AWS Quick Checklist
A 21-point pass over IAM and security groups — the fastest way to find the highest-severity misconfigurations in any AWS account.
This is the master template. Per-account status for each of our AWS accounts is tracked in AWS Quick Checklist.xlsx, which stays the source of truth for who has resolved what. Tick items here to work through an account; progress is saved in this browser only.
For the wider cloud picture, see the Infrastructure checklist — 18 account-level practices with examples.
Progress summary
| Total items | Not resolved | Resolved | % complete |
|---|---|---|---|
| 21 | 21 | 0 | 0% |
Severity key
| Severity | Items | What it means here |
|---|---|---|
| Critical | 7 | Directly exploitable exposure — root access, a public database port, or a key an outsider could already hold. Fix before anything else. |
| High | 9 | A missing control that turns a single mistake or leaked credential into a full account compromise. |
| Medium | 5 | Hardening and hygiene — narrows the blast radius and removes standing access nobody needs. |
IAM
0 of 16 complete
| Severity | Item | |
|---|---|---|
| Critical | ||
| Critical | ||
| Critical | ||
| Critical | ||
| High | ||
| High | ||
| High | ||
| High | ||
| High | ||
| High | ||
| High | ||
| High | ||
| High | ||
| Medium | ||
| Medium | ||
| Medium |
Security Group
0 of 4 complete
| Severity | Item | |
|---|---|---|
| Critical | ||
| Critical | ||
| Critical | ||
| Medium |
General
0 of 1 complete
| Severity | Item | |
|---|---|---|
| Medium |
Last updated: September 2026 · Source: AWS Quick Checklist.xlsx (Template sheet)