Skip to content

Latest commit

 

History

History
32 lines (29 loc) · 3.24 KB

File metadata and controls

32 lines (29 loc) · 3.24 KB

Generated by Merlin Studio (https://app.merlin-studio.cloud). Licensed under the Apache License, Version 2.0 (https://www.apache.org/licenses/LICENSE-2.0).

AWS Architecture Design Scorecard

Score: 100/100 | Grade: A

Category Check Status Weight Explanation
Account Hierarchy Mandatory accounts (Management/LogArchive/Audit) ✅ PASS 25 All three mandatory accounts have contact emails configured.
Account Hierarchy OU structure ✅ PASS 15 OU structure 'by_environment' with 3 workload account(s).
IAM IAM Identity Center ✅ PASS 20 Identity provider: iam_idc, 5 permission set(s).
IAM SCPs (Service Control Policies) ✅ PASS 15 5 effective SCP(s) attached (Deny-Root-Access, Guardrails-Security, Protect-Security-Services, Quarantine-Policy, Require-IMDSv2).
Networking VPC count vs profile ✅ PASS 10 6 VPC(s) for profile standard (expected 1-6, +2 for compliance overlay VPCs).
Networking Transit Gateway ✅ PASS 15 Transit Gateway enabled for cross-VPC/region routing.
Networking VPC Flow Logs ✅ PASS 10 Flow Logs enabled on all 6 VPC(s).
Networking Public/private subnet separation ✅ PASS 10 All VPCs have private subnets alongside any public ones.
Security Baseline GuardDuty ✅ PASS 20 GuardDuty enabled with appropriate protection features.
Security Baseline Security Hub ✅ PASS 15 Security Hub on with 3 standard(s).
Security Baseline CloudTrail org-trail ✅ PASS 20 Multi-region organization-level CloudTrail configured.
Security Baseline AWS Config ✅ PASS 10 AWS Config recorder enabled.
Security Baseline CMK encryption ✅ PASS 10 CMK log encryption enabled with 1 declared key(s).
Advanced Security Macie ✅ PASS 15 Macie enabled — appropriate for declared compliance/sensitivity.
Advanced Security Inspector ✅ PASS 10 Inspector enabled for ECR / EC2 / Lambda vulnerability scanning. LZA users: enable out-of-band — see security-config.yaml header (LZA 1.14.x has no native Inspector block). OpenTofu / CDK / tfvars render natively.
Advanced Security Network Firewall ✅ PASS 15 Centralized egress inspection is live: AWS Network Firewall in the 'inspection' VPC, with spokes routing 0.0.0.0/0 through the Transit Gateway to the firewall (appliance mode) before NAT/IGW. CDE traffic is isolated in its own TGW route domain.
Logging Centralized log bucket ✅ PASS 15 Centralized log bucket: acme-bank-central-logs-PLACEHOLDER_ACCOUNT_ID_LogArchive.
Logging Log retention ✅ PASS 15 2555 days meets required floor (2555).
Compliance Region pinning vs sovereignty ✅ PASS 20 All enabled regions (4) within US sovereignty zone.
Compliance HSM-backed CMK ✅ PASS 5 No FedRAMP High / EUCS High; HSM not required.
Compliance GovCloud alignment ✅ PASS 5 GovCloud not required.
Backup & DR AWS Backup vault ✅ PASS 15 AWS Backup vault with Vault Lock enabled.
Backup & DR Cross-region backup copy ✅ PASS 10 Backups copied to secondary region: us-west-2.
Cost Budgets + Anomaly Detection ✅ PASS 10 Both Budgets and Cost Anomaly Detection enabled.