Application · app-aws

Amazon Web Services (ap-south-1)

Controls (9)

Open list →
ControlNameDomainApplicationsQ3 testOpen findings
ACC-01MFA and SSO enforced for workforce accessAccess ControlAmazon Web Services (ap-south-1), Microsoft Entra ID, GitHub Enterprise CloudPass0
ACC-03Privileged access is just-in-time and reviewedAccess ControlAmazon Web Services (ap-south-1), Microsoft Entra ID, SAP S/4HANAFail1
CHG-03Developers have no standing production access; deployments via pipeline onlyChange ManagementAmazon Web Services (ap-south-1), GitHub Enterprise CloudPass0
VUL-01Vulnerabilities are scanned and remediated within SLASecurity OperationsAmazon Web Services (ap-south-1), GitHub Enterprise CloudNot tested0
LOG-01Security events are centrally logged and monitored 24x7Logging & MonitoringAmazon Web Services (ap-south-1), Microsoft Entra ID, Meridian Customer PortalPass0
LOG-02Audit logs retained 180 days online and 5 years archived, tamper-protectedLogging & MonitoringAmazon Web Services (ap-south-1), SAP S/4HANANot tested0
OPS-01Backups are performed daily and monitoredOperations & ResilienceAmazon Web Services (ap-south-1), Microsoft Azure (corporate)Pass0
BCP-01Backup restore and DR are testedOperations & ResilienceAmazon Web Services (ap-south-1), Microsoft Azure (corporate)Pass0
ENC-01Customer and payment data encrypted at rest and in transitData ProtectionAmazon Web Services (ap-south-1), Meridian Customer PortalPass0

Open findings (1)

Open list →
FindingObservationControlApplicationsSeverityStatusOwnerActionValidation
F-ITGC-02Standing privileged access in production AWSACC-03Amazon Web Services (ap-south-1), Microsoft Entra ID, SAP S/4HANAMediumIn ProgressRahul NairREM-F-ITGC-02 · In ProgressPending