Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
terraform-aws-secure-baseline — Terraform 모듈로, CIS Amazon Web Services Foundations 및 AWS Foundational Security Best Practices를 기반으로 AWS 계정을 보안 기준 구성으로 설정합니다. | Kitploit
도구/GitHubGitHub/nozaq/terraform-aws-secure-baseline
Cloud Infrastructure SecurityConfiguration AuditingCloud SecurityDevSecOpsMisconfiguration
GitHubnozaq/terraform-aws-secure-baseline

terraform-aws-secure-baseline

Terraform 모듈로, CIS Amazon Web Services Foundations 및 AWS Foundational Security Best Practices를 기반으로 AWS 계정을 보안 기준 구성으로 설정합니다.

저장소 보기

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
1.2k3782017일 전Kitploit 검토 완료

terraform-aws-secure-baseline

Github Actions Releases

Terraform 모듈 레지스트리

AWS 계정을 적절한 보안 구성 기준으로 설정하기 위한 Terraform 모듈입니다. 대부분의 구성은 [CIS Amazon Web Services Foundations v1.4.0] 및 [AWS Foundational Security Best Practices v1.0.0]을 기반으로 합니다.

다양한 벤치마크에서 어떤 항목이 적용되는지 확인하려면 벤치마크 준수를 참조하세요.

기능

ID 및 액세스 관리

  • IAM 암호 정책 설정
  • 사고 처리를 위한 AWS 지원 연락용 IAM 역할 생성
  • 루트 계정 상태 감사를 위한 AWS Config 규칙 활성화
  • 각 리전에서 IAM Access Analyzer 활성화
  • S3 계정 수준 공용 액세스 차단 구성 활성화

로깅 및 모니터링

  • 모든 리전에서 CloudTrail을 활성화하고 CloudWatch Logs로 이벤트 전달
  • 모든 S3 버킷에 대해 객체 수준 로깅이 기본적으로 활성화됨
  • CloudTrail Insights 이벤트 로깅이 기본적으로 활성화됨
  • CloudTrail 로그는 AWS Key Management Service를 사용하여 암호화됨
  • 모든 로그는 액세스 로깅이 활성화된 S3 버킷에 저장됨
  • 로그는 지정된 기간(기본값 90일) 후에 Amazon Glacier로 자동 보관됨
  • AWS 계정에서 중요한 변경 사항이 발생할 때 알림을 보내는 CloudWatch 알람 설정
  • 각 리전에서 AWS Config를 활성화하여 구성 스냅샷 자동 생성
  • SecurityHub를 활성화하고 사용 가능한 기준을 구독
  • 각 리전에서 GuardDuty 활성화

네트워킹 및 컴퓨팅

  • 모든 리전의 기본 VPC에서 기본 라우팅 테이블, 기본 네트워크 ACL, 기본 보안 그룹과 관련된 모든 규칙 제거
  • 기본 서브넷에서 자동 공용 IP 할당 비활성화
  • 보안 그룹 규칙에서 제한되지 않은 일반 포트를 감사하는 AWS Config 규칙 활성화
  • 모든 리전의 기본 VPC에서 VPC 흐름 로그 활성화
  • 새로 생성되는 볼륨에 대해 기본 EBS 암호화 활성화

Usage```hcl

data "aws_caller_identity" "current" {} data "aws_region" "current" {}

module "secure_baseline" { source = "nozaq/secure-baseline/aws"

audit_log_bucket_name = "YOUR_BUCKET_NAME" aws_account_id = data.aws_caller_identity.current.account_id region = data.aws_region.current.name support_iam_role_principal_arns = ["YOUR_IAM_USER"]

providers = { aws = aws aws.ap-northeast-1 = aws.ap-northeast-1 aws.ap-northeast-2 = aws.ap-northeast-2 aws.ap-northeast-3 = aws.ap-northeast-3 aws.ap-south-1 = aws.ap-south-1 aws.ap-southeast-1 = aws.ap-southeast-1 aws.ap-southeast-2 = aws.ap-southeast-2 aws.ca-central-1 = aws.ca-central-1 aws.eu-central-1 = aws.eu-central-1 aws.eu-north-1 = aws.eu-north-1 aws.eu-west-1 = aws.eu-west-1 aws.eu-west-2 = aws.eu-west-2 aws.eu-west-3 = aws.eu-west-3 aws.sa-east-1 = aws.sa-east-1 aws.us-east-1 = aws.us-east-1 aws.us-east-2 = aws.us-east-2 aws.us-west-1 = aws.us-west-1 aws.us-west-2 = aws.us-west-2 } }

Check [the example](https://github.com/nozaq/terraform-aws-secure-baseline/blob/main/examples/simple/regions.tf) to understand how these providers are defined.
Note that you need to define a provider for each AWS region and pass them to the module. Currently this is the recommended way to handle multiple regions in one module.
Detailed information can be found at [Providers within Modules - Terraform Docs].

A new S3 bucket to store audit logs is automatically created by default, while the external S3 bucket can be specified. It is useful when you already have a centralized S3 bucket to store all logs. Please see [external-bucket](https://github.com/nozaq/terraform-aws-secure-baseline/blob/main/examples/external-bucket) example for more detail.

### Managing multiple accounts in AWS Organization

When you have multiple AWS accounts in your AWS Organization, `secure-baseline` module configures the separated environment for each AWS account. You can change this behavior to centrally manage security information and audit logs from all accounts in one master account.
Check [organization](https://github.com/nozaq/terraform-aws-secure-baseline/blob/main/examples/organization) example for more detail.

## Submodules

This module is composed of several submodules and each of which can be used independently.
[Modules in Package Sub-directories - Terraform] describes how to source a submodule.

- [alarm-baseline](https://github.com/nozaq/terraform-aws-secure-baseline/blob/main/modules/alarm-baseline)
- [analyzer-baseline](https://github.com/nozaq/terraform-aws-secure-baseline/blob/main/modules/analyzer-baseline)
- [cloudtrail-baseline](https://github.com/nozaq/terraform-aws-secure-baseline/blob/main/modules/cloudtrail-baseline)
- [config-baseline](https://github.com/nozaq/terraform-aws-secure-baseline/blob/main/modules/config-baseline)
- [ebs-baseline](https://github.com/nozaq/terraform-aws-secure-baseline/blob/main/modules/ebs-baseline)
- [guardduty-baseline](https://github.com/nozaq/terraform-aws-secure-baseline/blob/main/modules/guardduty-baseline)
- [iam-baseline](https://github.com/nozaq/terraform-aws-secure-baseline/blob/main/modules/iam-baseline)
- [s3-baseline](https://github.com/nozaq/terraform-aws-secure-baseline/blob/main/modules/s3-baseline)
- [secure-bucket](https://github.com/nozaq/terraform-aws-secure-baseline/blob/main/modules/secure-bucket)
- [securityhub-baseline](https://github.com/nozaq/terraform-aws-secure-baseline/blob/main/modules/securityhub-baseline)
- [vpc-baseline](https://github.com/nozaq/terraform-aws-secure-baseline/blob/main/modules/vpc-baseline)

## Compatibility

- Starting from v1.0, this module requires [Terraform Provider for AWS](https://github.com/terraform-providers/terraform-provider-aws) v4.0 or later. [Version 1.0 Upgrade Guide](https://github.com/nozaq/terraform-aws-secure-baseline/blob/main/docs/upgrade-1.0.md) described the recommended procedure after the upgrade.
- Starting from v0.20, this module requires [Terraform Provider for AWS](https://github.com/terraform-providers/terraform-provider-aws) v3.0 or later. Please use v0.19 if you need to use v2.x or earlier.
- Starting from v0.10, this module requires Terraform v0.12 or later. Please use v0.9 if you need to use Terraform v0.11 or ealier.

<!-- BEGINNING OF PRE-COMMIT-TERRAFORM DOCS HOOK -->
## Requirements

| Name | Version |
|------|---------|
| <a name="requirement_terraform"></a> [terraform](#requirement\_terraform) | >= 1.1.4 |
| <a name="requirement_aws"></a> [aws](#requirement\_aws) | >= 4.3 |

## Providers

| Name | Version |
|------|---------|
| <a name="provider_aws"></a> [aws](#provider\_aws) | >= 4.3 |
도구 다운로드