Amazon Bedrock configuration hardening security checks
Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.
On Amazon Bedrock, Black Cat runs 4 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Amazon Bedrock connector needs.
Checks (4)
severity: medium Bedrock Guardrail Weak Content Filters fix difficulty: easy #
Strengthen the guardrail's content filter strength and prompt-attack coverage
- Open AWS Bedrock Console > Guardrails
- Edit the guardrail's content filters
- Set input filter strength to MEDIUM or HIGH and enable a PROMPT_ATTACK filter
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: high Bedrock No Guardrails Configured fix difficulty: medium #
Create at least one Bedrock Guardrail for this account/region
- Open AWS Bedrock Console > Guardrails
- Create a guardrail with content filters, denied topics, and PII redaction
- Attach it to models, agents, and flows as appropriate
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Bedrock Flow References Draft Prompt fix difficulty: easy #
Publish a versioned prompt and update the flow to reference it
- Open AWS Bedrock Console > Prompt management
- Create a version of the draft prompt used by the flow
- Update the flow's prompt node to reference the published version
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Bedrock Orphaned Knowledge Base fix difficulty: easy #
Attach the knowledge base to an agent or delete it if unused
- Open AWS Bedrock Console > Knowledge bases
- Confirm whether the knowledge base is still needed
- Attach it to an agent, or delete it to reduce unmanaged data exposure
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10