diff --git a/checks/check_extra7119 b/checks/check_extra7119 index e5928f69..081cbbd5 100644 --- a/checks/check_extra7119 +++ b/checks/check_extra7119 @@ -11,17 +11,6 @@ # CONDITIONS OF ANY KIND, either express or implied. See the License for the # specific language governing permissions and limitations under the License. -# Remediation: -# -# https://www.cloudconformity.com/knowledge-base/aws/RDS/instance-deletion-protection.html -# https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/Overview.DBInstance.Modifying.html -# -# aws rds modify-db-instance \ -# --region us-east-1 \ -# --db-instance-identifier test-db \ -# --deletion-protection \ -# [--apply-immediately | --no-apply-immediately] - CHECK_ID_extra7119="7.119" CHECK_TITLE_extra7119="[extra7119] Check if Glue security configurations used by ETL Development endpoints have S3 encryption enabled." CHECK_SCORED_extra7119="NOT_SCORED" diff --git a/checks/check_extra7121 b/checks/check_extra7121 index e5d5c35f..2aa1ef5a 100644 --- a/checks/check_extra7121 +++ b/checks/check_extra7121 @@ -11,17 +11,6 @@ # CONDITIONS OF ANY KIND, either express or implied. See the License for the # specific language governing permissions and limitations under the License. -# Remediation: -# -# https://www.cloudconformity.com/knowledge-base/aws/RDS/instance-deletion-protection.html -# https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/Overview.DBInstance.Modifying.html -# -# aws rds modify-db-instance \ -# --region us-east-1 \ -# --db-instance-identifier test-db \ -# --deletion-protection \ -# [--apply-immediately | --no-apply-immediately] - CHECK_ID_extra7121="7.121" CHECK_TITLE_extra7121="[extra7121] Check if Glue security configurations used by ETL Development endpoints have CloudWatch logs encryption enabled." CHECK_SCORED_extra7121="NOT_SCORED" diff --git a/checks/check_extra7123 b/checks/check_extra7123 index f601c9a4..a6671e86 100644 --- a/checks/check_extra7123 +++ b/checks/check_extra7123 @@ -11,17 +11,6 @@ # CONDITIONS OF ANY KIND, either express or implied. See the License for the # specific language governing permissions and limitations under the License. -# Remediation: -# -# https://www.cloudconformity.com/knowledge-base/aws/RDS/instance-deletion-protection.html -# https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/Overview.DBInstance.Modifying.html -# -# aws rds modify-db-instance \ -# --region us-east-1 \ -# --db-instance-identifier test-db \ -# --deletion-protection \ -# [--apply-immediately | --no-apply-immediately] - CHECK_ID_extra7123="7.123" CHECK_TITLE_extra7123="[extra7123] Check if Glue security configurations used by ETL Development endpoints have Job bookmark encryption enabled." CHECK_SCORED_extra7123="NOT_SCORED" diff --git a/groups/group24_glue b/groups/group24_glue new file mode 100644 index 00000000..4e06b2d0 --- /dev/null +++ b/groups/group24_glue @@ -0,0 +1,19 @@ +#!/usr/bin/env bash + +# Prowler - the handy cloud security tool (copyright 2222) by Toni de la Fuente +# +# Licensed under the Apache License, Version 2.0 (the "License"); you may not +# use this file except in compliance with the License. You may obtain a copy +# of the License at http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software distributed +# under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR +# CONDITIONS OF ANY KIND, either express or implied. See the License for the +# specific language governing permissions and limitations under the License. + +GROUP_ID[24]='glue' +GROUP_NUMBER[24]='24.0' +GROUP_TITLE[24]='Amazon Glue related security checks - [glue] ******************' +GROUP_RUN_BY_DEFAULT[24]='N' # run it when execute_all is called +GROUP_CHECKS[24]='extra7115,extra7116,extra7117,extra7118,extra7120,extra7122' +