

# Operational Best Practices for ACSC ISM - Part 2
<a name="operational-best-practices-for-acsc-ism-part-2"></a>

Conformance packs provide a general-purpose compliance framework designed to enable you to create security, operational or cost-optimization governance checks using managed or custom AWS Config rules and AWS Config remediation actions. Conformance Packs, as sample templates, are not designed to fully ensure compliance with a specific governance or compliance standard. You are responsible for making your own assessment of whether your use of the Services meets applicable legal and regulatory requirements.

The following provides additional sample mapping between the Australian Cyber Security Centre (ACSC) Information Security Manual (ISM) 2020-06 and AWS managed Config rules. Each Config rule applies to a specific AWS resource, and relates to one or more ISM controls. An ISM control can be related to multiple Config rules. Refer to the table below for more detail and guidance related to these mappings.

This sample conformance pack template contains mappings to controls within the ISM framework, which was created by the Commonwealth of Australia and can be found at [Australian Government Information Security Manual](https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-principles). Licensing of the framework under Creative Commons Attribution 4.0 International Public License and copyright information for the framework (including a disclaimer of warranties) can be found at [ACSC \| Copyright](https://www.cyber.gov.au/acsc/copyright).



| Control ID  | AWS Config Rule  | Guidance  | 
| --- | --- | --- | 
| 1984 | [appmesh-virtual-gateway-backend-defaults-tls](https://docs.aws.amazon.com/config/latest/developerguide/appmesh-virtual-gateway-backend-defaults-tls.html) | Checks if backend defaults for AWS App Mesh virtual gateways require the virtual gateways to communicate with all ports using TLS. The rule is NON\_COMPLIANT if configuration.Spec.BackendDefaults.ClientPolicy.Tls.Enforce is false. | 
| 1984 | [appmesh-virtual-node-backend-defaults-tls-on](https://docs.aws.amazon.com/config/latest/developerguide/appmesh-virtual-node-backend-defaults-tls-on.html) | Checks if backend defaults for AWS App Mesh virtual nodes require the virtual nodes to communicate with all ports using TLS. The rule is NON\_COMPLIANT if configuration.Spec.BackendDefaults.ClientPolicy.Tls.Enforce is false. | 
| 1984 | [msk-in-cluster-node-require-tls](https://docs.aws.amazon.com/config/latest/developerguide/msk-in-cluster-node-require-tls.html) | Checks if an Amazon MSK cluster enforces encryption in transit using HTTPS (TLS) with the broker nodes of the cluster. The rule is NON\_COMPLIANT if plain text communication is enabled for in-cluster broker node connections. | 
| 1984 | [rds-mysql-instance-encrypted-in-transit](https://docs.aws.amazon.com/config/latest/developerguide/rds-mysql-instance-encrypted-in-transit.html) | Checks if connections to Amazon RDS for MySQL database instances are configured to use encryption in transit. The rule is NON\_COMPLIANT if the associated database parameter group is not in-sync or if the require\_secure\_transport parameter is not set to 1.  | 
| 1984 | [rds-postgres-instance-encrypted-in-transit](https://docs.aws.amazon.com/config/latest/developerguide/rds-postgres-instance-encrypted-in-transit.html) | Checks if connections to Amazon RDS for PostgreSQL database instances are configured to use encryption in transit. The rule is NON\_COMPLIANT if the associated database parameter group is not in-sync or if the rds.force\_ssl parameter is not set to 1. | 
| 1985 | [ebs-snapshot-public-restorable-check](https://docs.aws.amazon.com/config/latest/developerguide/ebs-snapshot-public-restorable-check.html) | Checks if Amazon Elastic Block Store (Amazon EBS) snapshots are not publicly restorable. The rule is NON\_COMPLIANT if one or more snapshots with RestorableByUserIds field are set to all, that is, Amazon EBS snapshots are public. | 
| 1985 | [s3-bucket-mfa-delete-enabled](https://docs.aws.amazon.com/config/latest/developerguide/s3-bucket-mfa-delete-enabled.html) | Checks if Amazon Elastic Block Store (Amazon EBS) snapshots are not publicly restorable. The rule is NON\_COMPLIANT if one or more snapshots with RestorableByUserIds field are set to all, that is, Amazon EBS snapshots are public. | 
| 1985 | [s3-bucket-public-read-prohibited](https://docs.aws.amazon.com/config/latest/developerguide/s3-bucket-public-read-prohibited.html) | Checks if your Amazon S3 buckets do not allow public read access. The rule checks the Block Public Access settings, the bucket policy, and the bucket access control list (ACL).<br />The rule is compliant when both of the following are true:+  The Block Public Access setting restricts public policies or the bucket policy does not allow public read access. <br />+  The Block Public Access setting restricts public ACLs or the bucket ACL does not allow public read access. <br />The rule is non-compliant when:+  If the Block Public Access setting does not restrict public policies, AWS Config evaluates whether the policy allows public read access. If the policy allows public read access, the rule is non-compliant. <br />+  If the Block Public Access setting does not restrict public bucket ACLs, AWS Config evaluates whether the bucket ACL allows public read access. If the bucket ACL allows public read access, the rule is non-compliant.  | 
| 1985 | [s3-bucket-public-write-prohibited](https://docs.aws.amazon.com/config/latest/developerguide/s3-bucket-public-write-prohibited.html) | Checks if your Amazon S3 buckets do not allow public write access. The rule checks the Block Public Access settings, the bucket policy, and the bucket access control list (ACL).<br />The rule is compliant when both of the following are true:+  The Block Public Access setting restricts public policies or the bucket policy does not allow public write access. <br />+  The Block Public Access setting restricts public ACLs or the bucket ACL does not allow public write access. <br />The rule is non-compliant when:+  If the Block Public Access setting does not restrict public policies, AWS Config evaluates whether the policy allows public write access. If the policy allows public write access, the rule is non-compliant. <br />+  If the Block Public Access setting does not restrict public bucket ACLs, AWS Config evaluates whether the bucket ACL allows public write access. If the bucket ACL allows public write access, the rule is non-compliant.  | 
| 1985 | [aurora-resources-in-logically-air-gapped-vault](https://docs.aws.amazon.com/config/latest/developerguide/aurora-resources-in-logically-air-gapped-vault.html) | Checks if Amazon Aurora DB clusters are in a logically air-gapped vault. The rule is NON\_COMPLIANT if an Amazon Aurora DB cluster is not in a logically air-gapped vault within the specified time period. | 
| 1985 | [ebs-resources-in-logically-air-gapped-vault](https://docs.aws.amazon.com/config/latest/developerguide/ebs-resources-in-logically-air-gapped-vault.html) | Checks if Amazon Elastic Block Store (Amazon EBS) volumes are in a logically air-gapped vault. The rule is NON\_COMPLIANT if an Amazon EBS volume is not in a logically air-gapped vault within the specified time period. | 
| 1985 | [ec2-resources-in-logically-air-gapped-vault](https://docs.aws.amazon.com/config/latest/developerguide/ec2-resources-in-logically-air-gapped-vault.html) | Checks if Amazon Elastic Block Store (Amazon EBS) instances are in a logically air-gapped vault. The rule is NON\_COMPLIANT if an Amazon EBS instance is not in a logically air-gapped vault within the specified time period. | 
| 1985 | [efs-resources-in-logically-air-gapped-vault](https://docs.aws.amazon.com/config/latest/developerguide/efs-resources-in-logically-air-gapped-vault.html) | Checks if Amazon Elastic File System (Amazon EFS) File Systems are in a logically air-gapped vault. The rule is NON\_COMPLIANT if an Amazon EFS File System is not in a logically air-gapped vault within the specified time period. | 
| 1985 | [s3-resources-in-logically-air-gapped-vault](https://docs.aws.amazon.com/config/latest/developerguide/s3-resources-in-logically-air-gapped-vault.html) | Checks if Amazon Simple Storage Service (Amazon S3) buckets are in a logically air-gapped vault. The rule is NON\_COMPLIANT if an Amazon S3 bucket is not in a logically air-gapped vault within the specified time period. | 

## Template
<a name="acsc-ism-conformance-pack-sample"></a>

This templates is available on GitHub: [Operational Best Practices for ACSC ISM - Part 2](https://github.com/awslabs/aws-config-rules/blob/master/aws-config-conformance-packs/Operational-Best-Practices-for-ACSC-ISM-Part2.yaml).