Skip to content

Amazon Bedrock data sharing & exposure security checks

External sharing, public links, guest access, retention and data-protection settings that quietly push company data outside the tenant.

On Amazon Bedrock, Black Cat runs 4 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Amazon Bedrock connector needs.

Checks (4)

severity: medium Bedrock Agent Multiple Knowledge Bases fix difficulty: medium #

Review data exposure from multiple knowledge bases

  1. Open AWS Bedrock Console > Agents
  2. Review each knowledge base and its data source
  3. Remove unnecessary knowledge base associations

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: medium Bedrock Agent No Customer-Managed Encryption fix difficulty: medium #

Configure a customer-managed KMS key for the agent

  1. Open AWS KMS Console and create or select a key
  2. Open AWS Bedrock Console > Agents
  3. Update the agent to use the customer-managed key

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: low Bedrock Agent Session Memory Enabled fix difficulty: easy #

Review if session memory is appropriate for this agent's data sensitivity

  1. Assess what data the agent processes
  2. If handling sensitive data, disable session memory

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: medium Bedrock Agent Long Session TTL fix difficulty: easy #

Reduce idle session TTL to 30 minutes or less

  1. Open AWS Bedrock Console > Agents
  2. Update the agent idle session timeout to 1800 seconds or less

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

More Amazon Bedrock checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial