Amazon Bedrock data sharing & exposure security checks
External sharing, public links, guest access, retention and data-protection settings that quietly push company data outside the tenant.
On Amazon Bedrock, Black Cat runs 4 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Amazon Bedrock connector needs.
Checks (4)
severity: medium Bedrock Agent Multiple Knowledge Bases fix difficulty: medium #
Review data exposure from multiple knowledge bases
- Open AWS Bedrock Console > Agents
- Review each knowledge base and its data source
- Remove unnecessary knowledge base associations
Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12
severity: medium Bedrock Agent No Customer-Managed Encryption fix difficulty: medium #
Configure a customer-managed KMS key for the agent
- Open AWS KMS Console and create or select a key
- Open AWS Bedrock Console > Agents
- Update the agent to use the customer-managed key
Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12
severity: low Bedrock Agent Session Memory Enabled fix difficulty: easy #
Review if session memory is appropriate for this agent's data sensitivity
- Assess what data the agent processes
- If handling sensitive data, disable session memory
Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12
severity: medium Bedrock Agent Long Session TTL fix difficulty: easy #
Reduce idle session TTL to 30 minutes or less
- Open AWS Bedrock Console > Agents
- Update the agent idle session timeout to 1800 seconds or less
Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12