⚠ Critical items requiring immediate attention
- Publicly-accessible S3 bucket(s): log****, por****, v1-501****-hpg-artifactstore, v1-501****-hpt-itemstore, v1-501****-hpt-patientdocs, v1-501****-hpt-uploadpatientstore — includes possible cardholder/patient data stores.
- RDS instance(s) marked PubliclyAccessible: vm1lxyp9qd594ip, vm1lxyp9qd594ip-2.
Disclaimer: Internal engineering gap-check only. Not a formal QSA assessment. Formal compliance requires a Qualified Security Assessor (QSA). Read-only automated collection; no AWS resources were modified.
Least-privilege posture for IAM users/roles and public-exposure checks on S3 and RDS.
Admin sprawlWildcard trustS3 publicRDS public
7.2 — Privileged Access (IAM Users)
| User | Privilege Source | Attached Policies | Status |
|---|
| ali-prod | admin group | (via group) | Needs Review |
| craigprod | scoped | (via group) | Compliant |
| farhanprod | admin group | (via group) | Needs Review |
| hptprodui | scoped | AmazonS3FullAccess | Compliant |
| payalkprod | admin group | (via group) | Needs Review |
| rakheeprod | admin group | (via group) | Needs Review |
| ses-smtp-user.20200903-084439 | scoped | (via group) | Compliant |
| ses-smtp-user.20230729-183444 | scoped | (via group) | Compliant |
| waris-prod | admin group | (via group) | Needs Review |
7.2 — S3 Public-Access Restriction
| Bucket | Public Access Block | Effective | Status |
|---|
| adm**** | 0/4 | private | Gap |
| aws-cloudtrail-logs-501****-aa073ab8 | 4/4 | private | Compliant |
| bac**** | 4/4 | private | Compliant |
| cdk-hnb659fds-assets-501****-us-east-1 | 4/4 | private | Compliant |
| cf-templates-e4zlcd7q18st-us-east-2 | 0/4 | private | Gap |
| cod**** | 4/4 | private | Compliant |
| for**** | 0/4 | private | Gap |
| hp-cf-logging | 4/4 | private | Compliant |
| hp-vpc-flowlog | 4/4 | private | Compliant |
| hptuat-mongodumps | 0/4 | private | Gap |
| hptwarmeeting | 4/4 | private | Compliant |
| log**** | 0/4 | PUBLIC | Critical |
| por**** | 0/4 | PUBLIC | Critical |
| regionalapi-s3bucketaccesslogs-wrzn070su9k7 | 4/4 | private | Compliant |
| rev**** | 4/4 | private | Compliant |
| v1-501****-hpg-artifactstore | 0/4 | PUBLIC | Critical |
| v1-501****-hpg-artifactstore-backup | 4/4 | private | Compliant |
| v1-501****-hpg-secretstore | 4/4 | private | Compliant |
| v1-501****-hpt-itemstore | 3/4 | PUBLIC | Critical |
| v1-501****-hpt-patientdocs | 3/4 | PUBLIC | Critical |
| v1-501****-hpt-uploadpatientstore | 3/4 | PUBLIC | Critical |
IAM Access Analyzer active findings (external/public access): 12 — review each for unintended cross-account/public exposure.
Control Mapping
| Control | Description | Status | Evidence |
|---|
| 7.2.1 | Access limited to least privilege / need-to-know | Needs Review | 5 user(s) with account-admin: ali-prod, farhanprod, payalkprod, rakheeprod, waris-prod |
| 7.2.2 | Privileges assigned by role/function | Needs Review | 5 users in 'admin' group — verify each needs full admin |
| 7.2.5 (Roles) | No overly-permissive role trust policies | Compliant | 0 role(s) with wildcard trust of 59 total |
| 7.2.1 (S3) | S3 buckets restricted from public access | Critical | 6 bucket(s) evaluate as public; 11/21 have full PAB |
| 7.2.1 (RDS) | Databases not publicly reachable | Critical | 2 DB(s) PubliclyAccessible: vm1lxyp9qd594ip, vm1lxyp9qd594ip-2 |
| 7.2.5 (Analyzer) | Access review tooling enabled (IAM Access Analyzer) | Compliant | 12 active external-access finding(s) |
Recommendations
HighRemediate public S3 buckets (log****, por****, v1-501****-hpg-artifactstore, v1-501****-hpt-itemstore, v1-501****-hpt-patientdocs, v1-501****-hpt-uploadpatientstore): enable all 4 Public Access Block settings and remove public bucket policies/ACLs. Confirm no cardholder/patient data is exposed.
HighDisable PubliclyAccessible on RDS instance(s) vm1lxyp9qd594ip, vm1lxyp9qd594ip-2 and place behind private subnets/security groups.
MediumReview the 5-member 'admin' group and apply least privilege / just-in-time elevation.
ProcessPerform documented access reviews at least every 6 months (PCI 7.2.4).