
Scope Assessment results

Budget alerts threshold percentages are not correct: 49% 99% 149%
  Done
CL-Roderick needs to enable MFA (This is a new person that I has not been added from our side and was not there when the previous assessment was done. Will confirm with the client and get MFA configured)
  No change
update tcf-test-ctl-MyCloudTrail-8TTAdG82Kfhf to be a multi-region trail
  Done
AWS Config rules to be cleaned up
  Config rules are not added by scripts, are inherited from Management Account
Update tcf-test-flowlog-cloudwatch and set Filter to capture All traffic
  Done
update tcf-test-flowlog-S3 and set Filter to capture All traffic
  Done
Tag default route table
  I don't create the default route table, this is done by the Silicon Terraform "Base Setup Scripts"
Tag DHCP option sets
  I don't create the DHCP option sets, this is done by the Silicon Terraform "Base Setup Scripts"
Tag Elastic IP 13.246.126.51
  Done
Create Custom NACLs
  Done
Tag Default NACL
  I don't create the Default NACL, this is done by the Silicon Terraform "Base Setup Scripts"
Tag Default Security Group
  I don't create the Default Security Group, this is done by the Silicon Terraform "Base Setup Scripts"
Add Descriptions to Security Group Rules
  Done
Enable Always on EBS encryption
  This is not possible with CloudFormation, can it be done by the Silicon Terraform "Base Setup Scripts"
Tag EBS Snapshots
  Done
Guardduty is enabled in Ireland, and not Cape Town region
  Guardduty is not added by scripts, is inherited from Management Account
Enable KMS Key rotation for the following Keys ec2, cloudtrails3 and ec2-instance
  Done
Enable all RDS Event Subscriptions
  Done
Create Custom RDS Option Group
  Done
Create Custom RDS Parameter Group
  Done
SNS Topic technical-notifications does not have any subscriptions
  This is expected as no-one wants to get the messages.
Enable versioning on S3 bucket serverless-framework-tcf-test-af-south-1
  (The serverless deployment buckets does not require versioning as it is versioned within the serverless framework. Also, this bucket is replaced when deployments are done. I do not think that this is a critical issue in the environment and can be ignored. Peter, check if this can be done in script)
Enable Block public access on S3 bucket serverless-framework-tcf-test-af-south-1
  (Same as above. I am sure that this was enabled in the script. Also, you already have block access enabled on the account)
Enable encryption on S3 Bucket tcf-test-config-bucket
  (Same as above. I am sure that this was enabled in the script)
Enable LifeCycle policy on S3 Bucket tcf-test-config-bucket
  (Lifecycle policy is not required on the serverless deployment bucket)
Enable LifeCycle policy on S3 tcf-test-ctl-cloudtrails3bucket-1vviktslis8yh
  Deleted old test bucket
Enable LifeCycle policy on S3 tcf-test-ctl-cloudtrails3bucket-da8ega3ij71x
  Deleted old test bucket
Enable LifeCycle policy on S3 tcf-test-ctl-cloudtrails3bucket-v2vf3dyig7lt
  Deleted old test bucket
Alter AWS Backup Plan to run at 2:00 AM and not 2:00 PM
  Changed Cron to (0 2 * * ? *)
Cloudwatch alarms don't need an Insufficient data Alarm trigger if set to "Treat missing data as bad"
  Removed Insufficient data Alarm trigger
