Amazon Web Services (AWS) logo

Amazon Web Services (AWS)

AccessVulnerabilities
Cloud Provider

Mycroft tests your AWS accounts daily for the IAM, encryption, logging, network and backup settings auditors ask about.

AWS configuration changes constantly, so a console screenshot is out of date almost immediately. Mycroft reads the same APIs an auditor would ask you to capture, records a pass or fail with the raw response attached, and tracks GuardDuty and Security Hub findings to closure.

How Mycroft connects to AWS

How it connects
You create an IAM role in your account and give Mycroft its ARN, which Mycroft then assumes through OIDC. Static access keys are supported as an alternative.
What Mycroft can access
Read-only across the account, covering IAM, S3, EC2, ECS, EKS and related configuration, plus the IAM user listing behind access reviews. Mycroft runs a pull model and does not write back.

Which controls AWS evidence maps to

Each row is a control an auditor tests and the specific artifact Mycroft collects from AWS to satisfy it. Collection runs on a schedule and every result is timestamped.

Amazon Web Services (AWS) compliance control mappings and the evidence Mycroft collects for each
FrameworkControlWhat it requiresEvidence collected from AWS
SOC 2CC6.1Logical access controls restrict access to information assets.IAM user, role, group and attached-policy inventory; MFA status on the root account and every IAM user; access key age against your rotation policy.
SOC 2CC6.3Access is granted on least privilege and removed when no longer needed.Per-principal permission inventory with wildcard and administrator policy detection, reconciled against your identity provider and HR roster in the user access review.
SOC 2CC6.6Logical access measures protect against threats from outside the system boundary.Security group and network ACL rules flagged for unrestricted (0.0.0.0/0) ingress on sensitive ports; S3 public access block status per bucket and account.
SOC 2CC7.1Configuration changes and vulnerabilities are detected through monitoring.CloudTrail enabled, multi-region and log-file-validated; GuardDuty and Security Hub enabled with findings ingested, deduplicated and aged.
SOC 2A1.2Backup and recovery processes support availability commitments.RDS automated backup retention, snapshot schedules and multi-AZ configuration compared against the recovery objectives in your policies.
ISO 27001A.8.2Privileged access rights are restricted and controlled.Inventory of principals holding AdministratorAccess or equivalent, with MFA state and last-used timestamps for each.
ISO 27001A.8.8Technical vulnerabilities are identified and remediated.GuardDuty and Security Hub findings with severity, first-seen date, owner and time-to-remediate against your SLA.
ISO 27001A.8.15Logs of activities are produced, stored and protected.CloudTrail trail configuration, log file validation status, and the retention period on the destination log bucket.
HIPAA§164.312(a)(2)(iv)Encryption of electronic protected health information at rest.Encryption state for S3 buckets, EBS volumes, RDS instances and snapshots, with KMS key rotation status for each key in use.
HIPAA§164.312(b)Audit controls record and examine activity in systems holding ePHI.Proof that CloudTrail is capturing management and data events across all regions, with retention meeting the six-year documentation requirement.

What Mycroft collects automatically

Gathered from AWS on a schedule, dated and stored against the controls above.

  • IAM credential report: every user, their MFA status, key age and last activity
  • Encryption at rest across S3, EBS, RDS and their snapshots, with the KMS keys and rotation state behind them
  • CloudTrail configuration: enabled, multi-region, validated, and retained for the required period
  • Public exposure surface: S3 public access blocks, security group ingress rules, publicly accessible RDS instances
  • GuardDuty and Security Hub findings, deduplicated and aged with owner and status
  • RDS and EBS backup retention, snapshot cadence and multi-AZ configuration
  • Account password policy and root account usage

Manual work this removes

The tasks that disappear from someone's quarter once AWS is connected.

  • Screenshotting the IAM console each quarter for the access review
  • Downloading credential reports and diffing them by hand to find stale access keys
  • Confirming bucket public-access and volume encryption settings with engineers individually
  • Checking each region separately for coverage gaps
  • Exporting GuardDuty findings to show they were triaged

AWS and Mycroft: frequently asked questions

Yes. With AWS connected, the controls that depend on infrastructure configuration (CC6.1, CC6.3, CC6.6, CC7.1 and A1.2) are tested continuously and evidenced automatically. Each test result is stored with a timestamp and the underlying API response, which is what an auditor samples during fieldwork.
Mycroft assumes an IAM role in your account through OIDC, using a role ARN you create; static access keys are supported as an alternative. Access is read-only across the account, covering IAM, S3, EC2, ECS, EKS and related configuration, plus the IAM user listing behind access reviews. Mycroft runs a pull model and does not write back.
Yes. Multi-account estates are the normal case. The role is deployed per account (via CloudFormation StackSets or Terraform for large organizations) and evidence is attributed to the account it came from, so a finding in a sandbox account does not contaminate the production evidence in your report.
Daily by default, with on-demand re-runs after you remediate something. That cadence is what distinguishes continuous monitoring evidence from a point-in-time snapshot, and it is what SOC 2 CC7.1 and ISO 27001 A.8.16 are actually asking for.
No. Mycroft consumes them, ingesting their findings, removes duplicates across accounts and regions, attaches an owner and tracks each one to closure against your remediation SLA. The scanners keep detecting; Mycroft turns detection into the evidence that detection was acted on.

We turn the compliance nightmare into a dream

Talk to us