Model Customer-Managed KMS Encryption Check
|
High | N/A |
123456789012 |
us-east-2 |
BR-31 |
Batch Inference Output Encryption Check
|
Medium | N/A |
123456789012 |
us-east-2 |
BR-32 |
Bedrock CloudWatch Alarm Check
|
Informational | N/A |
123456789012 |
us-east-2 |
BR-33 |
Amazon Inspector Lambda Code Scanning Check
Details and remediationDetails
No Lambda functions with Bedrock indicators were found in us-east-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
No action required. If Bedrock-calling Lambda functions exist, ensure their function name, ARN, description, handler, role, or environment variables contain a Bedrock identifier that the assessment can detect, or evaluate Inspector coverage manually. |
Informational | N/A |
123456789012 |
us-east-2 |
BR-34 |
Guardrail Prompt Attack Filter
|
Informational | N/A |
123456789012 |
us-east-2 |
BR-35 |
Guardrail Image Content Filter Coverage
|
Informational | N/A |
123456789012 |
us-east-2 |
BR-36 |
Application Inference Profile Governance
|
Informational | N/A |
123456789012 |
us-east-2 |
BR-37 |
Bedrock Account Data Retention
|
High | Failed |
123456789012 |
us-east-2 |
BR-38 |
Automated Reasoning Policy CMK Encryption
|
Informational | N/A |
123456789012 |
us-east-2 |
BR-39 |
Marketplace Model Endpoint VPC Configuration
|
Informational | N/A |
123456789012 |
us-east-2 |
BR-40 |
Marketplace Model Endpoint CMK Encryption
|
Informational | N/A |
123456789012 |
us-east-2 |
AG-07 |
Agentic AI Model Invocation Logging
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements. |
Informational | N/A |
123456789012 |
us-east-2 |
AG-08 |
Agentic AI API Audit Trail
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage Resolution
Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured. |
Informational | N/A |
123456789012 |
us-east-2 |
AG-10 |
Agentic AI Adversarial Evaluation Coverage
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs Resolution
Configure model or application evaluations that include adversarial, safety, and security-relevant test cases. |
Informational | N/A |
123456789012 |
us-east-2 |
AG-11 |
Agentic AI Prompt Flow Validation
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region Resolution
Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions. |
Informational | N/A |
123456789012 |
us-east-2 |
AG-06 |
Agentic AI Tool Execution Least Privilege
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region Resolution
Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required. |
Informational | N/A |
123456789012 |
us-east-2 |
AG-12 |
Agentic AI Invocation Abuse Controls
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas Resolution
Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns. |
Informational | N/A |
123456789012 |
us-east-2 |
AG-02 |
Agentic AI Harmful Content Guardrail Coverage
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads. |
Informational | N/A |
123456789012 |
us-east-2 |
AG-04 |
Agentic AI Automated Reasoning Guardrails
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: No Bedrock guardrails configured in this region Resolution
Configure automated reasoning policies on guardrails where formal response validation is required. |
Informational | N/A |
123456789012 |
us-east-2 |
AG-03 |
Agentic AI Sensitive Information Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: No Bedrock guardrails configured in this region Resolution
Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns. |
Informational | N/A |
123456789012 |
us-east-2 |
AG-05 |
Agentic AI Grounding Controls
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: No Bedrock guardrails configured in this region Resolution
Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows. |
Informational | N/A |
123456789012 |
us-east-2 |
AG-01 |
Agentic AI Agent Guardrail Association
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region Resolution
Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating. |
Informational | N/A |
123456789012 |
us-east-2 |
AG-13 |
Agentic AI Session Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region Resolution
Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements. |
Informational | N/A |
123456789012 |
us-east-2 |
AG-14 |
Agentic AI Operational Abuse Alarms
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms Resolution
Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available. |
Informational | N/A |
123456789012 |
us-east-2 |
AG-30 |
Agentic AI Prompt Attack Protection
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agents should prevent prompt attacks before untrusted input can redirect planning or tool use. Source check BR-34: No Bedrock guardrails configured in this region Resolution
Enable a preventive PROMPT_ATTACK input filter on each guardrail and use Standard tier where prompt-leakage protection is required. |
Informational | N/A |
123456789012 |
us-west-2 |
BR-02 |
Amazon Bedrock private connectivity check
|
Informational | N/A |
123456789012 |
us-west-2 |
BR-04 |
Bedrock Model Invocation Logging Check
|
Informational | N/A |
123456789012 |
us-west-2 |
BR-05 |
Bedrock Guardrails Check
|
Informational | N/A |
123456789012 |
us-west-2 |
BR-06 |
Bedrock CloudTrail Logging Check
|
Informational | N/A |
123456789012 |
us-west-2 |
BR-07 |
Bedrock Prompt Management Check
Details and remediationDetails
Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Implement Prompt Management to: 1. Create and version your prompts 2. Test different prompt variants 3. Share prompts across your organization 4. Maintain consistent prompt templates |
Informational | N/A |
123456789012 |
us-west-2 |
BR-08 |
Bedrock Agent IAM Roles Check
|
Informational | N/A |
123456789012 |
us-west-2 |
BR-09 |
Bedrock Knowledge Base Encryption Check
|
Informational | N/A |
123456789012 |
us-west-2 |
BR-10 |
Bedrock Guardrail IAM Enforcement Check
|
Informational | N/A |
123456789012 |
us-west-2 |
BR-11 |
Bedrock Custom Model Encryption Check
|
Informational | N/A |
123456789012 |
us-west-2 |
BR-12 |
Bedrock Invocation Log Encryption Check
|
Informational | N/A |
123456789012 |
us-west-2 |
BR-13 |
Bedrock Flows Guardrails Check
|
Informational | N/A |
123456789012 |
us-west-2 |
BR-16 |
Guardrail Tier Validation Check
|
Medium | N/A |
123456789012 |
us-west-2 |
BR-17 |
Custom Model Customer-Managed KMS Encryption Check
|
High | N/A |
123456789012 |
us-west-2 |
BR-18 |
Model Evaluation Implementation Check
|
Informational | N/A |
123456789012 |
us-west-2 |
BR-19 |
Prompt Flow Validation Check
|
Medium | N/A |
123456789012 |
us-west-2 |
BR-20 |
Knowledge Base Customer-Managed KMS Encryption Check
|
High | N/A |
123456789012 |
us-west-2 |
BR-21 |
Agent Action Group IAM Least Privilege Check
|
High | N/A |
123456789012 |
us-west-2 |
BR-22 |
Model Invocation Throttling Limits Check
|
Informational | N/A |
123456789012 |
us-west-2 |
BR-23 |
Guardrail Content Filter Coverage Check
|
Informational | N/A |
123456789012 |
us-west-2 |
BR-24 |
Automated Reasoning Policy Implementation Check
|
Medium | N/A |
123456789012 |
us-west-2 |
BR-25 |
RAG Evaluation Jobs Check
|
Low | N/A |
123456789012 |
us-west-2 |
BR-26 |
Guardrail Sensitive Information Filter Check
|
High | N/A |
123456789012 |
us-west-2 |
BR-27 |
Guardrail Contextual Grounding Check
|
Medium | N/A |
123456789012 |
us-west-2 |
BR-28 |
Agent Guardrail Association Check
|
High | N/A |
123456789012 |
us-west-2 |
BR-29 |
Agent Idle Session TTL Check
|
Low | N/A |
123456789012 |
us-west-2 |
BR-30 |
Imported Model Customer-Managed KMS Encryption Check
|
High | N/A |
123456789012 |
us-west-2 |
BR-31 |
Batch Inference Output Encryption Check
|
Medium | N/A |
123456789012 |
us-west-2 |
BR-32 |
Bedrock CloudWatch Alarm Check
|
Informational | N/A |
123456789012 |
us-west-2 |
BR-33 |
Amazon Inspector Lambda Code Scanning Check
Details and remediationDetails
No Lambda functions with Bedrock indicators were found in us-west-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
No action required. If Bedrock-calling Lambda functions exist, ensure their function name, ARN, description, handler, role, or environment variables contain a Bedrock identifier that the assessment can detect, or evaluate Inspector coverage manually. |
Informational | N/A |
123456789012 |
us-west-2 |
BR-34 |
Guardrail Prompt Attack Filter
|
Informational | N/A |
123456789012 |
us-west-2 |
BR-35 |
Guardrail Image Content Filter Coverage
|
Informational | N/A |
123456789012 |
us-west-2 |
BR-36 |
Application Inference Profile Governance
|
Informational | N/A |
123456789012 |
us-west-2 |
BR-37 |
Bedrock Account Data Retention
|
High | Failed |
123456789012 |
us-west-2 |
BR-38 |
Automated Reasoning Policy CMK Encryption
|
Informational | N/A |
123456789012 |
us-west-2 |
BR-39 |
Marketplace Model Endpoint VPC Configuration
|
Informational | N/A |
123456789012 |
us-west-2 |
BR-40 |
Marketplace Model Endpoint CMK Encryption
|
Informational | N/A |
123456789012 |
us-west-2 |
AG-07 |
Agentic AI Model Invocation Logging
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agents can take multi-step actions, so prompt, response, and guardrail traces need to be available for investigation. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Amazon Bedrock model invocation logging and retain logs according to your incident response and data governance requirements. |
Informational | N/A |
123456789012 |
us-west-2 |
AG-08 |
Agentic AI API Audit Trail
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. Agent activity must be attributable through CloudTrail events for Bedrock control plane and runtime operations. Source check BR-06: No regional Bedrock resources found to audit with Bedrock-specific CloudTrail coverage Resolution
Enable CloudTrail trails with management event logging and validate that Bedrock API activity is captured. |
Informational | N/A |
123456789012 |
us-west-2 |
AG-10 |
Agentic AI Adversarial Evaluation Coverage
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agentic applications should be tested for adversarial prompts and unsafe behaviors before production use. Source check BR-18: No regional Bedrock resources found to assess with model evaluation jobs Resolution
Configure model or application evaluations that include adversarial, safety, and security-relevant test cases. |
Informational | N/A |
123456789012 |
us-west-2 |
AG-11 |
Agentic AI Prompt Flow Validation
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Validated prompt flows reduce the risk that malformed orchestration logic causes unsafe agent behavior. Source check BR-19: No Bedrock prompt flows configured in this region Resolution
Validate Bedrock flow definitions before deployment and remediate validation findings before publishing new versions. |
Informational | N/A |
123456789012 |
us-west-2 |
AG-06 |
Agentic AI Tool Execution Least Privilege
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Agent action groups are tool execution boundaries; over-permissive roles can let an agent perform unintended operations. Source check BR-21: No Bedrock agents configured in this region Resolution
Restrict action group Lambda roles and referenced IAM permissions to the specific tools, resources, and actions required. |
Informational | N/A |
123456789012 |
us-west-2 |
AG-12 |
Agentic AI Invocation Abuse Controls
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. Autonomous agents can amplify token usage through retries, loops, or high-volume tool workflows. Source check BR-22: No regional Bedrock resources found to assess model invocation throttling quotas Resolution
Configure service quotas, throttling limits, and alerting to detect and limit abnormal model invocation patterns. |
Informational | N/A |
123456789012 |
us-west-2 |
AG-02 |
Agentic AI Harmful Content Guardrail Coverage
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Agents should use guardrails that filter harmful content in both intermediate and final responses. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Configure guardrails with appropriate content filters and thresholds for all agent-facing workloads. |
Informational | N/A |
123456789012 |
us-west-2 |
AG-04 |
Agentic AI Automated Reasoning Guardrails
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Automated reasoning policies help verify agent responses against deterministic business or safety rules. Source check BR-24: No Bedrock guardrails configured in this region Resolution
Configure automated reasoning policies on guardrails where formal response validation is required. |
Informational | N/A |
123456789012 |
us-west-2 |
AG-03 |
Agentic AI Sensitive Information Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agents can receive and produce sensitive data across conversations, tool calls, and retrieved context. Source check BR-26: No Bedrock guardrails configured in this region Resolution
Configure guardrail sensitive-information filters for PII entities and custom sensitive-data patterns. |
Informational | N/A |
123456789012 |
us-west-2 |
AG-05 |
Agentic AI Grounding Controls
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Grounding checks reduce the chance that an agent acts on hallucinated or irrelevant context. Source check BR-27: No Bedrock guardrails configured in this region Resolution
Enable contextual grounding checks on guardrails for RAG and tool-using agent workflows. |
Informational | N/A |
123456789012 |
us-west-2 |
AG-01 |
Agentic AI Agent Guardrail Association
Details and remediationDetails
Agentic AI security domain: Guardrail Enforcement. Bedrock agents should have guardrails associated so autonomous interactions are filtered consistently. Source check BR-28: No Bedrock agents configured in this region Resolution
Associate an approved Bedrock guardrail with each Bedrock agent and prepare the agent after updating. |
Informational | N/A |
123456789012 |
us-west-2 |
AG-13 |
Agentic AI Session Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Long-lived idle sessions widen the window for session reuse and unintended continuation of agent context. Source check BR-29: No Bedrock agents configured in this region Resolution
Set a conservative idleSessionTTLInSeconds value for agents based on application session requirements. |
Informational | N/A |
123456789012 |
us-west-2 |
AG-14 |
Agentic AI Operational Abuse Alarms
Details and remediationDetails
Agentic AI security domain: Abuse & Cost Protection. CloudWatch alarms help detect anomalous invocation errors, throttling, or volume caused by autonomous workflows. Source check BR-32: No regional Bedrock resources found to monitor with CloudWatch alarms Resolution
Configure CloudWatch alarms for Bedrock invocation errors, throttles, latency, and token or request volume where metrics are available. |
Informational | N/A |
123456789012 |
us-west-2 |
AG-30 |
Agentic AI Prompt Attack Protection
Details and remediationDetails
Agentic AI security domain: Prompt & Input Protection. Agents should prevent prompt attacks before untrusted input can redirect planning or tool use. Source check BR-34: No Bedrock guardrails configured in this region Resolution
Enable a preventive PROMPT_ATTACK input filter on each guardrail and use Standard tier where prompt-leakage protection is required. |
Informational | N/A |
123456789012 |
Global |
SM-02 |
SageMaker IAM Permissions Check
|
High | Passed |
123456789012 |
us-east-1 |
SM-01 |
SageMaker Internet Access Check
|
Informational | N/A |
123456789012 |
us-east-1 |
SM-02 |
SageMaker SSO Configuration Check
|
Medium | Passed |
123456789012 |
us-east-1 |
SM-03 |
Data Protection Check
|
Informational | N/A |
123456789012 |
us-east-1 |
SM-04 |
GuardDuty Enabled
|
Medium | Passed |
123456789012 |
us-east-1 |
SM-26 |
GuardDuty AI Protection
|
High | Failed |
123456789012 |
us-east-1 |
SM-05 |
SageMaker Model Registry Issue
|
Informational | N/A |
123456789012 |
us-east-1 |
SM-05 |
SageMaker Feature Store Issue
|
Informational | N/A |
123456789012 |
us-east-1 |
SM-05 |
SageMaker Pipelines Issue
|
Informational | N/A |
123456789012 |
us-east-1 |
SM-06 |
SageMaker Clarify No Clarify Usage
|
Informational | N/A |
123456789012 |
us-east-1 |
SM-07 |
SageMaker Model Monitor No Model Monitoring
|
Informational | N/A |
123456789012 |
us-east-1 |
SM-08 |
Model Registry Registry Not Used
|
Informational | N/A |
123456789012 |
us-east-1 |
SM-09 |
SageMaker Notebook Root Access Check
|
Informational | N/A |
123456789012 |
us-east-1 |
SM-10 |
SageMaker Notebook VPC Deployment Check
|
Informational | N/A |
123456789012 |
us-east-1 |
SM-11 |
SageMaker Model Network Isolation Check
|
Informational | N/A |
123456789012 |
us-east-1 |
SM-12 |
SageMaker Endpoint Instance Count Check
|
Informational | N/A |
123456789012 |
us-east-1 |
SM-13 |
SageMaker Monitoring Network Isolation Check
|
Informational | N/A |
123456789012 |
us-east-1 |
SM-14 |
SageMaker Model Repository Access Check
|
Informational | N/A |
123456789012 |
us-east-1 |
SM-15 |
SageMaker Feature Store Encryption Check
|
Informational | N/A |
123456789012 |
us-east-1 |
SM-16 |
SageMaker Data Quality Job Encryption Check
|
Informational | N/A |
123456789012 |
us-east-1 |
SM-17 |
SageMaker Processing Job Encryption Check
|
Informational | N/A |
123456789012 |
us-east-1 |
SM-18 |
SageMaker Transform Job Encryption Check
|
Informational | N/A |
123456789012 |
us-east-1 |
SM-19 |
SageMaker Hyperparameter Tuning Job Encryption Check
|
Informational | N/A |
123456789012 |
us-east-1 |
SM-20 |
SageMaker Compilation Job Encryption Check
|
Informational | N/A |
123456789012 |
us-east-1 |
SM-21 |
SageMaker AutoML Job Network Isolation Check
|
Informational | N/A |
123456789012 |
us-east-1 |
SM-22 |
Model Approval Workflow Check
|
Informational | N/A |
123456789012 |
us-east-1 |
SM-23 |
Model Drift Detection Check
|
Medium | Passed |
123456789012 |
us-east-1 |
SM-24 |
A/B Testing and Shadow Deployment Check
|
Low | Passed |
123456789012 |
us-east-1 |
SM-25 |
ML Lineage Tracking - Experiments Not Used
|
Informational | N/A |
123456789012 |
us-east-1 |
SM-27 |
HyperPod EBS CMK Encryption
|
Informational | N/A |
123456789012 |
us-east-1 |
SM-28 |
HyperPod VPC Configuration
|
Informational | N/A |
123456789012 |
us-east-1 |
SM-30 |
Model Package Group Resource Policy Exposure
|
Informational | N/A |
123456789012 |
us-east-2 |
SM-01 |
SageMaker Internet Access Check
|
Informational | N/A |
123456789012 |
us-east-2 |
SM-02 |
SageMaker SSO Configuration Check
|
Medium | Passed |
123456789012 |
us-east-2 |
SM-03 |
Data Protection Check
|
Informational | N/A |
123456789012 |
us-east-2 |
SM-04 |
GuardDuty Enabled
|
Medium | Passed |
123456789012 |
us-east-2 |
SM-26 |
GuardDuty AI Protection
|
High | Failed |
123456789012 |
us-east-2 |
SM-05 |
SageMaker Model Registry Issue
|
Informational | N/A |
123456789012 |
us-east-2 |
SM-05 |
SageMaker Feature Store Issue
|
Informational | N/A |
123456789012 |
us-east-2 |
SM-05 |
SageMaker Pipelines Issue
|
Informational | N/A |
123456789012 |
us-east-2 |
SM-06 |
SageMaker Clarify No Clarify Usage
|
Informational | N/A |
123456789012 |
us-east-2 |
SM-07 |
SageMaker Model Monitor No Model Monitoring
|
Informational | N/A |
123456789012 |
us-east-2 |
SM-08 |
Model Registry Registry Not Used
|
Informational | N/A |
123456789012 |
us-east-2 |
SM-09 |
SageMaker Notebook Root Access Check
|
Informational | N/A |
123456789012 |
us-east-2 |
SM-10 |
SageMaker Notebook VPC Deployment Check
|
Informational | N/A |
123456789012 |
us-east-2 |
SM-11 |
SageMaker Model Network Isolation Check
|
Informational | N/A |
123456789012 |
us-east-2 |
SM-12 |
SageMaker Endpoint Instance Count Check
|
Informational | N/A |
123456789012 |
us-east-2 |
SM-13 |
SageMaker Monitoring Network Isolation Check
|
Informational | N/A |
123456789012 |
us-east-2 |
SM-14 |
SageMaker Model Repository Access Check
|
Informational | N/A |
123456789012 |
us-east-2 |
SM-15 |
SageMaker Feature Store Encryption Check
|
Informational | N/A |
123456789012 |
us-east-2 |
SM-16 |
SageMaker Data Quality Job Encryption Check
|
Informational | N/A |
123456789012 |
us-east-2 |
SM-17 |
SageMaker Processing Job Encryption Check
|
Informational | N/A |
123456789012 |
us-east-2 |
SM-18 |
SageMaker Transform Job Encryption Check
|
Informational | N/A |
123456789012 |
us-east-2 |
SM-19 |
SageMaker Hyperparameter Tuning Job Encryption Check
|
Informational | N/A |
123456789012 |
us-east-2 |
SM-20 |
SageMaker Compilation Job Encryption Check
|
Informational | N/A |
123456789012 |
us-east-2 |
SM-21 |
SageMaker AutoML Job Network Isolation Check
|
Informational | N/A |
123456789012 |
us-east-2 |
SM-22 |
Model Approval Workflow Check
|
Informational | N/A |
123456789012 |
us-east-2 |
SM-23 |
Model Drift Detection Check
|
Medium | Passed |
123456789012 |
us-east-2 |
SM-24 |
A/B Testing and Shadow Deployment Check
|
Low | Passed |
123456789012 |
us-east-2 |
SM-25 |
ML Lineage Tracking - Experiments Not Used
|
Informational | N/A |
123456789012 |
us-east-2 |
SM-27 |
HyperPod EBS CMK Encryption
|
Informational | N/A |
123456789012 |
us-east-2 |
SM-28 |
HyperPod VPC Configuration
|
Informational | N/A |
123456789012 |
us-east-2 |
SM-30 |
Model Package Group Resource Policy Exposure
|
Informational | N/A |
123456789012 |
us-west-2 |
SM-01 |
SageMaker Internet Access Check
|
Informational | N/A |
123456789012 |
us-west-2 |
SM-02 |
SageMaker SSO Configuration Check
|
Medium | Passed |
123456789012 |
us-west-2 |
SM-03 |
Data Protection Check
|
Informational | N/A |
123456789012 |
us-west-2 |
SM-04 |
GuardDuty Enabled
|
Medium | Passed |
123456789012 |
us-west-2 |
SM-26 |
GuardDuty AI Protection
|
High | Failed |
123456789012 |
us-west-2 |
SM-05 |
SageMaker Model Registry Issue
|
Informational | N/A |
123456789012 |
us-west-2 |
SM-05 |
SageMaker Feature Store Issue
|
Informational | N/A |
123456789012 |
us-west-2 |
SM-05 |
SageMaker Pipelines Issue
|
Informational | N/A |
123456789012 |
us-west-2 |
SM-06 |
SageMaker Clarify No Clarify Usage
|
Informational | N/A |
123456789012 |
us-west-2 |
SM-07 |
SageMaker Model Monitor No Model Monitoring
|
Informational | N/A |
123456789012 |
us-west-2 |
SM-08 |
Model Registry Registry Not Used
|
Informational | N/A |
123456789012 |
us-west-2 |
SM-09 |
SageMaker Notebook Root Access Check
|
Informational | N/A |
123456789012 |
us-west-2 |
SM-10 |
SageMaker Notebook VPC Deployment Check
|
Informational | N/A |
123456789012 |
us-west-2 |
SM-11 |
SageMaker Model Network Isolation Check
|
Informational | N/A |
123456789012 |
us-west-2 |
SM-12 |
SageMaker Endpoint Instance Count Check
|
Informational | N/A |
123456789012 |
us-west-2 |
SM-13 |
SageMaker Monitoring Network Isolation Check
|
Informational | N/A |
123456789012 |
us-west-2 |
SM-14 |
SageMaker Model Repository Access Check
|
Informational | N/A |
123456789012 |
us-west-2 |
SM-15 |
SageMaker Feature Store Encryption Check
|
Informational | N/A |
123456789012 |
us-west-2 |
SM-16 |
SageMaker Data Quality Job Encryption Check
|
Informational | N/A |
123456789012 |
us-west-2 |
SM-17 |
SageMaker Processing Job Encryption Check
|
Informational | N/A |
123456789012 |
us-west-2 |
SM-18 |
SageMaker Transform Job Encryption Check
|
Informational | N/A |
123456789012 |
us-west-2 |
SM-19 |
SageMaker Hyperparameter Tuning Job Encryption Check
|
Informational | N/A |
123456789012 |
us-west-2 |
SM-20 |
SageMaker Compilation Job Encryption Check
|
Informational | N/A |
123456789012 |
us-west-2 |
SM-21 |
SageMaker AutoML Job Network Isolation Check
|
Informational | N/A |
123456789012 |
us-west-2 |
SM-22 |
Model Approval Workflow Check
|
Informational | N/A |
123456789012 |
us-west-2 |
SM-23 |
Model Drift Detection Check
|
Medium | Passed |
123456789012 |
us-west-2 |
SM-24 |
A/B Testing and Shadow Deployment Check
|
Low | Passed |
123456789012 |
us-west-2 |
SM-25 |
ML Lineage Tracking - Experiments Not Used
|
Informational | N/A |
123456789012 |
us-west-2 |
SM-27 |
HyperPod EBS CMK Encryption
|
Informational | N/A |
123456789012 |
us-west-2 |
SM-28 |
HyperPod VPC Configuration
|
Informational | N/A |
123456789012 |
us-west-2 |
SM-30 |
Model Package Group Resource Policy Exposure
|
Informational | N/A |
123456789012 |
Global |
AC-02 |
AgentCore IAM Full Access Check
|
High | Passed |
123456789012 |
Global |
AC-03 |
AgentCore Unused Permissions
Details and remediationDetails
The following principals have AgentCore permissions but have never accessed the service: role 'AIMLSecurityMemberRole', role 'AwsSecurityAudit', role 'AWSServiceRoleForSupport', role 'cdk-hnb659fds-lookup-role-123456789012-us-east-1', role 'cdk-hnb659fds-lookup-role-123456789012-us-east-2', role 'CloudSecAuditRole', role 'CloudSeerTrustedServiceRole', role 'EpoxyAccessRole', role 'IibsAdminAccess-DO-NOT-DELETE', role 'InternalAuditInternal', role 'Nova-DO-NOT-DELETE', role 'ScoutSuiteRole' Resolution
Review and remove unused AgentCore permissions following least privilege principle |
Informational | N/A |
123456789012 |
Global |
AC-09 |
AgentCore Service-Linked Role Missing
Details and remediationDetails
Service-linked role 'AWSServiceRoleForBedrockAgentCoreNetwork' does not exist. VPC configuration for AgentCore Runtimes will fail without this role. Resolution
Allow iam:CreateServiceLinkedRole for arn:PARTITION:iam::*:role/aws-service-role/network.bedrock-agentcore.amazonaws.com/AWSServiceRoleForBedrockAgentCoreNetwork, replacing PARTITION with the deployment partition, and add StringEquals for iam:AWSServiceName = network.bedrock-agentcore.amazonaws.com. Then configure VPC networking on an AgentCore Runtime so AWS creates the service-linked role. |
Medium | Failed |
123456789012 |
us-east-1 |
AC-01 |
AgentCore VPC Configuration Check
|
Informational | N/A |
123456789012 |
us-east-1 |
AC-04 |
AgentCore Observability Check
|
Informational | N/A |
123456789012 |
us-east-1 |
AC-05 |
AgentCore Encryption Check
|
Informational | N/A |
123456789012 |
us-east-1 |
AC-06 |
AgentCore Browser Session Recording
|
Informational | N/A |
123456789012 |
us-east-1 |
AC-07 |
AgentCore Memory Configuration Check
|
Informational | N/A |
123456789012 |
us-east-1 |
AC-13 |
AgentCore Gateway Configuration Check
|
Informational | N/A |
123456789012 |
us-east-1 |
AC-08 |
AgentCore VPC Endpoints Check
|
Informational | N/A |
123456789012 |
us-east-1 |
AC-10 |
AgentCore Resource-Based Policies Check
|
Informational | N/A |
123456789012 |
us-east-1 |
AC-11 |
AgentCore Policy Engine Encryption Check
|
Informational | N/A |
123456789012 |
us-east-1 |
AC-12 |
AgentCore Gateway Encryption Check
|
Informational | N/A |
123456789012 |
us-east-1 |
AC-14 |
AgentCore Identity Token Vault CMK Encryption
|
High | Failed |
123456789012 |
us-east-1 |
AC-15 |
AgentCore Code Interpreter Network Isolation
|
Informational | N/A |
123456789012 |
us-east-1 |
AC-16 |
AgentCore Custom Browser Network Isolation
|
Informational | N/A |
123456789012 |
us-east-1 |
AC-17 |
AgentCore Online Evaluation Coverage
|
Medium | Failed |
123456789012 |
us-east-1 |
AG-24 |
Agentic AI Gateway Inbound Authorization
|
Informational | N/A |
123456789012 |
us-east-1 |
AG-25 |
Agentic AI Gateway Tool Policy Enforcement
|
Informational | N/A |
123456789012 |
us-east-1 |
AG-26 |
Agentic AI Gateway Error Detail Exposure
|
Informational | N/A |
123456789012 |
us-east-1 |
AG-27 |
Agentic AI Gateway WAF Protection
|
Informational | N/A |
123456789012 |
Global |
AG-16 |
Agentic AI AgentCore Least Privilege
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Over-permissive AgentCore principals can let agents or operators bypass intended autonomy and tool boundaries. Source check AC-02: No roles with overly permissive AgentCore access found Resolution
Replace full-access AgentCore permissions with least-privilege IAM policies scoped to required resources and actions. |
High | Passed |
123456789012 |
Global |
AG-17 |
Agentic AI Stale AgentCore Access
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Unused AgentCore permissions increase the blast radius of compromised principals. Source check AC-03: The following principals have AgentCore permissions but have never accessed the service: role 'AIMLSecurityMemberRole', role 'AwsSecurityAudit', role 'AWSServiceRoleForSupport', role 'cdk-hnb659fds-lookup-role-123456789012-us-east-1', role 'cdk-hnb659fds-lookup-role-123456789012-us-east-2', role 'CloudSecAuditRole', role 'CloudSeerTrustedServiceRole', role 'EpoxyAccessRole', role 'IibsAdminAccess-DO-NOT-DELETE', role 'InternalAuditInternal', role 'Nova-DO-NOT-DELETE', role 'ScoutSuiteRole' Resolution
Remove or restrict stale AgentCore permissions for principals that no longer need access. |
Informational | N/A |
123456789012 |
us-east-1 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
Informational | N/A |
123456789012 |
us-east-1 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Informational | N/A |
123456789012 |
us-east-1 |
AG-19 |
Agentic AI Memory Data Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found Resolution
Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions. |
Informational | N/A |
123456789012 |
us-east-1 |
AG-20 |
Agentic AI Private AgentCore Connectivity
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found Resolution
Create required VPC endpoints for AgentCore services and validate endpoint availability. |
Informational | N/A |
123456789012 |
us-east-1 |
AG-21 |
Agentic AI Resource Policy Boundary
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies Resolution
Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources. |
Informational | N/A |
123456789012 |
us-east-1 |
AG-22 |
Agentic AI Policy Engine Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found Resolution
Configure policy engines with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
123456789012 |
us-east-1 |
AG-23 |
Agentic AI Gateway Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found Resolution
Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
123456789012 |
us-east-1 |
AG-28 |
Agentic AI Identity Token Vault Protection
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Agent credentials stored in the Identity token vault should use customer-controlled encryption where enhanced key control is required. Source check AC-14: AgentCore token vault 'default' uses a service-managed or AWS-owned key. Resolution
Configure the AgentCore Identity token vault with a customer-managed KMS key. |
High | Failed |
123456789012 |
us-east-1 |
AG-29 |
Agentic AI Code Interpreter Isolation
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent-executed code should run inside an explicit VPC boundary with controlled network paths. Source check AC-15: No custom AgentCore Code Interpreters found Resolution
Configure custom AgentCore Code Interpreters in VPC mode with approved subnets and security groups. |
Informational | N/A |
123456789012 |
us-east-1 |
AG-31 |
Agentic AI Browser Tool Isolation
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Browser tools can reach external systems and should use explicit private network boundaries. Source check AC-16: No custom AgentCore browsers found Resolution
Configure custom AgentCore browsers in VPC mode with approved subnets and security groups. |
Informational | N/A |
123456789012 |
us-east-1 |
AG-32 |
Agentic AI Online Evaluation Assurance
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Online evaluation provides continuous evidence about agent behavior, quality, and policy-relevant outcomes. Source check AC-17: No AgentCore online evaluation configurations found. Resolution
Configure an active AgentCore online evaluation with sampling, evaluators, CloudWatch input logs, and an output log group. |
Medium | Failed |
123456789012 |
us-east-2 |
AC-01 |
AgentCore VPC Configuration Check
|
Informational | N/A |
123456789012 |
us-east-2 |
AC-04 |
AgentCore Observability Check
|
Informational | N/A |
123456789012 |
us-east-2 |
AC-05 |
AgentCore Encryption Check
|
Informational | N/A |
123456789012 |
us-east-2 |
AC-06 |
AgentCore Browser Session Recording
|
Informational | N/A |
123456789012 |
us-east-2 |
AC-07 |
AgentCore Memory Configuration Check
|
Informational | N/A |
123456789012 |
us-east-2 |
AC-13 |
AgentCore Gateway Configuration Check
|
Informational | N/A |
123456789012 |
us-east-2 |
AC-08 |
AgentCore VPC Endpoints Check
|
Informational | N/A |
123456789012 |
us-east-2 |
AC-10 |
AgentCore Resource-Based Policies Check
|
Informational | N/A |
123456789012 |
us-east-2 |
AC-11 |
AgentCore Policy Engine Encryption Check
|
Informational | N/A |
123456789012 |
us-east-2 |
AC-12 |
AgentCore Gateway Encryption Check
|
Informational | N/A |
123456789012 |
us-east-2 |
AC-14 |
AgentCore Identity Token Vault CMK Encryption
|
High | Failed |
123456789012 |
us-east-2 |
AC-15 |
AgentCore Code Interpreter Network Isolation
|
Informational | N/A |
123456789012 |
us-east-2 |
AC-16 |
AgentCore Custom Browser Network Isolation
|
Informational | N/A |
123456789012 |
us-east-2 |
AC-17 |
AgentCore Online Evaluation Coverage
|
Medium | Failed |
123456789012 |
us-east-2 |
AG-24 |
Agentic AI Gateway Inbound Authorization
|
Informational | N/A |
123456789012 |
us-east-2 |
AG-25 |
Agentic AI Gateway Tool Policy Enforcement
|
Informational | N/A |
123456789012 |
us-east-2 |
AG-26 |
Agentic AI Gateway Error Detail Exposure
|
Informational | N/A |
123456789012 |
us-east-2 |
AG-27 |
Agentic AI Gateway WAF Protection
|
Informational | N/A |
123456789012 |
us-east-2 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
Informational | N/A |
123456789012 |
us-east-2 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Informational | N/A |
123456789012 |
us-east-2 |
AG-19 |
Agentic AI Memory Data Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found Resolution
Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions. |
Informational | N/A |
123456789012 |
us-east-2 |
AG-20 |
Agentic AI Private AgentCore Connectivity
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found Resolution
Create required VPC endpoints for AgentCore services and validate endpoint availability. |
Informational | N/A |
123456789012 |
us-east-2 |
AG-21 |
Agentic AI Resource Policy Boundary
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies Resolution
Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources. |
Informational | N/A |
123456789012 |
us-east-2 |
AG-22 |
Agentic AI Policy Engine Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found Resolution
Configure policy engines with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
123456789012 |
us-east-2 |
AG-23 |
Agentic AI Gateway Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found Resolution
Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
123456789012 |
us-east-2 |
AG-28 |
Agentic AI Identity Token Vault Protection
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Agent credentials stored in the Identity token vault should use customer-controlled encryption where enhanced key control is required. Source check AC-14: AgentCore token vault 'default' uses a service-managed or AWS-owned key. Resolution
Configure the AgentCore Identity token vault with a customer-managed KMS key. |
High | Failed |
123456789012 |
us-east-2 |
AG-29 |
Agentic AI Code Interpreter Isolation
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent-executed code should run inside an explicit VPC boundary with controlled network paths. Source check AC-15: No custom AgentCore Code Interpreters found Resolution
Configure custom AgentCore Code Interpreters in VPC mode with approved subnets and security groups. |
Informational | N/A |
123456789012 |
us-east-2 |
AG-31 |
Agentic AI Browser Tool Isolation
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Browser tools can reach external systems and should use explicit private network boundaries. Source check AC-16: No custom AgentCore browsers found Resolution
Configure custom AgentCore browsers in VPC mode with approved subnets and security groups. |
Informational | N/A |
123456789012 |
us-east-2 |
AG-32 |
Agentic AI Online Evaluation Assurance
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Online evaluation provides continuous evidence about agent behavior, quality, and policy-relevant outcomes. Source check AC-17: No AgentCore online evaluation configurations found. Resolution
Configure an active AgentCore online evaluation with sampling, evaluators, CloudWatch input logs, and an output log group. |
Medium | Failed |
123456789012 |
us-west-2 |
AC-01 |
AgentCore VPC Configuration Check
|
Informational | N/A |
123456789012 |
us-west-2 |
AC-04 |
AgentCore Observability Check
|
Informational | N/A |
123456789012 |
us-west-2 |
AC-05 |
AgentCore Encryption Check
|
Informational | N/A |
123456789012 |
us-west-2 |
AC-06 |
AgentCore Browser Session Recording
|
Informational | N/A |
123456789012 |
us-west-2 |
AC-07 |
AgentCore Memory Configuration Check
|
Informational | N/A |
123456789012 |
us-west-2 |
AC-13 |
AgentCore Gateway Configuration Check
|
Informational | N/A |
123456789012 |
us-west-2 |
AC-08 |
AgentCore VPC Endpoints Check
|
Informational | N/A |
123456789012 |
us-west-2 |
AC-10 |
AgentCore Resource-Based Policies Check
|
Informational | N/A |
123456789012 |
us-west-2 |
AC-11 |
AgentCore Policy Engine Encryption Check
|
Informational | N/A |
123456789012 |
us-west-2 |
AC-12 |
AgentCore Gateway Encryption Check
|
Informational | N/A |
123456789012 |
us-west-2 |
AC-14 |
AgentCore Identity Token Vault CMK Encryption
|
High | Failed |
123456789012 |
us-west-2 |
AC-15 |
AgentCore Code Interpreter Network Isolation
|
Informational | N/A |
123456789012 |
us-west-2 |
AC-16 |
AgentCore Custom Browser Network Isolation
|
Informational | N/A |
123456789012 |
us-west-2 |
AC-17 |
AgentCore Online Evaluation Coverage
|
Medium | Failed |
123456789012 |
us-west-2 |
AG-24 |
Agentic AI Gateway Inbound Authorization
|
Informational | N/A |
123456789012 |
us-west-2 |
AG-25 |
Agentic AI Gateway Tool Policy Enforcement
|
Informational | N/A |
123456789012 |
us-west-2 |
AG-26 |
Agentic AI Gateway Error Detail Exposure
|
Informational | N/A |
123456789012 |
us-west-2 |
AG-27 |
Agentic AI Gateway WAF Protection
|
Informational | N/A |
123456789012 |
us-west-2 |
AG-15 |
Agentic AI Runtime Network Boundary
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent runtimes should execute inside explicit network boundaries to reduce unintended external reachability. Source check AC-01: No AgentCore resources found Resolution
Configure AgentCore runtimes with appropriate VPC settings and restrict network paths to required services. |
Informational | N/A |
123456789012 |
us-west-2 |
AG-18 |
Agentic AI AgentCore Observability
Details and remediationDetails
Agentic AI security domain: Auditability & Observability. AgentCore observability provides the telemetry needed to investigate runtime, tool, memory, and gateway behavior. Source check AC-04: No AgentCore resources found Resolution
Enable CloudWatch Logs, tracing, and AgentCore observability for runtime and gateway resources where supported. |
Informational | N/A |
123456789012 |
us-west-2 |
AG-19 |
Agentic AI Memory Data Protection
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Agent memory can contain sensitive user or business context and should use customer-controlled encryption where required. Source check AC-07: No Memory resources found Resolution
Configure AgentCore memory resources with customer-managed KMS keys and review memory access permissions. |
Informational | N/A |
123456789012 |
us-west-2 |
AG-20 |
Agentic AI Private AgentCore Connectivity
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Private service connectivity reduces exposure for agents that access AgentCore control or runtime services. Source check AC-08: No AgentCore resources found Resolution
Create required VPC endpoints for AgentCore services and validate endpoint availability. |
Informational | N/A |
123456789012 |
us-west-2 |
AG-21 |
Agentic AI Resource Policy Boundary
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Resource-based policies add a second authorization boundary for AgentCore runtimes and gateways. Source check AC-10: No AgentCore resources found to check for resource-based policies Resolution
Attach resource-based policies to AgentCore resources to constrain principals, accounts, and network sources. |
Informational | N/A |
123456789012 |
us-west-2 |
AG-22 |
Agentic AI Policy Engine Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Policy engines contain authorization logic for tool calls and should be protected with appropriate encryption controls. Source check AC-11: No Policy Engines found Resolution
Configure policy engines with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
123456789012 |
us-west-2 |
AG-23 |
Agentic AI Gateway Data Protection
Details and remediationDetails
Agentic AI security domain: Tool Authorization. Gateway configuration can include tool schemas, target definitions, and integration metadata. Source check AC-12: No Gateways found Resolution
Configure AgentCore gateways with customer-managed KMS keys where enhanced key control is required. |
Informational | N/A |
123456789012 |
us-west-2 |
AG-28 |
Agentic AI Identity Token Vault Protection
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Agent credentials stored in the Identity token vault should use customer-controlled encryption where enhanced key control is required. Source check AC-14: AgentCore token vault 'default' uses a service-managed or AWS-owned key. Resolution
Configure the AgentCore Identity token vault with a customer-managed KMS key. |
High | Failed |
123456789012 |
us-west-2 |
AG-29 |
Agentic AI Code Interpreter Isolation
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Agent-executed code should run inside an explicit VPC boundary with controlled network paths. Source check AC-15: No custom AgentCore Code Interpreters found Resolution
Configure custom AgentCore Code Interpreters in VPC mode with approved subnets and security groups. |
Informational | N/A |
123456789012 |
us-west-2 |
AG-31 |
Agentic AI Browser Tool Isolation
Details and remediationDetails
Agentic AI security domain: Bounded Autonomy. Browser tools can reach external systems and should use explicit private network boundaries. Source check AC-16: No custom AgentCore browsers found Resolution
Configure custom AgentCore browsers in VPC mode with approved subnets and security groups. |
Informational | N/A |
123456789012 |
us-west-2 |
AG-32 |
Agentic AI Online Evaluation Assurance
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Online evaluation provides continuous evidence about agent behavior, quality, and policy-relevant outcomes. Source check AC-17: No AgentCore online evaluation configurations found. Resolution
Configure an active AgentCore online evaluation with sampling, evaluators, CloudWatch input logs, and an output log group. |
Medium | Failed |
123456789012 |
Global |
AR-01 |
AWS Agent Registry IAM Full Access Check
|
High | Passed |
123456789012 |
Global |
AR-02 |
AWS Agent Registry Unused Permissions
|
Informational | N/A |
123456789012 |
us-east-1 |
AR-03 |
AWS Agent Registry Publication Approval Governance
|
Informational | N/A |
123456789012 |
us-east-1 |
AR-04 |
AWS Agent Registry Discovery Authorization
|
Informational | N/A |
123456789012 |
us-east-1 |
AR-05 |
AWS Agent Registry Customer-Managed KMS Encryption
|
Informational | N/A |
123456789012 |
us-east-1 |
AR-06 |
AWS Agent Registry Organization Auto-Detection
|
Informational | N/A |
123456789012 |
us-east-1 |
AR-07 |
AWS Agent Registry Record Lifecycle Governance
|
Informational | N/A |
123456789012 |
us-east-1 |
AR-08 |
AWS Agent Registry Record Provenance
|
Informational | N/A |
123456789012 |
us-east-1 |
AG-33 |
Agentic AI Registry Publication Approval Governance
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry approval workflows control which agents, tools, and skills become discoverable to consumers. Source check AR-03: No AWS Agent Registry registries found. Resolution
Require manual review for registry publication where organizational policy does not permit automatic approval. |
Informational | N/A |
123456789012 |
us-east-1 |
AG-34 |
Agentic AI Registry Discovery Authorization
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry discovery authorization requires review against intended callers and effective access boundaries. Source check AR-04: No AWS Agent Registry registries found. Resolution
Review effective IAM access or compare custom JWT audiences, clients, scopes, and claims with approved registry consumers. |
Informational | N/A |
123456789012 |
us-east-1 |
AG-35 |
Agentic AI Registry Metadata Encryption
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Registry records can contain agent, tool, endpoint, and ownership metadata that benefits from customer-controlled encryption. Source check AR-05: No AWS Agent Registry registries found. Resolution
Create the registry with a customer-managed KMS key when organizational policy requires customer-controlled encryption. |
Informational | N/A |
123456789012 |
us-east-1 |
AG-36 |
Agentic AI Organization Discovery Coverage
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Organization-wide auto-detection provides visibility into unmanaged agent resources. Source check AR-06: No AWS Agent Registry registries found. Resolution
Enable organization-scoped registry auto-detection where centralized discovery is required. |
Informational | N/A |
123456789012 |
us-east-1 |
AG-37 |
Agentic AI Registry Record Lifecycle Governance
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry lifecycle states provide operational visibility but do not independently prove a security control. Source check AR-07: No AWS Agent Registry registries found. Resolution
Review failed or unknown record lifecycle states operationally. |
Informational | N/A |
123456789012 |
us-east-1 |
AG-38 |
Agentic AI Registry Record Provenance
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Consumers need attributable record origin and source lineage to understand which account and resource produced an entry. Source check AR-08: No AWS Agent Registry registries found. Resolution
Ensure records retain creator attribution and auto-detected records retain source provenance. |
Informational | N/A |
123456789012 |
us-east-2 |
AR-03 |
AWS Agent Registry Publication Approval Governance Incomplete
|
Informational | N/A |
123456789012 |
us-east-2 |
AR-04 |
AWS Agent Registry Discovery Authorization Incomplete
|
Informational | N/A |
123456789012 |
us-east-2 |
AR-05 |
AWS Agent Registry Customer-Managed KMS Encryption Incomplete
|
Informational | N/A |
123456789012 |
us-east-2 |
AR-06 |
AWS Agent Registry Organization Auto-Detection Incomplete
|
Informational | N/A |
123456789012 |
us-east-2 |
AR-07 |
AWS Agent Registry Record Lifecycle Governance Incomplete
|
Informational | N/A |
123456789012 |
us-east-2 |
AR-08 |
AWS Agent Registry Record Provenance Incomplete
|
Informational | N/A |
123456789012 |
us-east-2 |
AG-33 |
Agentic AI Registry Publication Approval Governance
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry approval workflows control which agents, tools, and skills become discoverable to consumers. Source check AR-03: Assessment could not enumerate AWS Agent Registry registries: AccessDeniedException (Unauthorized access). Resolution
Require manual review for registry publication where organizational policy does not permit automatic approval. |
Informational | N/A |
123456789012 |
us-east-2 |
AG-34 |
Agentic AI Registry Discovery Authorization
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry discovery authorization requires review against intended callers and effective access boundaries. Source check AR-04: Assessment could not enumerate AWS Agent Registry registries: AccessDeniedException (Unauthorized access). Resolution
Review effective IAM access or compare custom JWT audiences, clients, scopes, and claims with approved registry consumers. |
Informational | N/A |
123456789012 |
us-east-2 |
AG-35 |
Agentic AI Registry Metadata Encryption
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Registry records can contain agent, tool, endpoint, and ownership metadata that benefits from customer-controlled encryption. Source check AR-05: Assessment could not enumerate AWS Agent Registry registries: AccessDeniedException (Unauthorized access). Resolution
Create the registry with a customer-managed KMS key when organizational policy requires customer-controlled encryption. |
Informational | N/A |
123456789012 |
us-east-2 |
AG-36 |
Agentic AI Organization Discovery Coverage
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Organization-wide auto-detection provides visibility into unmanaged agent resources. Source check AR-06: Assessment could not enumerate AWS Agent Registry registries: AccessDeniedException (Unauthorized access). Resolution
Enable organization-scoped registry auto-detection where centralized discovery is required. |
Informational | N/A |
123456789012 |
us-east-2 |
AG-37 |
Agentic AI Registry Record Lifecycle Governance
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry lifecycle states provide operational visibility but do not independently prove a security control. Source check AR-07: Assessment could not enumerate AWS Agent Registry registries: AccessDeniedException (Unauthorized access). Resolution
Review failed or unknown record lifecycle states operationally. |
Informational | N/A |
123456789012 |
us-east-2 |
AG-38 |
Agentic AI Registry Record Provenance
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Consumers need attributable record origin and source lineage to understand which account and resource produced an entry. Source check AR-08: Assessment could not enumerate AWS Agent Registry registries: AccessDeniedException (Unauthorized access). Resolution
Ensure records retain creator attribution and auto-detected records retain source provenance. |
Informational | N/A |
123456789012 |
us-west-2 |
AR-03 |
AWS Agent Registry Publication Approval Governance
|
Informational | N/A |
123456789012 |
us-west-2 |
AR-04 |
AWS Agent Registry Discovery Authorization
|
Informational | N/A |
123456789012 |
us-west-2 |
AR-05 |
AWS Agent Registry Customer-Managed KMS Encryption
|
Informational | N/A |
123456789012 |
us-west-2 |
AR-06 |
AWS Agent Registry Organization Auto-Detection
|
Informational | N/A |
123456789012 |
us-west-2 |
AR-07 |
AWS Agent Registry Record Lifecycle Governance
|
Informational | N/A |
123456789012 |
us-west-2 |
AR-08 |
AWS Agent Registry Record Provenance
|
Informational | N/A |
123456789012 |
us-west-2 |
AG-33 |
Agentic AI Registry Publication Approval Governance
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry approval workflows control which agents, tools, and skills become discoverable to consumers. Source check AR-03: No AWS Agent Registry registries found. Resolution
Require manual review for registry publication where organizational policy does not permit automatic approval. |
Informational | N/A |
123456789012 |
us-west-2 |
AG-34 |
Agentic AI Registry Discovery Authorization
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry discovery authorization requires review against intended callers and effective access boundaries. Source check AR-04: No AWS Agent Registry registries found. Resolution
Review effective IAM access or compare custom JWT audiences, clients, scopes, and claims with approved registry consumers. |
Informational | N/A |
123456789012 |
us-west-2 |
AG-35 |
Agentic AI Registry Metadata Encryption
Details and remediationDetails
Agentic AI security domain: Memory & Data Privacy. Registry records can contain agent, tool, endpoint, and ownership metadata that benefits from customer-controlled encryption. Source check AR-05: No AWS Agent Registry registries found. Resolution
Create the registry with a customer-managed KMS key when organizational policy requires customer-controlled encryption. |
Informational | N/A |
123456789012 |
us-west-2 |
AG-36 |
Agentic AI Organization Discovery Coverage
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Organization-wide auto-detection provides visibility into unmanaged agent resources. Source check AR-06: No AWS Agent Registry registries found. Resolution
Enable organization-scoped registry auto-detection where centralized discovery is required. |
Informational | N/A |
123456789012 |
us-west-2 |
AG-37 |
Agentic AI Registry Record Lifecycle Governance
Details and remediationDetails
Agentic AI security domain: Agent Identity & Access. Registry lifecycle states provide operational visibility but do not independently prove a security control. Source check AR-07: No AWS Agent Registry registries found. Resolution
Review failed or unknown record lifecycle states operationally. |
Informational | N/A |
123456789012 |
us-west-2 |
AG-38 |
Agentic AI Registry Record Provenance
Details and remediationDetails
Agentic AI security domain: Auditability & Continuous Assurance. Consumers need attributable record origin and source lineage to understand which account and resource produced an entry. Source check AR-08: No AWS Agent Registry registries found. Resolution
Ensure records retain creator attribution and auto-detected records retain source provenance. |
Informational | N/A |
123456789012 |
Global |
FS-01 |
AWS Shield Advanced Not Enabled
Details and remediationDetails
AWS Shield Advanced is not subscribed. GenAI API endpoints are vulnerable to volumetric DDoS attacks that can exhaust token quotas and inflate costs. Resolution
1. Subscribe to AWS Shield Advanced for DDoS protection. 2. After subscribing, explicitly add resource protections in the Shield Advanced console for each Bedrock-facing resource (API Gateway stages, ALBs, CloudFront distributions, Route 53 hosted zones). Shield Advanced subscription alone does NOT automatically protect resources — each resource must be individually added to receive protection. 3. Enable Shield Response Team (SRT) access and configure proactive engagement. 4. Alternatively, use AWS Firewall Manager with a Shield Advanced policy to automate resource protection based on tags or resource types. |
Low | Failed |
123456789012 |
Global |
FS-01 |
No Regional WAF Web ACLs Found
Details and remediationDetails
No AWS WAF regional Web ACLs found. Without WAF, GenAI endpoints lack rate-based rules to block abusive callers. Resolution
1. Create a WAF Web ACL with rate-based rules (e.g., 1000 req/5 min per IP). 2. Associate the ACL with API Gateway stages or ALBs fronting Bedrock. 3. Add AWS Managed Rules for known bad inputs. |
Medium | Failed |
123456789012 |
Global |
FS-02 |
No API Gateway Usage Plans Found
|
Informational | N/A |
123456789012 |
Global |
FS-03 |
Bedrock Token Quotas Customized
|
Medium | Passed |
123456789012 |
Global |
FS-04 |
No Cost Anomaly Detection Monitors
Details and remediationDetails
No AWS Cost Anomaly Detection monitors found. Unexpected spikes in Bedrock/SageMaker usage (e.g., from prompt injection loops) will go undetected. Resolution
1. Create a Cost Anomaly Detection monitor scoped to AWS/Bedrock and AWS/SageMaker. 2. Configure alert subscriptions (SNS/email) for anomalies above threshold. 3. Set daily spend budgets with AWS Budgets as a secondary control. |
Medium | Failed |
123456789012 |
Global |
FS-05 |
No Bedrock CloudWatch Alarms Found
Details and remediationDetails
No CloudWatch alarms found for Bedrock metrics. Token exhaustion and throttling events will not trigger operational alerts. Resolution
Create CloudWatch alarms for: - AWS/Bedrock InvocationThrottles (threshold > 0) - AWS/Bedrock TokensProcessed (threshold based on quota) - Custom application-level token counters via EMF |
Medium | Failed |
123456789012 |
Global |
FS-06 |
No AI/ML Service Budgets Configured
Details and remediationDetails
No AWS Budgets found scoped to Bedrock or SageMaker. Unbounded GenAI spend can go undetected until the monthly bill. Resolution
1. Create cost budgets for AWS Bedrock and SageMaker with 80%/100% alert thresholds. 2. Add SNS notifications to on-call channels. 3. Consider budget actions to apply IAM deny policies when thresholds are breached. |
Medium | Failed |
123456789012 |
Global |
FS-07 |
Agent Action Boundary Check
|
Informational | N/A |
123456789012 |
Global |
FS-08 |
No AgentCore Runtimes Found
|
Informational | N/A |
123456789012 |
Global |
FS-09 |
Agent Lambda Functions Without Concurrency Limits
Details and remediationDetails
Agent-related Lambda functions without reserved concurrency: aiml-security-aiml-sec-123456789012-AgentCoreAssessment, aiml-security-aiml-sec-123456789012-CleanupBucket, aiml-security-aiml-sec-123456789012-ResolveRegions, aiml-security-aiml-sec-123456789012-SagemakerAssessment, aiml-security-aiml-sec-123456789012-GenerateReport, aiml-security-aiml-sec-123456789012-AgentRegistryAssessment, aiml-security-aiml-sec-123456789012-RAIGRCAssessment, aiml-security-aiml-sec-123456789012-BedrockAssessment, AIML-Standalone-CodeBuildStartBuildLambda-eAzlGvTTrtQW, aiml-security-aiml-sec-123456789012-IAMPermissionCaching. Unlimited concurrency allows runaway agent loops to exhaust account limits. Resolution
1. Set reserved concurrency on agent Lambda functions. 2. Implement maximum iteration counts in agent orchestration logic. 3. Use Step Functions with MaxConcurrency and timeout states. 4. Add circuit-breaker patterns to agent tool invocations. |
Medium | Failed |
123456789012 |
Global |
FS-10 |
Human-in-the-Loop Check — No Agent Workflows Found
Details and remediationDetails
No Step Functions state machines with agent/approval naming found. Verify that high-risk agent actions (e.g., fund transfers, account changes) have human approval gates. Resolution
Implement Step Functions .waitForTaskToken patterns for high-risk agent actions. Route approval requests to human reviewers via SNS/SES/Slack. |
Informational | N/A |
123456789012 |
Global |
FS-11 |
No Agent Rate Alarms Found
Details and remediationDetails
No CloudWatch alarms found for agent invocation rates. Looping or runaway agents will not trigger operational alerts. Resolution
Create CloudWatch alarms on: - Bedrock agent invocation counts (threshold based on expected max) - Lambda invocation errors for agent functions - Step Functions execution failures and timeouts |
Medium | Failed |
123456789012 |
Global |
FS-12 |
No Bedrock-Scoped SCPs Found
Details and remediationDetails
No Service Control Policies reference Bedrock. Without SCPs, any account in the organization can access any Bedrock model, including unapproved third-party models. Resolution
1. Create an SCP that denies bedrock:InvokeModel, bedrock:InvokeModelWithResponseStream, and bedrock:CreateModelInvocationJob outside approved model access. 2. Use Resource or NotResource with approved foundation-model, custom-model, provisioned-model, and inference-profile ARNs to express the allowlist. 3. Maintain a model inventory and update the SCP when models are approved/retired. |
High | Failed |
123456789012 |
Global |
FS-13 |
Model Provenance Tags Present
|
Medium | Passed |
123456789012 |
Global |
FS-14 |
Model Governance Config Rules Present
|
Medium | Passed |
123456789012 |
Global |
FS-15 |
No Bedrock Evaluation Jobs Found
Details and remediationDetails
No Bedrock Model Evaluation jobs found. Models have not been evaluated for adversarial robustness. Model-risk management (SR 11-7) expects documented model validation/evaluation. Resolution
1. Run Bedrock Model Evaluation with adversarial/red-team datasets. 2. Use FMEval library for automated robustness testing. 3. Schedule periodic re-evaluation after model updates. |
Medium | Failed |
123456789012 |
Global |
FS-16 |
ECR Image Scanning Covered by Inspector Enhanced Scanning
Details and remediationDetails
Amazon Inspector enhanced scanning for ECR is ENABLED account-wide, so all 2 repository(ies) are continuously scanned. 1 repository(ies) do not set scan-on-push (cdk-hnb659fds-container-assets-123456789012-us-east-1), which is expected when enhanced scanning supersedes basic scanning. Resolution
No action required while Inspector enhanced scanning stays enabled. If it is disabled, enable scan-on-push per repository. |
High | Passed |
123456789012 |
Global |
FS-20 |
No SageMaker Feature Groups Found
|
Informational | N/A |
123456789012 |
Global |
FS-21 |
No Training Data Buckets Identified
|
Informational | N/A |
123456789012 |
Global |
FS-22 |
Overly Permissive Knowledge Base IAM Roles
Details and remediationDetails
787 role(s) with wildcard KB permissions: - Role 'Admin' allows '*' - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-tb9zKkm0IYdg' allows 'bedrock:ListGuardrails' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-tb9zKkm0IYdg' allows 'bedrock:GetGuardrail' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-tb9zKkm0IYdg' allows 'bedrock:GetModelInvocationLoggingConfiguration' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-tb9zKkm0IYdg' allows 'bedrock:ListPrompts' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-tb9zKkm0IYdg' allows 'bedrock:GetPrompt' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-tb9zKkm0IYdg' allows 'bedrock:ListAgents' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-tb9zKkm0IYdg' allows 'bedrock:GetAgent' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-tb9zKkm0IYdg' allows 'bedrock:ListCustomModels' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-tb9zKkm0IYdg' allows 'bedrock:GetCustomModel' on Resource '*' (no ARN scoping to specific Knowledge Bases) Resolution
Replace wildcard bedrock:* with specific actions such as bedrock:Retrieve, bedrock:RetrieveAndGenerate. Scope resources to specific Knowledge Base ARNs. |
High | Failed |
123456789012 |
Global |
FS-24 |
No Knowledge Bases Found
|
Informational | N/A |
123456789012 |
Global |
FS-25 |
No OpenSearch Serverless Collections Found
Details and remediationDetails
No OpenSearch Serverless collections exist in this region, so there is no OpenSearch vector-store data at rest to encrypt. If Bedrock Knowledge Bases use a different vector store (S3 Vectors, Aurora, Pinecone), verify its encryption separately. Resolution
If you adopt OpenSearch Serverless as a Bedrock KB vector store, create an encryption policy specifying a customer-managed KMS key before creating the collection. |
Informational | N/A |
123456789012 |
Global |
FS-26 |
No OpenSearch Serverless Network Policies
|
High | Failed |
123456789012 |
Global |
FS-27 |
No Guardrails — Contextual Grounding Not Applicable
|
Informational | N/A |
123456789012 |
Global |
FS-27 |
No Automated Reasoning Policies Found
Details and remediationDetails
No Bedrock Automated Reasoning policies have been created. ARC (GA August 2025) uses formal verification to guarantee that GenAI outputs comply with authored business rules — e.g., loan criteria, regulatory thresholds, policy constraints. Without ARC policies, factual accuracy of outputs is not formally verified, only heuristically filtered by contextual grounding thresholds. Resolution
1. In the Amazon Bedrock console → Guardrails → Automated Reasoning, create a policy document encoding your business rules (e.g., eligibility criteria, rate limits, regulatory thresholds). 2. Associate the ARC policy with your guardrail (automatedReasoningPolicy.policies field in CreateGuardrail/UpdateGuardrail). 3. Set confidenceThreshold on the policy to control strictness. 4. ARC requires cross-Region inference — ensure your guardrail has a guardrailProfileArn configured (crossRegionDetails in GetGuardrail response). 5. Reference: AWS Announcement — Automated Reasoning checks GA (August 2025). |
Medium | Failed |
123456789012 |
Global |
FS-28 |
No Guardrails — Topic Policy Not Applicable
|
Informational | N/A |
123456789012 |
Global |
FS-29 |
ADVISORY: Compliance Disclaimer — Manual Review Required
Details and remediationDetails
Application-level compliance disclaimers cannot be verified via AWS APIs. Manual review required to confirm GenAI outputs include required regulatory disclosures. Resolution
1. Implement post-processing to append required disclaimers to GenAI outputs. 2. Use Bedrock Guardrails word filters to block outputs that omit required disclosures. 3. Document disclaimer requirements in the AI use case register. 4. Test disclaimer presence in QA/UAT before production deployment. |
Informational | N/A |
123456789012 |
Global |
FS-30 |
ADVISORY: Compliance Dataset Coverage — Manual Review Required
Details and remediationDetails
Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation jobs include compliance-specific datasets (fair lending/ECOA, Fair Housing Act, UDAP/UDAAP, AML/KYC edge cases). Whether any evaluation jobs exist at all is assessed by FS-15. Resolution
Run Bedrock Model Evaluation with compliance-specific datasets: - Fair lending test cases (ECOA, Fair Housing Act) - UDAP/UDAAP unfair/deceptive practice scenarios - AML/KYC edge cases |
Informational | N/A |
123456789012 |
Global |
FS-31 |
No Knowledge Bases Found
|
Informational | N/A |
123456789012 |
Global |
FS-32 |
ADVISORY: Source Attribution — Manual Review Required
Details and remediationDetails
Source attribution in GenAI responses cannot be verified via AWS APIs. Manual review required to confirm responses include citations. Resolution
1. Use Bedrock RetrieveAndGenerate with citations enabled. 2. Include source document references in response post-processing. 3. Test citation accuracy in QA before production deployment. 4. Consider Bedrock Guardrails grounding checks to validate response accuracy. |
Informational | N/A |
123456789012 |
Global |
FS-33 |
No Knowledge Bases Found
|
Informational | N/A |
123456789012 |
Global |
FS-34 |
Legacy Foundation Models Available in Region
Details and remediationDetails
Legacy/deprecated foundation models are available in this account/region: anthropic.claude-sonnet-4-20250514-v1:0, twelvelabs.marengo-embed-2-7-v1:0, anthropic.claude-opus-4-1-20250805-v1:0, amazon.nova-premier-v1:0:8k, amazon.nova-premier-v1:0:20k, amazon.nova-premier-v1:0:1000k, amazon.nova-premier-v1:0:mm, amazon.nova-premier-v1:0, amazon.nova-canvas-v1:0, amazon.nova-reel-v1:0. This API reports model *availability*, not actual usage — it cannot determine which models your applications invoke. Legacy models have older training-data cutoffs and may produce outdated information if used. Review whether any are in active use. Resolution
1. Identify which (if any) of these legacy models your applications invoke (e.g., via CloudTrail InvokeModel events or application config). 2. Migrate active usage to current model versions. 3. Document training-data cutoff dates for all models in use. 4. Add data-currency disclaimers to outputs from models with old cutoffs. |
Informational | N/A |
123456789012 |
Global |
FS-35 |
ADVISORY: Harmful-Content Test Coverage — Manual Review Required
Details and remediationDetails
Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation/FMEval jobs include harmful-content datasets (toxicity, hate speech, violence/self-harm). Whether any evaluation jobs exist at all is assessed by FS-15. Resolution
Run Bedrock Model Evaluation or FMEval with harmful content datasets: - Toxicity detection - Hate speech classification - Violence/self-harm content |
Informational | N/A |
123456789012 |
Global |
FS-36 |
No Guardrails — Content Filters Not Applicable
|
Informational | N/A |
123456789012 |
Global |
FS-37 |
ADVISORY: User Feedback Mechanism — Manual Review Required
Details and remediationDetails
User feedback mechanisms for harmful outputs cannot be verified via AWS APIs. Manual review required. Resolution
1. Implement thumbs-up/down or flag-for-review UI in GenAI applications. 2. Route flagged outputs to human reviewers via SQS/SNS. 3. Log feedback to DynamoDB/S3 for model improvement. 4. Define SLAs for reviewing flagged content. |
Informational | N/A |
123456789012 |
Global |
FS-38 |
No Guardrails — Word Filters Not Applicable
|
Informational | N/A |
123456789012 |
Global |
FS-39 |
No SageMaker Clarify Bias Monitoring
Details and remediationDetails
No SageMaker Clarify model bias monitoring schedules found. Models making financial decisions (credit, insurance) may exhibit discriminatory bias without detection. Resolution
1. Configure SageMaker Clarify bias detection for all models making credit, insurance, or employment decisions. 2. Define protected attributes (age, gender, race proxies). 3. Set bias metric thresholds and alert on violations. 4. Document bias testing results for regulatory examination. |
High | Failed |
123456789012 |
Global |
FS-40 |
ADVISORY: Bias Dataset Coverage — Manual Review Required
Details and remediationDetails
Bedrock model-evaluation dataset content cannot be inspected via API. Manually verify your model-evaluation jobs include bias/fairness datasets (demographic parity, equal-opportunity, counterfactual fairness) for any GenAI models used in financial decisions (ECOA/Fair Housing). Whether any evaluation jobs exist at all is assessed by FS-15. Resolution
Run Bedrock Model Evaluation with bias test datasets: - Demographic parity test cases - Equal opportunity scenarios - Counterfactual fairness tests |
Informational | N/A |
123456789012 |
Global |
FS-41 |
No SageMaker Clarify Explainability Monitoring
Details and remediationDetails
No SageMaker Clarify explainability monitoring found. Models making adverse financial decisions may not provide required explanations (ECOA adverse action notices). Resolution
1. Configure SageMaker Clarify explainability for credit/lending models. 2. Generate SHAP values for feature importance. 3. Map top features to human-readable adverse action reason codes. 4. Store explanations for regulatory examination. |
High | Failed |
123456789012 |
Global |
FS-42 |
No SageMaker Model Cards Found
Details and remediationDetails
No SageMaker Model Cards found. If GenAI workloads run on Bedrock rather than SageMaker, model documentation may legitimately live elsewhere; Model Cards are a SageMaker-specific artifact. Resolution
1. For SageMaker models, create a Model Card documenting intended use, out-of-scope uses, training data and bias evaluations. 2. For Bedrock-only estates, record the equivalent documentation in your model-governance system and reference the AWS AI Service Cards. |
Informational | N/A |
123456789012 |
Global |
FS-43 |
Bedrock Invocation Logging Not Enabled
Details and remediationDetails
Bedrock model invocation logging is not enabled, so no invocation logs are being delivered and there is no log content to mask. Prompt and completion content is therefore also unavailable for audit. Resolution
1. Enable Bedrock model invocation logging. 2. If delivering to CloudWatch Logs, attach a data protection policy masking PII to the destination log group. |
Informational | N/A |
123456789012 |
Global |
FS-44 |
Amazon Macie Enabled but Automated Discovery Disabled
Details and remediationDetails
Amazon Macie is enabled, but automated sensitive data discovery is DISABLED. Enabling Macie alone does not scan any data, so S3 buckets containing training data and KB data sources are not being evaluated for PII. Resolution
1. Enable automated sensitive data discovery in Macie. 2. Confirm the classification scope includes training data and KB source buckets. 3. Alternatively, create targeted classification jobs for those buckets. |
High | Failed |
123456789012 |
Global |
FS-45 |
No Guardrails — PII Filters Not Applicable
|
Informational | N/A |
123456789012 |
Global |
FS-46 |
No AI/ML Data Buckets Identified
|
Informational | N/A |
123456789012 |
Global |
FS-47 |
No Guardrails — Grounding Threshold Not Applicable
|
Informational | N/A |
123456789012 |
Global |
FS-48 |
No Active Knowledge Bases for RAG
Details and remediationDetails
No active Bedrock Knowledge Bases found. GenAI responses are not grounded in authoritative data sources, increasing hallucination risk. Resolution
1. Create Bedrock Knowledge Bases with authoritative financial data. 2. Use RetrieveAndGenerate API to ground responses. 3. Configure data sources with current regulatory and product information. |
Medium | Failed |
123456789012 |
Global |
FS-49 |
ADVISORY: Hallucination Disclaimer — Manual Review Required
Details and remediationDetails
Application-level hallucination disclaimers cannot be verified via AWS APIs. Manual review required. Resolution
1. Add disclaimers to GenAI outputs: 'AI-generated content may contain errors. Verify with authoritative sources before acting.' 2. Implement post-processing to append disclaimers. 3. Test disclaimer presence in QA before production. |
Informational | N/A |
123456789012 |
Global |
FS-50 |
No Guardrails With Relevance Grounding Filters
Details and remediationDetails
No guardrails have RELEVANCE contextual grounding filters. Without relevance filters, responses that are off-topic or unrelated to the user query will not be blocked, increasing hallucination risk in RAG-based applications. Resolution
Enable the RELEVANCE contextual grounding filter in Bedrock Guardrails with a threshold of ≥0.7 to block responses that are not relevant to the user query. Also enable the GROUNDING filter (≥0.7) to block responses not supported by the retrieved source context. |
Medium | Failed |
123456789012 |
Global |
FS-51 |
No Guardrails — Prompt Attack Filters Not Applicable
|
Informational | N/A |
123456789012 |
Global |
FS-52 |
Bedrock Lambda Functions on Current Runtimes
|
Medium | Passed |
123456789012 |
Global |
FS-53 |
No WAF Web ACLs — Injection Rules Not Applicable
|
Informational | N/A |
123456789012 |
Global |
FS-54 |
ADVISORY: Penetration Testing — Manual Review Required
Details and remediationDetails
Penetration testing evidence cannot be verified via AWS APIs. Manual review required to confirm GenAI applications have been tested. Resolution
1. Conduct penetration testing of GenAI applications at least annually and before major releases. 2. Include AI-specific test cases: prompt injection, jailbreak, indirect (cross-domain) injection, system-prompt leakage, and data-extraction attempts. 3. Consider AWS Security Agent for on-demand, AI-driven penetration testing (GA March 2026; available in US East N. Virginia, US West Oregon, Europe Ireland, Europe Frankfurt, Asia Pacific Sydney, Asia Pacific Tokyo, with cross-account shared-VPC testing via AWS RAM). Open-source tools such as Garak or PyRIT and manual red-teaming are complementary options. Verify current regional availability on the AWS Security Agent page before relying on it. 4. Document findings and remediation for regulatory examination, and tag tested resources with a last-pentest-date for audit trail. 5. For DORA compliance, include GenAI in TLPT (Threat-Led Penetration Testing) scope. |
Informational | N/A |
123456789012 |
Global |
FS-55 |
No Output Validation Functions Found
Details and remediationDetails
No Lambda functions with output validation/sanitization naming found. GenAI outputs may be passed directly to downstream systems without validation. Resolution
1. Implement output validation Lambda functions in GenAI pipelines. 2. Validate output schema, length, and content before downstream use. 3. Sanitize outputs before rendering in web UIs (XSS prevention). 4. Encode outputs appropriately for the target context (HTML, SQL, JSON). |
Medium | Failed |
123456789012 |
Global |
FS-56 |
No WAF ACLs — XSS Prevention Not Applicable
|
Informational | N/A |
123456789012 |
Global |
FS-57 |
ADVISORY: Output Encoding — Manual Review Required
Details and remediationDetails
Output encoding practices cannot be verified via AWS APIs. Manual code review required. Resolution
1. HTML-encode GenAI outputs before rendering in web UIs. 2. Use parameterized queries when GenAI output is used in database operations. 3. JSON-encode outputs before embedding in JavaScript contexts. 4. Validate output length and format before passing to downstream APIs. |
Informational | N/A |
123456789012 |
Global |
FS-58 |
ADVISORY: Output Schema Validation — Manual Review Required
Details and remediationDetails
Found 0 Lambda function(s) whose names suggest schema/validation handling. Structured-output / JSON-schema validation of GenAI responses is an application-layer control that cannot be verified automatically — manual review required. Resolution
1. Use Bedrock structured output (response schemas) where supported. 2. Implement JSON schema validation on Lambda output processors. 3. Reject malformed outputs and return safe error responses. 4. Log schema validation failures to CloudWatch for monitoring. |
Informational | N/A |
123456789012 |
Global |
FS-59 |
No Guardrails — Topic Allowlist Not Applicable
|
Informational | N/A |
123456789012 |
Global |
FS-60 |
ADVISORY: Contextual Grounding for Off-Topic Prevention
Details and remediationDetails
Contextual grounding for off-topic prevention is covered by guardrail grounding checks (FS-47) and RAG configuration (FS-48). Additionally verify system prompts explicitly scope the assistant's role. Resolution
1. Include explicit scope instructions in system prompts. 2. Use Bedrock Guardrails relevance grounding filter. 3. Test with off-topic prompts in QA to verify rejection behavior. |
Informational | N/A |
123456789012 |
Global |
FS-61 |
No Knowledge Bases Found
|
Informational | N/A |
123456789012 |
Global |
FS-62 |
ADVISORY: Data Currency Disclaimer — Manual Review Required
Details and remediationDetails
Data currency disclaimers cannot be verified via AWS APIs. Manual review required. Resolution
1. Add data currency disclaimers to GenAI outputs: 'Information based on data current as of [KB last sync date].' 2. Expose KB last sync timestamp in application responses. 3. Alert users when KB data is older than defined threshold. |
Informational | N/A |
123456789012 |
Global |
FS-63 |
Foundation Model Lifecycle Governance Detected
Details and remediationDetails
12 AWS Config rule(s) with lifecycle- or model-related names were found, indicating some account-side model lifecycle governance: s3-version-lifecycle-policy-check-conformance-pack-p8leqndpf, s3-version-lifecycle-policy-check-conformance-pack-sawupzefn, securityhub-ecr-private-lifecycle-policy-configured-d43efb24, securityhub-s3-lifecycle-policy-check-7366ee18, securityhub-s3express-dir-bucket-lifecycle-rules-check-e56d6ca5. Rule names are a heuristic; whether these rules enforce model currency is not assessed. For context, 17 of 122 model(s) offered in this region are marked LEGACY (for example ai21.jamba-1-5-large-v1:0, ai21.jamba-1-5-mini-v1:0, amazon.nova-canvas-v1:0, amazon.nova-premier-v1:0, amazon.nova-premier-v1:0:1000k); this reflects the regional catalogue, not this account's usage. Resolution
Confirm the matched rules genuinely track model currency, and that deprecation notifications are monitored. |
Medium | Passed |
123456789012 |
Global |
FS-65 |
No Knowledge Bases Found
|
Informational | N/A |
123456789012 |
Global |
FS-66 |
No AgentCore Runtimes Found
|
Informational | N/A |
123456789012 |
Global |
FS-67 |
No Agent Action-Group Lambda Functions Found
Details and remediationDetails
No Lambda functions matching agent action-group naming patterns found. If agents perform financial transactions, verify transaction-value limits are enforced in the action-group implementation. Resolution
1. Implement transaction-value threshold checks in all agent action-group Lambda functions that initiate financial operations. 2. Use AgentCore Policy Engine to enforce maximum transaction amounts as a policy constraint on tool calls. 3. Reject or escalate to human review any transaction exceeding defined limits. |
Informational | N/A |
123456789012 |
Global |
FS-68 |
API Gateway Request Body Size Limits Not Enforced
Details and remediationDetails
Found 4 REST API(s) and 0 regional WAF Web ACL(s), but none enforce a maximum request-body size. Note: an API Gateway request validator does NOT cap body size (it validates the schema and required params; the REST limit is a fixed 10 MB), and a WAF body SizeConstraint only inspects the first ~16 KB of the body by default. Oversized prompts can exhaust Bedrock token quotas and inflate costs. Resolution
1. Add a maxLength (or maxItems/maxProperties) bound to the request-body JSON-Schema model used by your request validator, so oversized prompts are rejected with a 400. 2. Add a WAF SizeConstraintStatement on the request Body sized within WAF's body-inspection window (default 16 KB; raise via the web ACL AssociationConfig, or set OversizeHandling=MATCH to block bodies beyond the window), and associate the ACL with the API stage. 3. Set the max_tokens parameter in Bedrock API calls to cap output length. 4. Implement client-side token counting before submitting requests. |
Medium | Failed |
123456789012 |
Global |
FS-69 |
Prompt Input Validation Functions Present
Details and remediation |
Medium | Passed |
123456789012 |
us-east-1 |
FS-00 |
Responsible AI GRC — Regional Scope Not Applicable
|
Informational | N/A |
123456789012 |
us-west-2 |
FS-00 |
Responsible AI GRC — Regional Scope Not Applicable
|
Informational | N/A |
123456789012 |
us-east-2 |
FS-00 |
Responsible AI GRC — Regional Scope Not Applicable
|
Informational | N/A |
123456789012 |
us-east-1 |
OW-01 |
OWASP LLM01: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis. |
Informational | N/A |
123456789012 |
us-east-1 |
OW-07 |
OWASP LLM07: Model Invocation Logging
Details and remediation |
Informational | N/A |
123456789012 |
us-east-1 |
OW-07 |
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident. |
Informational | N/A |
123456789012 |
us-east-1 |
OW-07 |
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
|
Informational | N/A |
123456789012 |
us-east-1 |
OW-09 |
OWASP LLM09: Model Evaluation Jobs
|
Informational | N/A |
123456789012 |
us-east-1 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
|
Informational | N/A |
123456789012 |
us-east-1 |
OW-06 |
OWASP LLM06: Agent Action-Group Least Privilege
|
Informational | N/A |
123456789012 |
us-east-1 |
OW-10 |
OWASP LLM10: Service Quota Throttling Limits
Details and remediation |
Informational | N/A |
123456789012 |
us-east-1 |
OW-01 |
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier. |
Informational | N/A |
123456789012 |
us-east-1 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
|
Informational | N/A |
123456789012 |
us-east-1 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
|
Informational | N/A |
123456789012 |
us-east-1 |
OW-02 |
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation |
Informational | N/A |
123456789012 |
us-east-1 |
OW-01 |
OWASP LLM01: Contextual Grounding Guardrail
|
Informational | N/A |
123456789012 |
us-east-1 |
OW-04 |
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation |
Informational | N/A |
123456789012 |
us-east-1 |
OW-09 |
OWASP LLM09: Contextual Grounding for Faithfulness
|
Informational | N/A |
123456789012 |
us-east-1 |
OW-06 |
OWASP LLM06: Bedrock Agent Guardrail Association
|
Informational | N/A |
123456789012 |
us-east-1 |
OW-06 |
OWASP LLM06: Agent Idle Session TTL
|
Informational | N/A |
123456789012 |
us-east-1 |
OW-03 |
OWASP LLM03: Imported-Model KMS Provenance
|
Informational | N/A |
123456789012 |
us-east-1 |
OW-10 |
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation |
Informational | N/A |
123456789012 |
us-east-1 |
OW-03 |
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check BR-33: Amazon Inspector Lambda standard scanning and Lambda code scanning are both ENABLED in us-east-1. Detected 1 Lambda function(s) with Bedrock indicators: aiml-security-aiml-sec-123456789012-BedrockAssessment. Resolution
Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain. |
Medium | Passed |
123456789012 |
us-east-1 |
OW-01 |
OWASP LLM01: Preventive Prompt Attack Filter
|
Informational | N/A |
123456789012 |
us-east-1 |
OW-02 |
OWASP LLM02: Bedrock Data Retention Boundary
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check BR-37: Bedrock account data retention is inherit; this does not establish an explicit account-level zero-data-retention setting. Resolution
Configure Bedrock account data retention as none and disable provider data sharing when prompts or responses may contain sensitive information. |
High | Failed |
123456789012 |
us-east-1 |
OW-02 |
OWASP LLM02: Automated Reasoning Policy Encryption
Details and remediation |
Informational | N/A |
123456789012 |
us-east-1 |
OW-03 |
OWASP LLM03: Marketplace Endpoint VPC Isolation
Details and remediation |
Informational | N/A |
123456789012 |
us-east-1 |
OW-02 |
OWASP LLM02: Marketplace Endpoint CMK Encryption
|
Informational | N/A |
123456789012 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Internet Exposure
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-01: No SageMaker notebook instances or domains found to check Resolution
Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths. |
Informational | N/A |
123456789012 |
us-east-1 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: No SageMaker resources found to check for data protection Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
Informational | N/A |
123456789012 |
us-east-1 |
OW-01 |
OWASP LLM01: GuardDuty AI Protection
|
High | Failed |
123456789012 |
us-east-1 |
OW-10 |
OWASP LLM10: GuardDuty AI Protection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check SM-26: GuardDuty is enabled, but the AI Protection detector feature is not enabled. Resolution
Enable the GuardDuty AI_PROTECTION detector feature to detect supported anomalous model invocation and cost-harvesting activity. |
High | Failed |
123456789012 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Clarify Evaluation
|
Informational | N/A |
123456789012 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation |
Informational | N/A |
123456789012 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Model Monitor Coverage
|
Informational | N/A |
123456789012 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Notebook VPC Deployment
|
Informational | N/A |
123456789012 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Model Network Isolation
|
Informational | N/A |
123456789012 |
us-east-1 |
OW-10 |
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation |
Informational | N/A |
123456789012 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker Container Repository Access
Details and remediation |
Informational | N/A |
123456789012 |
us-east-1 |
OW-02 |
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation |
Informational | N/A |
123456789012 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker AutoML Network Isolation
|
Informational | N/A |
123456789012 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically. |
Informational | N/A |
123456789012 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release. |
Informational | N/A |
123456789012 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
123456789012 |
us-east-1 |
OW-09 |
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
123456789012 |
us-east-1 |
OW-03 |
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain. |
Informational | N/A |
123456789012 |
us-east-1 |
OW-04 |
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated. |
Informational | N/A |
123456789012 |
us-east-1 |
OW-02 |
OWASP LLM02: HyperPod Volume CMK Encryption
Details and remediation |
Informational | N/A |
123456789012 |
us-east-1 |
OW-03 |
OWASP LLM03: HyperPod VPC Boundary
Details and remediation |
Informational | N/A |
123456789012 |
us-east-1 |
OW-03 |
OWASP LLM03: Model Registry Resource Policy Boundary
|
Informational | N/A |
123456789012 |
Global |
OW-06 |
OWASP LLM06: AgentCore IAM Least Privilege
|
High | Passed |
123456789012 |
us-east-1 |
OW-06 |
OWASP LLM06: AgentCore Resource-Based Policies
|
Informational | N/A |
123456789012 |
us-east-1 |
OW-02 |
OWASP LLM02: AgentCore Token Vault CMK Encryption
Details and remediation |
High | Failed |
123456789012 |
us-east-1 |
OW-06 |
OWASP LLM06: Code Interpreter Network Isolation
|
Informational | N/A |
123456789012 |
us-east-1 |
OW-06 |
OWASP LLM06: Browser Tool Network Isolation
|
Informational | N/A |
123456789012 |
Global |
OW-10 |
OWASP LLM10: WAF Rate-Based & Shield Protection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-01: AWS Shield Advanced is not subscribed. GenAI API endpoints are vulnerable to volumetric DDoS attacks that can exhaust token quotas and inflate costs. Resolution
Add a WAF RateBasedStatement plus a SizeConstraintStatement on the GenAI ingress and subscribe to AWS Shield Advanced. |
Low | Failed |
123456789012 |
Global |
OW-10 |
OWASP LLM10: WAF Rate-Based & Shield Protection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-01: No AWS WAF regional Web ACLs found. Without WAF, GenAI endpoints lack rate-based rules to block abusive callers. Resolution
Add a WAF RateBasedStatement plus a SizeConstraintStatement on the GenAI ingress and subscribe to AWS Shield Advanced. |
Medium | Failed |
123456789012 |
Global |
OW-10 |
OWASP LLM10: API Gateway Usage Plans
|
Informational | N/A |
123456789012 |
Global |
OW-10 |
OWASP LLM10: Bedrock TPM/RPM Quotas Customised
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-03: Found 266 Bedrock token-based quota(s); at least one applied value exceeds the AWS default, indicating quotas have been reviewed and raised. Resolution
Customise Bedrock service quotas above the account default so consumption is explicitly bounded. |
Medium | Passed |
123456789012 |
Global |
OW-10 |
OWASP LLM10: Cost Anomaly Detection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-04: No AWS Cost Anomaly Detection monitors found. Unexpected spikes in Bedrock/SageMaker usage (e.g., from prompt injection loops) will go undetected. Resolution
Configure AWS Cost Anomaly Detection monitors that include Bedrock and SageMaker. |
Medium | Failed |
123456789012 |
Global |
OW-10 |
OWASP LLM10: Token / Throttle Alarms
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-05: No CloudWatch alarms found for Bedrock metrics. Token exhaustion and throttling events will not trigger operational alerts. Resolution
Create CloudWatch alarms on the Bedrock namespace for InvocationThrottles and token counters. |
Medium | Failed |
123456789012 |
Global |
OW-10 |
OWASP LLM10: AWS Budgets with Bedrock Filters
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-06: No AWS Budgets found scoped to Bedrock or SageMaker. Unbounded GenAI spend can go undetected until the monthly bill. Resolution
Configure AWS Budgets with FilterExpression / CostFilters targeting Bedrock or SageMaker spend, with an alerting SNS action. |
Medium | Failed |
123456789012 |
Global |
OW-06 |
OWASP LLM06: Agent Execution Role Least Privilege
|
Informational | N/A |
123456789012 |
Global |
OW-06 |
OWASP LLM06: AgentCore Gateway Policy Engine
|
Informational | N/A |
123456789012 |
Global |
OW-06 |
OWASP LLM06: Agent Tool Concurrency Limits
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check FS-09: Agent-related Lambda functions without reserved concurrency: aiml-security-aiml-sec-123456789012-AgentCoreAssessment, aiml-security-aiml-sec-123456789012-CleanupBucket, aiml-security-aiml-sec-123456789012-ResolveRegions, aiml-security-aiml-sec-123456789012-SagemakerAssessment, aiml-security-aiml-sec-123456789012-GenerateReport, aiml-security-aiml-sec-123456789012-AgentRegistryAssessment, aiml-security-aiml-sec-123456789012-RAIGRCAssessment, aiml-security-aiml-sec-123456789012-BedrockAssessment, AIML-Standalone-CodeBuildStartBuildLambda-eAzlGvTTrtQW, aiml-security-aiml-sec-123456789012-IAMPermissionCaching. Unlimited concurrency allows runaway agent loops to exhaust account limits. Resolution
Set reserved concurrency on agent action-group Lambdas so a runaway agent cannot exhaust downstream capacity. |
Medium | Failed |
123456789012 |
Global |
OW-06 |
OWASP LLM06: Human-in-the-Loop Callback States
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check FS-10: No Step Functions state machines with agent/approval naming found. Verify that high-risk agent actions (e.g., fund transfers, account changes) have human approval gates. Resolution
Insert Step Functions .waitForTaskToken callback states before any high-risk agent-triggered action. |
Informational | N/A |
123456789012 |
Global |
OW-03 |
OWASP LLM03: SCP-Enforced Model Allowlist
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check FS-12: No Service Control Policies reference Bedrock. Without SCPs, any account in the organization can access any Bedrock model, including unapproved third-party models. Resolution
Attach an Organizations SCP that denies Bedrock inference outside allowlisted model and inference-profile ARNs using Resource or NotResource scoping. |
High | Failed |
123456789012 |
Global |
OW-03 |
OWASP LLM03: Custom-Model Provenance Tags
|
Medium | Passed |
123456789012 |
Global |
OW-03 |
OWASP LLM03: Config Rules for Model Onboarding
|
Medium | Passed |
123456789012 |
Global |
OW-03 |
OWASP LLM03: Adversarial Evaluation Coverage
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check FS-15: No Bedrock Model Evaluation jobs found. Models have not been evaluated for adversarial robustness. Model-risk management (SR 11-7) expects documented model validation/evaluation. Resolution
Run Bedrock evaluation jobs that include adversarial and safety datasets before promoting a model to production. |
Medium | Failed |
123456789012 |
Global |
OW-03 |
OWASP LLM03: ECR Image Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check FS-16: Amazon Inspector enhanced scanning for ECR is ENABLED account-wide, so all 2 repository(ies) are continuously scanned. 1 repository(ies) do not set scan-on-push (cdk-hnb659fds-container-assets-123456789012-us-east-1), which is expected when enhanced scanning supersedes basic scanning. Resolution
Enable Amazon Inspector enhanced scanning or scan-on-push on ECR repositories that hold model / agent container images. |
High | Passed |
123456789012 |
Global |
OW-04 |
OWASP LLM04: Feature Store Offline Recovery
Details and remediation |
Informational | N/A |
123456789012 |
Global |
OW-04 |
OWASP LLM04: Training-Data Versioning
|
Informational | N/A |
123456789012 |
Global |
OW-08 |
OWASP LLM08: KB IAM Scope
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-22: 787 role(s) with wildcard KB permissions: - Role 'Admin' allows '*' - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-tb9zKkm0IYdg' allows 'bedrock:ListGuardrails' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-tb9zKkm0IYdg' allows 'bedrock:GetGuardrail' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-tb9zKkm0IYdg' allows 'bedrock:GetModelInvocationLoggingConfiguration' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-tb9zKkm0IYdg' allows 'bedrock:ListPrompts' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-tb9zKkm0IYdg' allows 'bedrock:GetPrompt' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-tb9zKkm0IYdg' allows 'bedrock:ListAgents' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-tb9zKkm0IYdg' allows 'bedrock:GetAgent' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-tb9zKkm0IYdg' allows 'bedrock:ListCustomModels' on Resource '*' (no ARN scoping to specific Knowledge Bases) - Role 'aiml-sec-123456789012-BedrockSecurityAssessmentFunc-tb9zKkm0IYdg' allows 'bedrock:GetCustomModel' on Resource '*' (no ARN scoping to specific Knowledge Bases) Resolution
Scope Knowledge Base IAM roles to specific KB ARNs; remove wildcard bedrock:* on KB actions. |
High | Failed |
123456789012 |
Global |
OW-08 |
OWASP LLM08: KB Metadata Filtering
|
Informational | N/A |
123456789012 |
Global |
OW-08 |
OWASP LLM08: OpenSearch Serverless Encryption
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-25: No OpenSearch Serverless collections exist in this region, so there is no OpenSearch vector-store data at rest to encrypt. If Bedrock Knowledge Bases use a different vector store (S3 Vectors, Aurora, Pinecone), verify its encryption separately. Resolution
Use a customer-managed KMS key on the OpenSearch Serverless encryption policy for the vector collection. |
Informational | N/A |
123456789012 |
Global |
OW-08 |
OWASP LLM08: OpenSearch Serverless Network Policy
Details and remediationDetails
OWASP category: LLM08:2025 Vector and Embedding Weaknesses. Source check FS-26: No OpenSearch Serverless network policies found. Vector store collections may be publicly accessible. Resolution
Set AllowFromPublic=false on the OpenSearch Serverless network policy and restrict access to bedrock.amazonaws.com or a specific VPC endpoint. |
High | Failed |
123456789012 |
Global |
OW-09 |
OWASP LLM09: Knowledge-Base Ingestion Freshness
|
Informational | N/A |
123456789012 |
Global |
OW-09 |
OWASP LLM09: Source Attribution
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check FS-32: Source attribution in GenAI responses cannot be verified via AWS APIs. Manual review required to confirm responses include citations. Resolution
Return citations in RetrieveAndGenerate responses so end users can verify grounding. |
Informational | N/A |
123456789012 |
Global |
OW-09 |
OWASP LLM09: KB S3 Data-Source Integrity
|
Informational | N/A |
123456789012 |
Global |
OW-04 |
OWASP LLM04: SageMaker Model Card Documentation
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check FS-42: No SageMaker Model Cards found. If GenAI workloads run on Bedrock rather than SageMaker, model documentation may legitimately live elsewhere; Model Cards are a SageMaker-specific artifact. Resolution
Create SageMaker Model Cards for production models that document intended use, training data provenance, and bias/fairness evaluations so poisoned or drifted models are detectable against a documented baseline. |
Informational | N/A |
123456789012 |
Global |
OW-09 |
OWASP LLM09: SageMaker Model Card Documentation
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check FS-42: No SageMaker Model Cards found. If GenAI workloads run on Bedrock rather than SageMaker, model documentation may legitimately live elsewhere; Model Cards are a SageMaker-specific artifact. Resolution
Document each production model's intended use, known limitations, and evaluation results in a SageMaker Model Card so misinformation risks tied to model behaviour are traceable to a reviewed system card. |
Informational | N/A |
123456789012 |
Global |
OW-02 |
OWASP LLM02: CloudWatch Log Data Protection Policies
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-43: Bedrock model invocation logging is not enabled, so no invocation logs are being delivered and there is no log content to mask. Prompt and completion content is therefore also unavailable for audit. Resolution
Apply a CloudWatch Logs data protection policy to log groups that receive Bedrock invocation logs. |
Informational | N/A |
123456789012 |
Global |
OW-02 |
OWASP LLM02: Macie Sensitive-Data Discovery
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-44: Amazon Macie is enabled, but automated sensitive data discovery is DISABLED. Enabling Macie alone does not scan any data, so S3 buckets containing training data and KB data sources are not being evaluated for PII. Resolution
Enable Amazon Macie with automated discovery on S3 buckets that hold training or knowledge-base data. |
High | Failed |
123456789012 |
Global |
OW-02 |
OWASP LLM02: Guardrail PII Entities Coverage
|
Informational | N/A |
123456789012 |
Global |
OW-02 |
OWASP LLM02: S3 Data-Classification Tagging
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check FS-46: No S3 buckets with AI/ML naming found. Resolution
Tag training and knowledge-base S3 buckets with a data-classification tag so downstream automations enforce controls consistent with the sensitivity level. |
Informational | N/A |
123456789012 |
Global |
OW-09 |
OWASP LLM09: Grounding Filter Threshold
|
Informational | N/A |
123456789012 |
Global |
OW-09 |
OWASP LLM09: Active Knowledge Base Present
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check FS-48: No active Bedrock Knowledge Bases found. GenAI responses are not grounded in authoritative data sources, increasing hallucination risk. Resolution
Deploy at least one ACTIVE Knowledge Base when Bedrock models are used, so grounded retrieval is available. |
Medium | Failed |
123456789012 |
Global |
OW-01 |
OWASP LLM01: PROMPT_ATTACK Filter at Standard Tier
|
Informational | N/A |
123456789012 |
Global |
OW-01 |
OWASP LLM01: Bedrock-Calling Lambda Runtimes
|
Medium | Passed |
123456789012 |
Global |
OW-01 |
OWASP LLM01: WAF SQLi & KnownBadInputs Coverage
|
Informational | N/A |
123456789012 |
Global |
OW-01 |
OWASP LLM01: Adversarial Testing Evidence
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check FS-54: Penetration testing evidence cannot be verified via AWS APIs. Manual review required to confirm GenAI applications have been tested. Resolution
Track adversarial / red-team penetration test evidence for the GenAI application via resource tags or an equivalent audit trail. |
Informational | N/A |
123456789012 |
Global |
OW-05 |
OWASP LLM05: Output-Validation Lambda
Details and remediationDetails
OWASP category: LLM05:2025 Improper Output Handling. Source check FS-55: No Lambda functions with output validation/sanitization naming found. GenAI outputs may be passed directly to downstream systems without validation. Resolution
Deploy an output-validation / sanitisation Lambda between the model response and any downstream consumer to filter injection payloads in generated output. |
Medium | Failed |
123456789012 |
Global |
OW-05 |
OWASP LLM05: WAF XSS Protection
|
Informational | N/A |
123456789012 |
Global |
OW-05 |
OWASP LLM05: Output Encoding Libraries
Details and remediationDetails
OWASP category: LLM05:2025 Improper Output Handling. Source check FS-57: Output encoding practices cannot be verified via AWS APIs. Manual code review required. Resolution
Ensure Lambdas that render model output use a well-known output-encoding library appropriate to the downstream sink (HTML, SQL, shell, etc.). |
Informational | N/A |
123456789012 |
Global |
OW-05 |
OWASP LLM05: Step Functions Output Schema Validation
Details and remediationDetails
OWASP category: LLM05:2025 Improper Output Handling. Source check FS-58: Found 0 Lambda function(s) whose names suggest schema/validation handling. Structured-output / JSON-schema validation of GenAI responses is an application-layer control that cannot be verified automatically — manual review required. Resolution
Add explicit schema-validation states in Step Functions workflows that consume model output. |
Informational | N/A |
123456789012 |
Global |
OW-06 |
OWASP LLM06: Agent Transaction Thresholds
Details and remediationDetails
OWASP category: LLM06:2025 Excessive Agency. Source check FS-67: No Lambda functions matching agent action-group naming patterns found. If agents perform financial transactions, verify transaction-value limits are enforced in the action-group implementation. Resolution
Encode agent transaction thresholds in Cedar policies or Lambda configuration so per-action limits are enforced. |
Informational | N/A |
123456789012 |
Global |
OW-10 |
OWASP LLM10: API Gateway Request Body Size Limits
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check FS-68: Found 4 REST API(s) and 0 regional WAF Web ACL(s), but none enforce a maximum request-body size. Note: an API Gateway request validator does NOT cap body size (it validates the schema and required params; the REST limit is a fixed 10 MB), and a WAF body SizeConstraint only inspects the first ~16 KB of the body by default. Oversized prompts can exhaust Bedrock token quotas and inflate costs. Resolution
Configure API Gateway request validation or an equivalent ingress control so GenAI endpoints reject oversized request bodies before they can drive excessive model consumption. |
Medium | Failed |
123456789012 |
Global |
OW-01 |
OWASP LLM01: Prompt-Input Validation Lambda
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check FS-69: Found 1 Lambda function(s) with input validation/sanitization naming patterns: aiml-security-aiml-sec-123456789012-CleanupBucket. Resolution
Deploy a prompt-input validation Lambda in front of Bedrock invocations to sanitise untrusted input before it reaches the model. |
Medium | Passed |
123456789012 |
us-east-1 |
OW-11 |
OWASP LLM07: System Prompt Embedded in Lambda Env Var
|
Medium | Passed |
123456789012 |
us-east-1 |
OW-12 |
OWASP LLM07: System-Prompt-Disclosure Denied Topic
|
Informational | N/A |
123456789012 |
us-east-2 |
OW-01 |
OWASP LLM01: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis. |
Informational | N/A |
123456789012 |
us-east-2 |
OW-07 |
OWASP LLM07: Model Invocation Logging
Details and remediation |
Informational | N/A |
123456789012 |
us-east-2 |
OW-07 |
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident. |
Informational | N/A |
123456789012 |
us-east-2 |
OW-07 |
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
|
Informational | N/A |
123456789012 |
us-east-2 |
OW-09 |
OWASP LLM09: Model Evaluation Jobs
|
Informational | N/A |
123456789012 |
us-east-2 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
|
Informational | N/A |
123456789012 |
us-east-2 |
OW-06 |
OWASP LLM06: Agent Action-Group Least Privilege
|
Informational | N/A |
123456789012 |
us-east-2 |
OW-10 |
OWASP LLM10: Service Quota Throttling Limits
Details and remediation |
Informational | N/A |
123456789012 |
us-east-2 |
OW-01 |
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier. |
Informational | N/A |
123456789012 |
us-east-2 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
|
Informational | N/A |
123456789012 |
us-east-2 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
|
Informational | N/A |
123456789012 |
us-east-2 |
OW-02 |
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation |
Informational | N/A |
123456789012 |
us-east-2 |
OW-01 |
OWASP LLM01: Contextual Grounding Guardrail
|
Informational | N/A |
123456789012 |
us-east-2 |
OW-04 |
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation |
Informational | N/A |
123456789012 |
us-east-2 |
OW-09 |
OWASP LLM09: Contextual Grounding for Faithfulness
|
Informational | N/A |
123456789012 |
us-east-2 |
OW-06 |
OWASP LLM06: Bedrock Agent Guardrail Association
|
Informational | N/A |
123456789012 |
us-east-2 |
OW-06 |
OWASP LLM06: Agent Idle Session TTL
|
Informational | N/A |
123456789012 |
us-east-2 |
OW-03 |
OWASP LLM03: Imported-Model KMS Provenance
|
Informational | N/A |
123456789012 |
us-east-2 |
OW-10 |
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation |
Informational | N/A |
123456789012 |
us-east-2 |
OW-03 |
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check BR-33: No Lambda functions with Bedrock indicators were found in us-east-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain. |
Informational | N/A |
123456789012 |
us-east-2 |
OW-01 |
OWASP LLM01: Preventive Prompt Attack Filter
|
Informational | N/A |
123456789012 |
us-east-2 |
OW-02 |
OWASP LLM02: Bedrock Data Retention Boundary
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check BR-37: Bedrock account data retention is inherit; this does not establish an explicit account-level zero-data-retention setting. Resolution
Configure Bedrock account data retention as none and disable provider data sharing when prompts or responses may contain sensitive information. |
High | Failed |
123456789012 |
us-east-2 |
OW-02 |
OWASP LLM02: Automated Reasoning Policy Encryption
Details and remediation |
Informational | N/A |
123456789012 |
us-east-2 |
OW-03 |
OWASP LLM03: Marketplace Endpoint VPC Isolation
Details and remediation |
Informational | N/A |
123456789012 |
us-east-2 |
OW-02 |
OWASP LLM02: Marketplace Endpoint CMK Encryption
|
Informational | N/A |
123456789012 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker Internet Exposure
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-01: No SageMaker notebook instances or domains found to check Resolution
Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths. |
Informational | N/A |
123456789012 |
us-east-2 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: No SageMaker resources found to check for data protection Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
Informational | N/A |
123456789012 |
us-east-2 |
OW-01 |
OWASP LLM01: GuardDuty AI Protection
|
High | Failed |
123456789012 |
us-east-2 |
OW-10 |
OWASP LLM10: GuardDuty AI Protection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check SM-26: GuardDuty is enabled, but the AI Protection detector feature is not enabled. Resolution
Enable the GuardDuty AI_PROTECTION detector feature to detect supported anomalous model invocation and cost-harvesting activity. |
High | Failed |
123456789012 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Clarify Evaluation
|
Informational | N/A |
123456789012 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation |
Informational | N/A |
123456789012 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Model Monitor Coverage
|
Informational | N/A |
123456789012 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker Notebook VPC Deployment
|
Informational | N/A |
123456789012 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker Model Network Isolation
|
Informational | N/A |
123456789012 |
us-east-2 |
OW-10 |
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation |
Informational | N/A |
123456789012 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker Container Repository Access
Details and remediation |
Informational | N/A |
123456789012 |
us-east-2 |
OW-02 |
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation |
Informational | N/A |
123456789012 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker AutoML Network Isolation
|
Informational | N/A |
123456789012 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically. |
Informational | N/A |
123456789012 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release. |
Informational | N/A |
123456789012 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
123456789012 |
us-east-2 |
OW-09 |
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
123456789012 |
us-east-2 |
OW-03 |
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain. |
Informational | N/A |
123456789012 |
us-east-2 |
OW-04 |
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated. |
Informational | N/A |
123456789012 |
us-east-2 |
OW-02 |
OWASP LLM02: HyperPod Volume CMK Encryption
Details and remediation |
Informational | N/A |
123456789012 |
us-east-2 |
OW-03 |
OWASP LLM03: HyperPod VPC Boundary
Details and remediation |
Informational | N/A |
123456789012 |
us-east-2 |
OW-03 |
OWASP LLM03: Model Registry Resource Policy Boundary
|
Informational | N/A |
123456789012 |
us-east-2 |
OW-06 |
OWASP LLM06: AgentCore Resource-Based Policies
|
Informational | N/A |
123456789012 |
us-east-2 |
OW-02 |
OWASP LLM02: AgentCore Token Vault CMK Encryption
Details and remediation |
High | Failed |
123456789012 |
us-east-2 |
OW-06 |
OWASP LLM06: Code Interpreter Network Isolation
|
Informational | N/A |
123456789012 |
us-east-2 |
OW-06 |
OWASP LLM06: Browser Tool Network Isolation
|
Informational | N/A |
123456789012 |
us-east-2 |
OW-11 |
OWASP LLM07: System Prompt Embedded in Lambda Env Var
|
Medium | Passed |
123456789012 |
us-east-2 |
OW-12 |
OWASP LLM07: System-Prompt-Disclosure Denied Topic
|
Informational | N/A |
123456789012 |
us-west-2 |
OW-01 |
OWASP LLM01: Model Invocation Logging
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-04: No regional Bedrock resources found to monitor with invocation logging Resolution
Enable Bedrock model invocation logging to S3 and/or CloudWatch Logs so injection attempts and their surrounding context are captured for detection and post-incident analysis. |
Informational | N/A |
123456789012 |
us-west-2 |
OW-07 |
OWASP LLM07: Model Invocation Logging
Details and remediation |
Informational | N/A |
123456789012 |
us-west-2 |
OW-07 |
OWASP LLM07: Bedrock Prompt Management Adoption
Details and remediationDetails
OWASP category: LLM07:2025 System Prompt Leakage. Source check BR-07: Prompt Management feature is not being used. This may lead to inconsistent prompt handling and suboptimal model responses. Resolution
Manage system prompts through Amazon Bedrock Prompt Management rather than inline code or Lambda env vars so prompts are versioned, IAM-scoped, and auditable — reducing the blast radius of a prompt-leakage incident. |
Informational | N/A |
123456789012 |
us-west-2 |
OW-07 |
OWASP LLM07: Guardrail Standard Tier for Prompt Leakage
|
Informational | N/A |
123456789012 |
us-west-2 |
OW-09 |
OWASP LLM09: Model Evaluation Jobs
|
Informational | N/A |
123456789012 |
us-west-2 |
OW-08 |
OWASP LLM08: Managed Knowledge-Base CMK Encryption
|
Informational | N/A |
123456789012 |
us-west-2 |
OW-06 |
OWASP LLM06: Agent Action-Group Least Privilege
|
Informational | N/A |
123456789012 |
us-west-2 |
OW-10 |
OWASP LLM10: Service Quota Throttling Limits
Details and remediation |
Informational | N/A |
123456789012 |
us-west-2 |
OW-01 |
OWASP LLM01: Guardrail Content Filter Coverage
Details and remediationDetails
OWASP category: LLM01:2025 Prompt Injection. Source check BR-23: No Bedrock guardrails configured in this region Resolution
Enable Bedrock guardrail content filters (HATE, VIOLENCE, SEXUAL, INSULTS, MISCONDUCT) at MEDIUM strength or higher, and set the PROMPT_ATTACK filter at STANDARD tier. |
Informational | N/A |
123456789012 |
us-west-2 |
OW-04 |
OWASP LLM04: RAG Evaluation Coverage
|
Informational | N/A |
123456789012 |
us-west-2 |
OW-09 |
OWASP LLM09: RAG Evaluation for Faithfulness
|
Informational | N/A |
123456789012 |
us-west-2 |
OW-02 |
OWASP LLM02: Guardrail PII / Regex Filters
Details and remediation |
Informational | N/A |
123456789012 |
us-west-2 |
OW-01 |
OWASP LLM01: Contextual Grounding Guardrail
|
Informational | N/A |
123456789012 |
us-west-2 |
OW-04 |
OWASP LLM04: Contextual Grounding on Retrieved Data
Details and remediation |
Informational | N/A |
123456789012 |
us-west-2 |
OW-09 |
OWASP LLM09: Contextual Grounding for Faithfulness
|
Informational | N/A |
123456789012 |
us-west-2 |
OW-06 |
OWASP LLM06: Bedrock Agent Guardrail Association
|
Informational | N/A |
123456789012 |
us-west-2 |
OW-06 |
OWASP LLM06: Agent Idle Session TTL
|
Informational | N/A |
123456789012 |
us-west-2 |
OW-03 |
OWASP LLM03: Imported-Model KMS Provenance
|
Informational | N/A |
123456789012 |
us-west-2 |
OW-10 |
OWASP LLM10: CloudWatch Consumption Alarms
Details and remediation |
Informational | N/A |
123456789012 |
us-west-2 |
OW-03 |
OWASP LLM03: Inspector Lambda Code Scanning
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check BR-33: No Lambda functions with Bedrock indicators were found in us-west-2; Inspector Lambda code-scanning coverage was not assessed for Bedrock-calling Lambda workloads. Resolution
Enable Amazon Inspector Lambda standard scanning and Lambda code scanning so vulnerable dependencies and hardcoded secrets in Bedrock-calling Lambda functions are detected as part of the GenAI supply chain. |
Informational | N/A |
123456789012 |
us-west-2 |
OW-01 |
OWASP LLM01: Preventive Prompt Attack Filter
|
Informational | N/A |
123456789012 |
us-west-2 |
OW-02 |
OWASP LLM02: Bedrock Data Retention Boundary
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check BR-37: Bedrock account data retention is inherit; this does not establish an explicit account-level zero-data-retention setting. Resolution
Configure Bedrock account data retention as none and disable provider data sharing when prompts or responses may contain sensitive information. |
High | Failed |
123456789012 |
us-west-2 |
OW-02 |
OWASP LLM02: Automated Reasoning Policy Encryption
Details and remediation |
Informational | N/A |
123456789012 |
us-west-2 |
OW-03 |
OWASP LLM03: Marketplace Endpoint VPC Isolation
Details and remediation |
Informational | N/A |
123456789012 |
us-west-2 |
OW-02 |
OWASP LLM02: Marketplace Endpoint CMK Encryption
|
Informational | N/A |
123456789012 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker Internet Exposure
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-01: No SageMaker notebook instances or domains found to check Resolution
Disable direct internet access on SageMaker notebooks and configure domains for VPC-only access to reduce supply-chain exposure from unmanaged network paths. |
Informational | N/A |
123456789012 |
us-west-2 |
OW-02 |
OWASP LLM02: SageMaker Data Encryption
Details and remediationDetails
OWASP category: LLM02:2025 Sensitive Information Disclosure. Source check SM-03: No SageMaker resources found to check for data protection Resolution
Configure SageMaker notebooks, domains, and training jobs to use customer-managed KMS keys and encryption in transit for sensitive training and inference data. |
Informational | N/A |
123456789012 |
us-west-2 |
OW-01 |
OWASP LLM01: GuardDuty AI Protection
|
High | Failed |
123456789012 |
us-west-2 |
OW-10 |
OWASP LLM10: GuardDuty AI Protection
Details and remediationDetails
OWASP category: LLM10:2025 Unbounded Consumption. Source check SM-26: GuardDuty is enabled, but the AI Protection detector feature is not enabled. Resolution
Enable the GuardDuty AI_PROTECTION detector feature to detect supported anomalous model invocation and cost-harvesting activity. |
High | Failed |
123456789012 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Clarify Evaluation
|
Informational | N/A |
123456789012 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker Model Monitor Coverage
Details and remediation |
Informational | N/A |
123456789012 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Model Monitor Coverage
|
Informational | N/A |
123456789012 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker Notebook VPC Deployment
|
Informational | N/A |
123456789012 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker Model Network Isolation
|
Informational | N/A |
123456789012 |
us-west-2 |
OW-10 |
OWASP LLM10: SageMaker Model Outbound Network Control
Details and remediation |
Informational | N/A |
123456789012 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker Container Repository Access
Details and remediation |
Informational | N/A |
123456789012 |
us-west-2 |
OW-02 |
OWASP LLM02: SageMaker Feature Store Encryption
Details and remediation |
Informational | N/A |
123456789012 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker AutoML Network Isolation
|
Informational | N/A |
123456789012 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Require SageMaker Model Registry approval workflows before production deployment so poisoned or unreviewed model versions are not promoted automatically. |
Informational | N/A |
123456789012 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Model Approval Workflow
Details and remediationDetails
OWASP category: LLM09:2025 Misinformation. Source check SM-22: No model package groups found. Model Registry is not being used for model governance. Resolution
Use SageMaker Model Registry approval workflows to ensure model behavior, intended use, and validation evidence are reviewed before production release. |
Informational | N/A |
123456789012 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
123456789012 |
us-west-2 |
OW-09 |
OWASP LLM09: SageMaker Model Drift Detection
Details and remediation |
Medium | Passed |
123456789012 |
us-west-2 |
OW-03 |
OWASP LLM03: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM03:2025 Supply Chain. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Use SageMaker Experiments and lineage associations to track training runs, parameters, artifacts, and model package provenance across the ML supply chain. |
Informational | N/A |
123456789012 |
us-west-2 |
OW-04 |
OWASP LLM04: SageMaker ML Lineage Tracking
Details and remediationDetails
OWASP category: LLM04:2025 Data and Model Poisoning. Source check SM-25: No SageMaker Experiments found. ML Lineage tracking through Experiments is not being utilized. Resolution
Track SageMaker training lineage from source data through model artifacts so poisoned data or model versions can be traced and remediated. |
Informational | N/A |
123456789012 |
us-west-2 |
OW-02 |
OWASP LLM02: HyperPod Volume CMK Encryption
Details and remediation |
Informational | N/A |
123456789012 |
us-west-2 |
OW-03 |
OWASP LLM03: HyperPod VPC Boundary
Details and remediation |
Informational | N/A |
123456789012 |
us-west-2 |
OW-03 |
OWASP LLM03: Model Registry Resource Policy Boundary
|
Informational | N/A |
123456789012 |
us-west-2 |
OW-06 |
OWASP LLM06: AgentCore Resource-Based Policies
|
Informational | N/A |
123456789012 |
us-west-2 |
OW-02 |
OWASP LLM02: AgentCore Token Vault CMK Encryption
Details and remediation |
High | Failed |
123456789012 |
us-west-2 |
OW-06 |
OWASP LLM06: Code Interpreter Network Isolation
|
Informational | N/A |
123456789012 |
us-west-2 |
OW-06 |
OWASP LLM06: Browser Tool Network Isolation
|
Informational | N/A |
123456789012 |
us-west-2 |
OW-11 |
OWASP LLM07: System Prompt Embedded in Lambda Env Var
|
Medium | Passed |
123456789012 |
us-west-2 |
OW-12 |
OWASP LLM07: System-Prompt-Disclosure Denied Topic
|
Informational | N/A |
Scope: API-provable Agentic AI security controls mapped to the AWS Well-Architected Agentic AI Lens security guidance. Human-in-the-loop governance is referenced in methodology but not scored automatically unless an AWS API can prove the control.
Scope: Responsible AI GRC comprises 64 automated checks that evaluate selected AWS configuration evidence against project-authored technical controls informed by the AWS User Guide to Governance, Risk, and Compliance for Responsible AI Adoption and by AWS financial-services generative-AI risk guidance. The controls originated as financial-services controls and were found applicable across multiple industries. They do not establish regulatory compliance, certify a system as responsible AI, or provide complete Responsible AI or GRC coverage. Regulatory framework mappings are preliminary. Manual legal, policy, model-risk, fairness, and use-case review remains required. This assessment records findings against each resolved CloudFormation TargetRegions entry. These checks are based on the AWS User Guide to Governance, Risk, and Compliance for Responsible AI Adoption. Severities follow a documented Likelihood × Impact methodology. Responsible AI GRC is not the AWS Well-Architected Responsible AI Lens. The Lens (November 2025) is a separate architectural review framework with eight focus areas. These checks do not implement, validate, or measure conformance to it, and passing them does not indicate Lens alignment.
Scope: mapping-based derivation from existing BR/SM/AC/AG/FS checks plus two net-new checks for LLM07 (System Prompt Leakage). Each finding's OWASP category (LLM01–LLM10) is encoded in the Finding_Details text. Preliminary and illustrative — validate mappings with your Security/Compliance team before using as evidence.
Assessment Notes
Assessment Scope
Bedrock, SageMaker, AgentCore, and AWS Agent Registry checks are based on the AWS Well-Architected Framework Generative AI Lens. Agentic AI Security references the AWS Well-Architected Agentic AI Lens. Controls that cannot be proven using AWS APIs, including semantic human-in-the-loop workflow quality, are not automatically scored. Responsible AI GRC checks are based on the AWS User Guide to Governance, Risk, and Compliance for Responsible AI Adoption. Responsible AI GRC is not the AWS Well-Architected Responsible AI Lens. The Lens (November 2025) is a separate architectural review framework with eight focus areas. These checks do not implement, validate, or measure conformance to it, and passing them does not indicate Lens alignment. OWASP Top 10 LLM references OWASP Top 10 LLM.