Security: iahcmd/aws-infra-platform
Security
Version
Supported
1.x
✅
< 1.0
❌
Reporting a Vulnerability
Do NOT open a public issue for security vulnerabilities.
Email findings to security@iahcmd.dev with subject: [SECURITY] aws-infra-platform - <description>.
Include: description, steps to reproduce, potential impact, and suggested fix.
Action
Timeframe
Acknowledgment
Within 48 hours
Initial assessment
Within 5 business days
Fix (critical)
Within 30 days
Fix (non-critical)
Within 90 days
Encryption at rest : KMS encryption for RDS, S3, EBS, ElastiCache, CloudWatch Logs
Encryption in transit : TLS 1.2+ enforced, HTTPS-only endpoints
Network isolation : Private subnets for workloads, NACLs, security groups
VPC Flow Logs : Network traffic auditing enabled
GuardDuty : Automated threat detection
CloudTrail : API activity logging for all regions
IAM least privilege : Scoped roles and policies for every service
No long-lived credentials : OIDC federation for CI/CD
MFA enforcement : Required for console access
SCPs : Service Control Policies for organizational guardrails
tfsec : Static analysis on all Terraform changes
checkov : Compliance framework scanning
OPA policies : Custom cost and security policies
Drift detection : Automated infrastructure drift alerts
Plan review : Manual approval required for production
CIS AWS Foundations Benchmark v1.5
AWS Well-Architected Framework (Security Pillar)
SOC 2 Type II controls (infrastructure layer)
There aren't any published security advisories
You can’t perform that action at this time.