Amazon Bedrock lifecycle & offboarding security checks
Dormant accounts, leavers with access, unowned assets and change-management gaps — the checks that catch what HR processes miss.
On Amazon Bedrock, Black Cat runs 4 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Amazon Bedrock connector needs.
Checks (4)
severity: critical Bedrock Agent Failed Status fix difficulty: medium #
Investigate and fix the agent failure
- Open AWS Bedrock Console > Agents
- Check failure reason in agent details
- Fix configuration and re-prepare the agent
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6
severity: medium Bedrock Agent Not Prepared (7+ days) fix difficulty: easy #
Prepare the agent or delete if no longer needed
- Open AWS Bedrock Console > Agents
- Select the agent and click Prepare
- If not needed, delete the agent
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6
severity: low Bedrock Agent Stale fix difficulty: easy #
Review and update or delete agents with no recent updates
- Open AWS Bedrock Console > Agents
- Review the agent and determine if still needed
- Update or delete as appropriate
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6
severity: high Bedrock Agent Orphaned Owner fix difficulty: easy #
Reassign the agent to an active owner
- Identify the agent creator via CloudTrail or tags
- Update the owner tag to an active team member
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6