RECOMMENDED

SCG-CSO-SDF: Secure Defaults

Providers SHOULD set all settings to their recommended secure defaults for top-level administrative accounts and privileged accounts when initially provisioned.

Secure Defaults on Provisioning

Footprint roles are designed with security in mind, providing multiple layers of security controls and encryption capabilities. However, Footprint allows customers to define the security configuration of services enabling customers the flexibility to meet their specific business requirements and compliance needs.

Best Practices:

  • Enable encryption at rest using customer-managed KMS keys
  • Use AWS Secrets Manager for master user password management
  • Enforce SSL/TLS connections for all database access
  • Enable comprehensive audit logging and monitoring
  • Deploy in private subnets with restrictive security groups
  • Implement automated backup encryption
  • Configure parameter groups with security-hardened settings