CCC-Complete (Policy) 0.1
Test results for this specific product, vendor, and version combination
| Vendor | FINOS |
| Product | CCC-Complete (Policy) |
| Version | 0.1 |
Download Raw Results
Download the original OCSF or HTML result files used to generate this page
| File Name | Download |
|---|---|
| aws-vpc-cfi-1775706869-vpc-cn03-allowed-requester-01 | |
| aws-vpc-cfi-1775706869-vpc-cn03-allowed-requester-02 | |
| aws-vpc-cfi-1775706869-vpc-cn03-disallowed-requester-01 | |
| aws-vpc-cfi-1775706869-vpc-cn03-disallowed-requester-02 | |
| aws-vpc-cfi-1775706869-vpc-cn03-non-allowlisted-requester-01 | |
| aws-vpc-cfi-1775706869-vpc | |
| aws-vpc-combined | |
| aws-vpc-prowler | |
| aws-vpc-summary |
Test Summary
Aggregate summary of all tests for this configuration result
| Resources In Configuration | 6 |
| Count of Tests | 36 |
| Passing Tests | 16 |
| Failing Tests | 20 |
| Catalogs Tested |
Control Catalog Summary
Summary of test results grouped by control catalog and resource
| Control Catalog | Resources | Total Tests | Passing | Failing | Tested Requirements | Missing Requirements | Unused Core Requirements |
|---|---|---|---|---|---|---|---|
| CCC.VPC | vpc-01f543721b8193a2...vpc-02ff4e20289c915b...vpc-071bf2e1e2416f26...vpc-0a6158c0cf30fae3...vpc-0bbce9271c5d2398...vpc-0d617b955f0a4466... | 36 | 16 | 20 | None |
Test Mapping Summary
Summary of test mappings showing how event codes map to test requirements
| Control Catalog | Test Requirement | Mapped Tests (Event Code | Total | Passing | Failing) |
|---|---|---|
| CCC.VPC | CCC.VPC.CN01.AR01 When a subscription is created, the subscription MUST NOT
contain default network resources.
| Main check: no default VPC exists12120 |
| CCC.VPC | CCC.VPC.CN02.AR01 When a resource is created in a public subnet, that resource
MUST NOT be assigned an external IP address by default.
| Main check (config): public subnets do not auto-assign external IPs12210 |
| CCC.VPC | CCC.VPC.CN04.AR01 When any network traffic goes to or from an interface in the VPC,
the service MUST capture and log all relevant information.
| Main check (config): flow logs are active and capture all traffic12210 |
Resource Summary
Summary of all resources mentioned in OCSF results
Test Results
OCSF test results filtered for entries with CCC compliance mappings
| Status | Finding | Resource Name | Resource Type | Message | Test Requirements |
|---|---|---|---|---|---|
| PASS | Main check: no default VPC exists ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I call "{vpcService}" with "CountDefaultVpcs"
✓ "{result}" is "0" | vpc-0bbce9271c5d23986 | vpc | Main check: no default VPC exists | |
| FAIL | Main check (config): public subnets do not auto-assign external IPs ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I refer to "{UID}" as "TargetVpcId"
✓ I call "{vpcService}" with "EvaluatePublicSubnetDefaultIPControl" using argument "{TargetVpcId}"
✓ "{result.ViolatingSubnetCount}" is "0"
✗ "{result.Reason}" contains "disable default public IP" - Error: expected {result.Reason} to contain 'disable default public IP', but got 'no public subnets found for in-scope VPC' | vpc-0bbce9271c5d23986 | vpc | Main check (config): public subnets do not auto-assign external IPs | |
| FAIL | Main check (config): flow logs are active and capture all traffic ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I refer to "{UID}" as "TargetVpcId"
✓ I call "{vpcService}" with "EvaluateVpcFlowLogsControl" using argument "{TargetVpcId}"
✗ "{result.FlowLogCount}" should be greater than "0" - Error: expected {result.FlowLogCount} (0) to be greater than 0
⊘ "{result.NonCompliantCount}" is "0" (skipped) | vpc-0bbce9271c5d23986 | vpc | Main check (config): flow logs are active and capture all traffic | |
| PASS | Main check: no default VPC exists ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I call "{vpcService}" with "CountDefaultVpcs"
✓ "{result}" is "0" | vpc-01f543721b8193a2c | vpc | Main check: no default VPC exists | |
| FAIL | Main check (config): public subnets do not auto-assign external IPs ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I refer to "{UID}" as "TargetVpcId"
✓ I call "{vpcService}" with "EvaluatePublicSubnetDefaultIPControl" using argument "{TargetVpcId}"
✓ "{result.ViolatingSubnetCount}" is "0"
✗ "{result.Reason}" contains "disable default public IP" - Error: expected {result.Reason} to contain 'disable default public IP', but got 'no public subnets found for in-scope VPC' | vpc-01f543721b8193a2c | vpc | Main check (config): public subnets do not auto-assign external IPs | |
| FAIL | Main check (config): flow logs are active and capture all traffic ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I refer to "{UID}" as "TargetVpcId"
✓ I call "{vpcService}" with "EvaluateVpcFlowLogsControl" using argument "{TargetVpcId}"
✗ "{result.FlowLogCount}" should be greater than "0" - Error: expected {result.FlowLogCount} (0) to be greater than 0
⊘ "{result.NonCompliantCount}" is "0" (skipped) | vpc-01f543721b8193a2c | vpc | Main check (config): flow logs are active and capture all traffic | |
| PASS | Main check: no default VPC exists ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I call "{vpcService}" with "CountDefaultVpcs"
✓ "{result}" is "0" | vpc-02ff4e20289c915b9 | vpc | Main check: no default VPC exists | |
| FAIL | Main check (config): public subnets do not auto-assign external IPs ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I refer to "{UID}" as "TargetVpcId"
✓ I call "{vpcService}" with "EvaluatePublicSubnetDefaultIPControl" using argument "{TargetVpcId}"
✓ "{result.ViolatingSubnetCount}" is "0"
✗ "{result.Reason}" contains "disable default public IP" - Error: expected {result.Reason} to contain 'disable default public IP', but got 'no public subnets found for in-scope VPC' | vpc-02ff4e20289c915b9 | vpc | Main check (config): public subnets do not auto-assign external IPs | |
| FAIL | Main check (config): flow logs are active and capture all traffic ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I refer to "{UID}" as "TargetVpcId"
✓ I call "{vpcService}" with "EvaluateVpcFlowLogsControl" using argument "{TargetVpcId}"
✗ "{result.FlowLogCount}" should be greater than "0" - Error: expected {result.FlowLogCount} (0) to be greater than 0
⊘ "{result.NonCompliantCount}" is "0" (skipped) | vpc-02ff4e20289c915b9 | vpc | Main check (config): flow logs are active and capture all traffic | |
| PASS | Main check: no default VPC exists ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I call "{vpcService}" with "CountDefaultVpcs"
✓ "{result}" is "0" | vpc-0d617b955f0a44661 | vpc | Main check: no default VPC exists | |
| FAIL | Main check (config): public subnets do not auto-assign external IPs ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I refer to "{UID}" as "TargetVpcId"
✓ I call "{vpcService}" with "EvaluatePublicSubnetDefaultIPControl" using argument "{TargetVpcId}"
✓ "{result.ViolatingSubnetCount}" is "0"
✗ "{result.Reason}" contains "disable default public IP" - Error: expected {result.Reason} to contain 'disable default public IP', but got 'no public subnets found for in-scope VPC' | vpc-0d617b955f0a44661 | vpc | Main check (config): public subnets do not auto-assign external IPs | |
| FAIL | Main check (config): flow logs are active and capture all traffic ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I refer to "{UID}" as "TargetVpcId"
✓ I call "{vpcService}" with "EvaluateVpcFlowLogsControl" using argument "{TargetVpcId}"
✗ "{result.FlowLogCount}" should be greater than "0" - Error: expected {result.FlowLogCount} (0) to be greater than 0
⊘ "{result.NonCompliantCount}" is "0" (skipped) | vpc-0d617b955f0a44661 | vpc | Main check (config): flow logs are active and capture all traffic | |
| PASS | Main check: no default VPC exists ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I call "{vpcService}" with "CountDefaultVpcs"
✓ "{result}" is "0" | vpc-0a6158c0cf30fae39 | vpc | Main check: no default VPC exists | |
| FAIL | Main check (config): public subnets do not auto-assign external IPs ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I refer to "{UID}" as "TargetVpcId"
✓ I call "{vpcService}" with "EvaluatePublicSubnetDefaultIPControl" using argument "{TargetVpcId}"
✓ "{result.ViolatingSubnetCount}" is "0"
✗ "{result.Reason}" contains "disable default public IP" - Error: expected {result.Reason} to contain 'disable default public IP', but got 'no public subnets found for in-scope VPC' | vpc-0a6158c0cf30fae39 | vpc | Main check (config): public subnets do not auto-assign external IPs | |
| FAIL | Main check (config): flow logs are active and capture all traffic ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I refer to "{UID}" as "TargetVpcId"
✓ I call "{vpcService}" with "EvaluateVpcFlowLogsControl" using argument "{TargetVpcId}"
✗ "{result.FlowLogCount}" should be greater than "0" - Error: expected {result.FlowLogCount} (0) to be greater than 0
⊘ "{result.NonCompliantCount}" is "0" (skipped) | vpc-0a6158c0cf30fae39 | vpc | Main check (config): flow logs are active and capture all traffic | |
| PASS | Main check: no default VPC exists ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I call "{vpcService}" with "CountDefaultVpcs"
✓ "{result}" is "0" | vpc-071bf2e1e2416f266 | vpc | Main check: no default VPC exists | |
| PASS | Main check (config): public subnets do not auto-assign external IPs ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I refer to "{UID}" as "TargetVpcId"
✓ I call "{vpcService}" with "EvaluatePublicSubnetDefaultIPControl" using argument "{TargetVpcId}"
✓ "{result.ViolatingSubnetCount}" is "0"
✓ "{result.Reason}" contains "disable default public IP" | vpc-071bf2e1e2416f266 | vpc | Main check (config): public subnets do not auto-assign external IPs | |
| PASS | Main check (config): flow logs are active and capture all traffic ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I refer to "{UID}" as "TargetVpcId"
✓ I call "{vpcService}" with "EvaluateVpcFlowLogsControl" using argument "{TargetVpcId}"
✓ "{result.FlowLogCount}" should be greater than "0"
✓ "{result.NonCompliantCount}" is "0" | vpc-071bf2e1e2416f266 | vpc | Main check (config): flow logs are active and capture all traffic | |
| PASS | Main check: no default VPC exists ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I call "{vpcService}" with "CountDefaultVpcs"
✓ "{result}" is "0" | vpc-0bbce9271c5d23986 | vpc | Main check: no default VPC exists | |
| FAIL | Main check (config): public subnets do not auto-assign external IPs ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I refer to "{UID}" as "TargetVpcId"
✓ I call "{vpcService}" with "EvaluatePublicSubnetDefaultIPControl" using argument "{TargetVpcId}"
✓ "{result.ViolatingSubnetCount}" is "0"
✗ "{result.Reason}" contains "disable default public IP" - Error: expected {result.Reason} to contain 'disable default public IP', but got 'no public subnets found for in-scope VPC' | vpc-0bbce9271c5d23986 | vpc | Main check (config): public subnets do not auto-assign external IPs | |
| FAIL | Main check (config): flow logs are active and capture all traffic ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I refer to "{UID}" as "TargetVpcId"
✓ I call "{vpcService}" with "EvaluateVpcFlowLogsControl" using argument "{TargetVpcId}"
✗ "{result.FlowLogCount}" should be greater than "0" - Error: expected {result.FlowLogCount} (0) to be greater than 0
⊘ "{result.NonCompliantCount}" is "0" (skipped) | vpc-0bbce9271c5d23986 | vpc | Main check (config): flow logs are active and capture all traffic | |
| PASS | Main check: no default VPC exists ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I call "{vpcService}" with "CountDefaultVpcs"
✓ "{result}" is "0" | vpc-01f543721b8193a2c | vpc | Main check: no default VPC exists | |
| FAIL | Main check (config): public subnets do not auto-assign external IPs ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I refer to "{UID}" as "TargetVpcId"
✓ I call "{vpcService}" with "EvaluatePublicSubnetDefaultIPControl" using argument "{TargetVpcId}"
✓ "{result.ViolatingSubnetCount}" is "0"
✗ "{result.Reason}" contains "disable default public IP" - Error: expected {result.Reason} to contain 'disable default public IP', but got 'no public subnets found for in-scope VPC' | vpc-01f543721b8193a2c | vpc | Main check (config): public subnets do not auto-assign external IPs | |
| FAIL | Main check (config): flow logs are active and capture all traffic ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I refer to "{UID}" as "TargetVpcId"
✓ I call "{vpcService}" with "EvaluateVpcFlowLogsControl" using argument "{TargetVpcId}"
✗ "{result.FlowLogCount}" should be greater than "0" - Error: expected {result.FlowLogCount} (0) to be greater than 0
⊘ "{result.NonCompliantCount}" is "0" (skipped) | vpc-01f543721b8193a2c | vpc | Main check (config): flow logs are active and capture all traffic | |
| PASS | Main check: no default VPC exists ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I call "{vpcService}" with "CountDefaultVpcs"
✓ "{result}" is "0" | vpc-02ff4e20289c915b9 | vpc | Main check: no default VPC exists | |
| FAIL | Main check (config): public subnets do not auto-assign external IPs ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I refer to "{UID}" as "TargetVpcId"
✓ I call "{vpcService}" with "EvaluatePublicSubnetDefaultIPControl" using argument "{TargetVpcId}"
✓ "{result.ViolatingSubnetCount}" is "0"
✗ "{result.Reason}" contains "disable default public IP" - Error: expected {result.Reason} to contain 'disable default public IP', but got 'no public subnets found for in-scope VPC' | vpc-02ff4e20289c915b9 | vpc | Main check (config): public subnets do not auto-assign external IPs | |
| FAIL | Main check (config): flow logs are active and capture all traffic ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I refer to "{UID}" as "TargetVpcId"
✓ I call "{vpcService}" with "EvaluateVpcFlowLogsControl" using argument "{TargetVpcId}"
✗ "{result.FlowLogCount}" should be greater than "0" - Error: expected {result.FlowLogCount} (0) to be greater than 0
⊘ "{result.NonCompliantCount}" is "0" (skipped) | vpc-02ff4e20289c915b9 | vpc | Main check (config): flow logs are active and capture all traffic | |
| PASS | Main check: no default VPC exists ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I call "{vpcService}" with "CountDefaultVpcs"
✓ "{result}" is "0" | vpc-0d617b955f0a44661 | vpc | Main check: no default VPC exists | |
| FAIL | Main check (config): public subnets do not auto-assign external IPs ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I refer to "{UID}" as "TargetVpcId"
✓ I call "{vpcService}" with "EvaluatePublicSubnetDefaultIPControl" using argument "{TargetVpcId}"
✓ "{result.ViolatingSubnetCount}" is "0"
✗ "{result.Reason}" contains "disable default public IP" - Error: expected {result.Reason} to contain 'disable default public IP', but got 'no public subnets found for in-scope VPC' | vpc-0d617b955f0a44661 | vpc | Main check (config): public subnets do not auto-assign external IPs | |
| FAIL | Main check (config): flow logs are active and capture all traffic ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I refer to "{UID}" as "TargetVpcId"
✓ I call "{vpcService}" with "EvaluateVpcFlowLogsControl" using argument "{TargetVpcId}"
✗ "{result.FlowLogCount}" should be greater than "0" - Error: expected {result.FlowLogCount} (0) to be greater than 0
⊘ "{result.NonCompliantCount}" is "0" (skipped) | vpc-0d617b955f0a44661 | vpc | Main check (config): flow logs are active and capture all traffic | |
| PASS | Main check: no default VPC exists ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I call "{vpcService}" with "CountDefaultVpcs"
✓ "{result}" is "0" | vpc-0a6158c0cf30fae39 | vpc | Main check: no default VPC exists | |
| FAIL | Main check (config): public subnets do not auto-assign external IPs ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I refer to "{UID}" as "TargetVpcId"
✓ I call "{vpcService}" with "EvaluatePublicSubnetDefaultIPControl" using argument "{TargetVpcId}"
✓ "{result.ViolatingSubnetCount}" is "0"
✗ "{result.Reason}" contains "disable default public IP" - Error: expected {result.Reason} to contain 'disable default public IP', but got 'no public subnets found for in-scope VPC' | vpc-0a6158c0cf30fae39 | vpc | Main check (config): public subnets do not auto-assign external IPs | |
| FAIL | Main check (config): flow logs are active and capture all traffic ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I refer to "{UID}" as "TargetVpcId"
✓ I call "{vpcService}" with "EvaluateVpcFlowLogsControl" using argument "{TargetVpcId}"
✗ "{result.FlowLogCount}" should be greater than "0" - Error: expected {result.FlowLogCount} (0) to be greater than 0
⊘ "{result.NonCompliantCount}" is "0" (skipped) | vpc-0a6158c0cf30fae39 | vpc | Main check (config): flow logs are active and capture all traffic | |
| PASS | Main check: no default VPC exists ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I call "{vpcService}" with "CountDefaultVpcs"
✓ "{result}" is "0" | vpc-071bf2e1e2416f266 | vpc | Main check: no default VPC exists | |
| PASS | Main check (config): public subnets do not auto-assign external IPs ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I refer to "{UID}" as "TargetVpcId"
✓ I call "{vpcService}" with "EvaluatePublicSubnetDefaultIPControl" using argument "{TargetVpcId}"
✓ "{result.ViolatingSubnetCount}" is "0"
✓ "{result.Reason}" contains "disable default public IP" | vpc-071bf2e1e2416f266 | vpc | Main check (config): public subnets do not auto-assign external IPs | |
| PASS | Main check (config): flow logs are active and capture all traffic ✓ a cloud api for "{Instance}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "vpc"
✓ I refer to "{result}" as "vpcService"
✓ I refer to "{UID}" as "TargetVpcId"
✓ I call "{vpcService}" with "EvaluateVpcFlowLogsControl" using argument "{TargetVpcId}"
✓ "{result.FlowLogCount}" should be greater than "0"
✓ "{result.NonCompliantCount}" is "0" | vpc-071bf2e1e2416f266 | vpc | Main check (config): flow logs are active and capture all traffic |