Sept. 5, 2023, 8:40 p.m. | /u/Creepy-Trust-9581

cybersecurity www.reddit.com

I have been tasked to do a security assessment/auditing in a small AWS infrastructure where they have some 20 EC2 instances. The AWS has mostly their DevOps environment with Github, Jenkins, secret managers etc. I am planning to check the security assessment against the CIS rules.
https://www.cisecurity.org/benchmark/amazon_web_services

Anyone has suggestion that I should be following else than CIS? Again, it not a penetration testing but a security assessment.
Thanks for your suggestions.

assessment auditing aws check cis cybersecurity devops ec2 environment etc github infrastructure jenkins managers planning rules secret security security assessment

Security Specialist

@ Nestlé | St. Louis, MO, US, 63164

Cybersecurity Analyst

@ Dana Incorporated | Pune, MH, IN, 411057

Sr. Application Security Engineer

@ CyberCube | United States

Linux DevSecOps Administrator (Remote)

@ Accenture Federal Services | Arlington, VA

Cyber Security Intern or Co-op

@ Langan | Parsippany, NJ, US, 07054-2172

Security Advocate - Application Security

@ Datadog | New York, USA, Remote