Generated by Merlin Studio (https://app.merlin-studio.cloud). Licensed under the Apache License, Version 2.0 (https://www.apache.org/licenses/LICENSE-2.0).
Score: 100/100 | Grade: A
| Category | Check | Status | Weight | Explanation |
|---|---|---|---|---|
| Account Hierarchy | Mandatory accounts (Management/LogArchive/Audit) | ✅ PASS | 25 | All three mandatory accounts have contact emails configured. |
| Account Hierarchy | OU structure | ✅ PASS | 15 | OU structure 'by_environment' with 3 workload account(s). |
| IAM | IAM Identity Center | ✅ PASS | 20 | Identity provider: iam_idc, 5 permission set(s). |
| IAM | SCPs (Service Control Policies) | ✅ PASS | 15 | 5 effective SCP(s) attached (Deny-Root-Access, Guardrails-Security, Protect-Security-Services, Quarantine-Policy, Require-IMDSv2). |
| Networking | VPC count vs profile | ✅ PASS | 10 | 6 VPC(s) for profile standard (expected 1-6, +2 for compliance overlay VPCs). |
| Networking | Transit Gateway | ✅ PASS | 15 | Transit Gateway enabled for cross-VPC/region routing. |
| Networking | VPC Flow Logs | ✅ PASS | 10 | Flow Logs enabled on all 6 VPC(s). |
| Networking | Public/private subnet separation | ✅ PASS | 10 | All VPCs have private subnets alongside any public ones. |
| Security Baseline | GuardDuty | ✅ PASS | 20 | GuardDuty enabled with appropriate protection features. |
| Security Baseline | Security Hub | ✅ PASS | 15 | Security Hub on with 3 standard(s). |
| Security Baseline | CloudTrail org-trail | ✅ PASS | 20 | Multi-region organization-level CloudTrail configured. |
| Security Baseline | AWS Config | ✅ PASS | 10 | AWS Config recorder enabled. |
| Security Baseline | CMK encryption | ✅ PASS | 10 | CMK log encryption enabled with 1 declared key(s). |
| Advanced Security | Macie | ✅ PASS | 15 | Macie enabled — appropriate for declared compliance/sensitivity. |
| Advanced Security | Inspector | ✅ PASS | 10 | Inspector enabled for ECR / EC2 / Lambda vulnerability scanning. LZA users: enable out-of-band — see security-config.yaml header (LZA 1.14.x has no native Inspector block). OpenTofu / CDK / tfvars render natively. |
| Advanced Security | Network Firewall | ✅ PASS | 15 | Centralized egress inspection is live: AWS Network Firewall in the 'inspection' VPC, with spokes routing 0.0.0.0/0 through the Transit Gateway to the firewall (appliance mode) before NAT/IGW. CDE traffic is isolated in its own TGW route domain. |
| Logging | Centralized log bucket | ✅ PASS | 15 | Centralized log bucket: acme-bank-central-logs-PLACEHOLDER_ACCOUNT_ID_LogArchive. |
| Logging | Log retention | ✅ PASS | 15 | 2555 days meets required floor (2555). |
| Compliance | Region pinning vs sovereignty | ✅ PASS | 20 | All enabled regions (4) within US sovereignty zone. |
| Compliance | HSM-backed CMK | ✅ PASS | 5 | No FedRAMP High / EUCS High; HSM not required. |
| Compliance | GovCloud alignment | ✅ PASS | 5 | GovCloud not required. |
| Backup & DR | AWS Backup vault | ✅ PASS | 15 | AWS Backup vault with Vault Lock enabled. |
| Backup & DR | Cross-region backup copy | ✅ PASS | 10 | Backups copied to secondary region: us-west-2. |
| Cost | Budgets + Anomaly Detection | ✅ PASS | 10 | Both Budgets and Cost Anomaly Detection enabled. |