TrustCloud launches Application Assurance: AI-native continuous control monitoring for enterprises. Read more →

AWS

Estimated reading: 6 minutes 6852 views

Set up AWS for automated tests with TrustCloud

TrustCloud’s API-based integrations map seamlessly to your frameworks and controls to power automated evidence collection, continuous monitoring, and predictive risk analysis. Let’s explore how you can set up AWS for automated tests.

By granting TrustCloud limited access to metadata through a service principal account, you can ensure that your systems remain compliant with your adopted controls. TrustCloud’s focus on trust, security, and simplifying compliance makes it a valuable asset in the GRC landscape.

Read our GRC Launchpad article: Integrations to learn more.

Explore 100+ evidence collection integrations to power evidence collection and real-time risk analysis.

Purpose

Once you set up your compliance TrustCloud program, TrustOps works to ensure that your systems remain compliant with your adopted controls. To do so, TrustCloud runs automated tests against systems in your product and business stack and verifies that they are properly configured.

This document outlines the steps you can take to grant TrustCloud access to only read metadata about the configuration settings for your AWS account so that TrustCloud can validate and generate evidence for your compliance program.

Instructions to grant TrustCloud limited access to AWS

  1. Access can be granted through CloudFormation using the link found in your TrustOps account to create an AWS connection:
    The link includes a URL for a CloudFormation template as well as TrustCloud’s account ID so only TrustCloud can assume this role. If you inspect the CloudFormation template, it only adds two policies: SecurityAudit and ViewOnlyAccess. Both those policies are AWS-managed and are designed specifically for the purpose of helping security audits. These policies do not grant any data-related permissions. TrustCloud can only inspect your metadata and configurations.
  2. Under the ‘Capabilities’ section, check the box that says “I acknowledge that AWS CloudFormation might create IAM resources with custom names”, then click on the “Create Stack” button.
  3. Once stack creation is complete, click on the ‘Outputs’ tab. The two key/value pairs will be used to set up the connection in TrustOps. These contain your account ID, allowing TrustOps to assume the role.
    The following screenshot shows the TrustCloud integration with AWS.
    AWS

Adding multiple accounts

Users can now add multiple accounts to connect with AWS, streamlining the management of multiple environments. This new feature allows organizations to easily monitor and control their resources from a single interface, enhancing efficiency and simplifying the integration management process.

To add account,

  1. Go to your TrustCloud program.
  2. Click on the “Integrations” from left-hand side menu.
  3. Click on “My Integrations”.
  4. Search for “AWS” in search bar and click on the AWS card.
    AWS
  5. Click on the “Add Account” button from the left-hand side menu.
    AWS
  6. Enter all the information as per the setup guide.
  7. Click on the “Test Connection” button to verify if the connection is established.
  8. Once the connection is successful, click on the “Connect to AWS” button.

Additional Information

The following links to documentation help explain how the access mechanism works and the purpose of the external ID value.

  1. Providing access to AWS accounts owned by third parties
  2. How to use an external ID when granting access to your AWS resources to a third party

Read more about Integrations which are built-in connectors between TrustCloud and an external SaaS service that run tests and pull inventories from the service.

TrustCloud enabled collection of data feeds from multiple AWS services. Below is a sample of services and the data feeds we collect.

S3

Data feeds

Types of control testing that TrustCloud enables with S3:

  1. Audit Logging
  2. Least-Privilege Access
  3. File Store Encryption
  4. Data in Transit Encryption

To automate the continuous monitoring of these controls, TrustCloud pulls the following types of data feeds from S3

  1. Access Permissions
  2. Role Access Permissions

The following section describes the sample endpoints that TrustCloud uses, and the corresponding data that is pulled into the hybrid data fabric.

Read: Access Permissions
   - UserID
   - UserName
   - Roles
   - Permissions
   - Email
   - 2FA enabled
   - SSO Mode

Read: Role Access Permissions
   - RoleName
   - Permissions

IAM

Data feeds

Types of control testing that TrustCloud enables with IAM:

  1. Multi-Factor Authentication
  2. Least-Privilege Access
  3. Role-Based Access
  4. Password Configuration

To automate the continuous monitoring of these controls, TrustCloud pulls the following types of data feeds from IAM

  1. Access Permissions
  2. Role Access Permissions

The following section describes the sample endpoints that TrustCloud uses, and the corresponding data that is pulled into the Hybrid Data Fabric.

Read: Access Permissions
   - UserID
   - UserName
   - Roles
   - Permissions
   - Email
   - 2FA enabled
   - SSO Mode

Read: Role Access Permissions
   - RoleName
   - Permissions

Application Load Balancer

Data feeds

Types of control testing that TrustCloud enables with ELB:

  1. Audit Logging
  2. Data in Transit Encryption
  3. TLS Endpoints and Certifications

To automate the continuous monitoring of these controls, TrustCloud pulls the following types of data feeds from ALB.

  1. Access Permissions
  2. Load Balancers

The following section describes the sample endpoints that TrustCloud uses, and the corresponding data that is pulled into the Hybrid Data Fabric.

Read: Access Permissions
   - UserID
   - UserName
   - Roles
   - Permissions
   - Email
   - 2FA enabled
   - SSO Mode

Read: Load Balancers
   - ID
   - Name
   - DNSName
   - Scheme
   - State
   - Type

RDS

Data feeds

Types of control testing that TrustCloud enables with RDS:

  1. Backup Plan
  2. Backup Storage
  3. Backup Retention
  4. Backup System Monitoring
  5. Data Store Encryption

To automate the continuous monitoring of these controls, TrustCloud pulls the following types of data feeds from RDS –

  1. Access Permissions
  2. Data Stores
  3. Role Access Permissions

The following section describes the sample endpoints that TrustCloud uses, and the corresponding data that is pulled into the Hybrid Data Fabric:

Read: Access Permissions
   - UserID
   - UserName
   - Roles
   - Permissions
   - Email
   - 2FA enabled
   - SSO Mode

Read: Data Stores
   - ID
   - Name
   - Database Type
   - BackupRetention Period
   - Public
   - Encrypted
   - AutoMinorVersion Upgrade
   - PrefferedMaintainenceWindow

Read: Role Access Permissions
   - RoleName
   - Permissions

DynamoDB

Data feeds

Types of control testing that TrustCloud enables with DynamoDB:

  1. Backup Plan
  2. Backup Storage
  3. Backup Retention
  4. Backup System Monitoring
  5. Data Store Encryption

To automate the continuous monitoring of these controls, TrustCloud pulls the following types of data feeds from DynamoDB

  1. Access Permissions

The following section describes sample endpoints that TrustCloud uses, and the corresponding data that is pulled into the Hybrid Data Fabric.

Read: Role Access Permissions
   - RoleName
   - Permissions

EC2

Data feeds

Types of control testing that TrustCloud enables with EC2:

  1. Firewalls
  2. Backup Storage

To automate the continuous monitoring of these controls, TrustCloud pulls the following types of data feeds from EC2

  1. Access Permissions
  2. Data Stores
  3. Role Access Permissions

The following section describes sample endpoints that TrustCloud uses, and the corresponding data that is pulled into the Hybrid Data Fabric.

Read: Role Access Permissions
   - RoleName
   - Permissions

Read: Role Access Permissions
   - RoleName
   - Permissions

AWS WAF

Data feeds

Types of control testing that TrustCloud enables with AWS WAF:

  1. Firewalls

To automate the continuous monitoring of these controls, TrustCloud pulls the following types of data feeds from AWS WAF

  1. Role Access Permissions
Read: Role Access Permissions
   - RoleName
   - Permissions

Join the conversation

You might also be interested in

Duo

This document outlines the steps you can take to grant TrustCloud access to only...

Google Cloud Platform

This document outlines the steps you can take to grant TrustCloud access to only...

Bitbucket

Instructions to grant TrustCloud read-only access to your Bitbucket organization...

Hybrid Data Fabric

The Hybrid Data Fabric is a built-in connector between your TrustCloud and an external...

Okta

Set up Okta for automated tests with TrustCloud! This document outlines the steps you...

ServiceNow

Set up ServiceNow for Ticket as Evidence with TrustCloud! This document outlines the steps...

Tenable.io

This document outlines the steps you can take to grant TrustCloud access to only...

Jira Cloud

Set up Jira Cloud for Jira Ticket as Evidence with TrustCloud! This document outlines...
OR

TrustCommunity

Instant support with our AI chatbot

Please login with your TrustCloud credentials to continue