AWS Misconfigurations
Redshift Audit
Checks performed
- Redshift Clusters Should Allow Version Upgrade
- Redshift Cluster Audit Should Have Logging Enabled
- Redshift Cluster Should Not Use Default Master Username
- Redshift Clusters Should Have Deferred Maintenance Enabled
- EMR In-Transit and At-Rest Encryption
- EMR Clusters Should Be In VPC
- EMR Cluster Logging Should Be Enabled
- EMR Cluster Master Node Should Not Have Public IP
- EMR Clusters Should Be In VPC
- EMR Instances Should Use Latest Generation
- EMR Instances Should Use Latest Generation
- Amazon EMR Clusters Should Have Kerberos Enabled
- Redshift User Activity Logging Should Be Enabled
- Idle Redshift Clusters Should Be Terminated
- Redshift Clusters Should Not Use Default Port
- Redshift Clusters Should Be Encrypted With KMS CMKs
- Redshift Clusters Should Be Encrypted
- Redshift Clusters Should Be Launched Within a VPC
- Redshift Cluster Should Not Be Publicly Accessible
- Redshift Clusters Should Allow Version Upgrade
- Redshift Cluster Nodes Should Be Of The Desired Type
- Clusters With High Disk Usage Should Be Scaled
- Redshift Clusters Should Use Latest Generation Of Nodes
- Redshift Nodes Limit
- Redshift Parameter Group Require SSL
- Redshift Reserved Node Lease Expiration In The Next 7 Days
- Redshift Reserved Node Lease Expiration In The Next 30 Days
- Redshift Reserved Nodes Should Not Have Status - Payment Failed
- Redshift Reserved Node Should Not Have Status - Payment Pending
- Redshift Reserved Node Recent Purchases Should Be Reviewed
- Redshift Automated Snapshots Should Have Retention Period Enabled
- Redshift Cluster Should Not be Underutilized
- Redshift Reserved Nodes Should Not Be Unused