
Amazon Web Services (AWS)
AccessVulnerabilities
Cloud Provider
Mycroft tests your AWS accounts daily for the IAM, encryption, logging, network and backup settings auditors ask about.
AWS configuration changes constantly, so a console screenshot is out of date almost immediately. Mycroft reads the same APIs an auditor would ask you to capture, records a pass or fail with the raw response attached, and tracks GuardDuty and Security Hub findings to closure.
How Mycroft connects to AWS
- How it connects
- You create an IAM role in your account and give Mycroft its ARN, which Mycroft then assumes through OIDC. Static access keys are supported as an alternative.
- What Mycroft can access
- Read-only across the account, covering IAM, S3, EC2, ECS, EKS and related configuration, plus the IAM user listing behind access reviews. Mycroft runs a pull model and does not write back.
Which controls AWS evidence maps to
Each row is a control an auditor tests and the specific artifact Mycroft collects from AWS to satisfy it. Collection runs on a schedule and every result is timestamped.
| Framework | Control | What it requires | Evidence collected from AWS |
|---|---|---|---|
| SOC 2 | CC6.1 | Logical access controls restrict access to information assets. | IAM user, role, group and attached-policy inventory; MFA status on the root account and every IAM user; access key age against your rotation policy. |
| SOC 2 | CC6.3 | Access is granted on least privilege and removed when no longer needed. | Per-principal permission inventory with wildcard and administrator policy detection, reconciled against your identity provider and HR roster in the user access review. |
| SOC 2 | CC6.6 | Logical access measures protect against threats from outside the system boundary. | Security group and network ACL rules flagged for unrestricted (0.0.0.0/0) ingress on sensitive ports; S3 public access block status per bucket and account. |
| SOC 2 | CC7.1 | Configuration changes and vulnerabilities are detected through monitoring. | CloudTrail enabled, multi-region and log-file-validated; GuardDuty and Security Hub enabled with findings ingested, deduplicated and aged. |
| SOC 2 | A1.2 | Backup and recovery processes support availability commitments. | RDS automated backup retention, snapshot schedules and multi-AZ configuration compared against the recovery objectives in your policies. |
| ISO 27001 | A.8.2 | Privileged access rights are restricted and controlled. | Inventory of principals holding AdministratorAccess or equivalent, with MFA state and last-used timestamps for each. |
| ISO 27001 | A.8.8 | Technical vulnerabilities are identified and remediated. | GuardDuty and Security Hub findings with severity, first-seen date, owner and time-to-remediate against your SLA. |
| ISO 27001 | A.8.15 | Logs of activities are produced, stored and protected. | CloudTrail trail configuration, log file validation status, and the retention period on the destination log bucket. |
| HIPAA | §164.312(a)(2)(iv) | Encryption of electronic protected health information at rest. | Encryption state for S3 buckets, EBS volumes, RDS instances and snapshots, with KMS key rotation status for each key in use. |
| HIPAA | §164.312(b) | Audit controls record and examine activity in systems holding ePHI. | Proof that CloudTrail is capturing management and data events across all regions, with retention meeting the six-year documentation requirement. |
What Mycroft collects automatically
Gathered from AWS on a schedule, dated and stored against the controls above.
- IAM credential report: every user, their MFA status, key age and last activity
- Encryption at rest across S3, EBS, RDS and their snapshots, with the KMS keys and rotation state behind them
- CloudTrail configuration: enabled, multi-region, validated, and retained for the required period
- Public exposure surface: S3 public access blocks, security group ingress rules, publicly accessible RDS instances
- GuardDuty and Security Hub findings, deduplicated and aged with owner and status
- RDS and EBS backup retention, snapshot cadence and multi-AZ configuration
- Account password policy and root account usage
Manual work this removes
The tasks that disappear from someone's quarter once AWS is connected.
- Screenshotting the IAM console each quarter for the access review
- Downloading credential reports and diffing them by hand to find stale access keys
- Confirming bucket public-access and volume encryption settings with engineers individually
- Checking each region separately for coverage gaps
- Exporting GuardDuty findings to show they were triaged
AWS and Mycroft: frequently asked questions
Can I automate SOC 2 evidence collection from AWS?
What AWS permissions does Mycroft need?
Does Mycroft work with AWS Organizations and multiple accounts?
How often are AWS controls re-tested?
Does this replace GuardDuty or Security Hub?
We turn the compliance nightmare into a dream
Talk to us


