Skip to main content

CCC-Complete (Policy) 0.1

Test results for this specific product, vendor, and version combination

VendorFINOS
ProductCCC-Complete (Policy)
Version0.1

Download Raw Results

Download the original OCSF or HTML result files used to generate this page

File NameDownload
aws-vpc-cfi-1775557775-vpc-cn03-allowed-requester-01
aws-vpc-cfi-1775557775-vpc-cn03-allowed-requester-02
aws-vpc-cfi-1775557775-vpc-cn03-disallowed-requester-01
aws-vpc-cfi-1775557775-vpc-cn03-disallowed-requester-02
aws-vpc-cfi-1775557775-vpc-cn03-non-allowlisted-requester-01
aws-vpc-cfi-1775557775-vpc
aws-vpc-combined
aws-vpc-prowler
aws-vpc-summary

Test Summary

Aggregate summary of all tests for this configuration result

Resources In Configuration6
Count of Tests36
Passing Tests16
Failing Tests20
Catalogs Tested

Control Catalog Summary

Summary of test results grouped by control catalog and resource

Control CatalogResourcesTotal TestsPassingFailingTested RequirementsMissing RequirementsUnused Core Requirements
CCC.VPC
vpc-00ceb92e81affe79...vpc-027ef85c88b9d68c...vpc-03e0763d329ec1a5...vpc-0b622dcd5eee1a98...vpc-0c697ba86026b9c5...vpc-0f691db8cf3afae0...
361620
None

Test Mapping Summary

Summary of test mappings showing how event codes map to test requirements

Control CatalogTest RequirementMapped Tests (Event Code | Total | Passing | Failing)
CCC.VPC
CCC.VPC.CN01.AR01
When a subscription is created, the subscription MUST NOT contain default network resources.
Main check: no default VPC exists
12120
CCC.VPC
CCC.VPC.CN02.AR01
When a resource is created in a public subnet, that resource MUST NOT be assigned an external IP address by default.
Main check (config): public subnets do not auto-assign external IPs
12210
CCC.VPC
CCC.VPC.CN04.AR01
When any network traffic goes to or from an interface in the VPC, the service MUST capture and log all relevant information.
Main check (config): flow logs are active and capture all traffic
12210

Resource Summary

Summary of all resources mentioned in OCSF results

Resource NameResource TypeControl CatalogsTotal TestsPassingFailing
vpc-00ceb92e81affe793
vpc624
vpc-027ef85c88b9d68c2
vpc660
vpc-03e0763d329ec1a53
vpc624
vpc-0b622dcd5eee1a986
vpc624
vpc-0c697ba86026b9c59
vpc624
vpc-0f691db8cf3afae09
vpc624

Test Results

OCSF test results filtered for entries with CCC compliance mappings

StatusFindingResource NameResource TypeMessageTest Requirements
PASS
Main check: no default VPC exists
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I call "{vpcService}" with "CountDefaultVpcs" ✓ "{result}" is "0"
vpc-0c697ba86026b9c59
vpc
Main check: no default VPC exists
FAIL
Main check (config): public subnets do not auto-assign external IPs
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I refer to "{UID}" as "TargetVpcId" ✓ I call "{vpcService}" with "EvaluatePublicSubnetDefaultIPControl" using argument "{TargetVpcId}" ✓ "{result.ViolatingSubnetCount}" is "0" ✗ "{result.Reason}" contains "disable default public IP" - Error: expected {result.Reason} to contain 'disable default public IP', but got 'no public subnets found for in-scope VPC'
vpc-0c697ba86026b9c59
vpc
Main check (config): public subnets do not auto-assign external IPs
FAIL
Main check (config): flow logs are active and capture all traffic
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I refer to "{UID}" as "TargetVpcId" ✓ I call "{vpcService}" with "EvaluateVpcFlowLogsControl" using argument "{TargetVpcId}" ✗ "{result.FlowLogCount}" should be greater than "0" - Error: expected {result.FlowLogCount} (0) to be greater than 0 ⊘ "{result.NonCompliantCount}" is "0" (skipped)
vpc-0c697ba86026b9c59
vpc
Main check (config): flow logs are active and capture all traffic
PASS
Main check: no default VPC exists
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I call "{vpcService}" with "CountDefaultVpcs" ✓ "{result}" is "0"
vpc-0b622dcd5eee1a986
vpc
Main check: no default VPC exists
FAIL
Main check (config): public subnets do not auto-assign external IPs
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I refer to "{UID}" as "TargetVpcId" ✓ I call "{vpcService}" with "EvaluatePublicSubnetDefaultIPControl" using argument "{TargetVpcId}" ✓ "{result.ViolatingSubnetCount}" is "0" ✗ "{result.Reason}" contains "disable default public IP" - Error: expected {result.Reason} to contain 'disable default public IP', but got 'no public subnets found for in-scope VPC'
vpc-0b622dcd5eee1a986
vpc
Main check (config): public subnets do not auto-assign external IPs
FAIL
Main check (config): flow logs are active and capture all traffic
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I refer to "{UID}" as "TargetVpcId" ✓ I call "{vpcService}" with "EvaluateVpcFlowLogsControl" using argument "{TargetVpcId}" ✗ "{result.FlowLogCount}" should be greater than "0" - Error: expected {result.FlowLogCount} (0) to be greater than 0 ⊘ "{result.NonCompliantCount}" is "0" (skipped)
vpc-0b622dcd5eee1a986
vpc
Main check (config): flow logs are active and capture all traffic
PASS
Main check: no default VPC exists
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I call "{vpcService}" with "CountDefaultVpcs" ✓ "{result}" is "0"
vpc-03e0763d329ec1a53
vpc
Main check: no default VPC exists
FAIL
Main check (config): public subnets do not auto-assign external IPs
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I refer to "{UID}" as "TargetVpcId" ✓ I call "{vpcService}" with "EvaluatePublicSubnetDefaultIPControl" using argument "{TargetVpcId}" ✓ "{result.ViolatingSubnetCount}" is "0" ✗ "{result.Reason}" contains "disable default public IP" - Error: expected {result.Reason} to contain 'disable default public IP', but got 'no public subnets found for in-scope VPC'
vpc-03e0763d329ec1a53
vpc
Main check (config): public subnets do not auto-assign external IPs
FAIL
Main check (config): flow logs are active and capture all traffic
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I refer to "{UID}" as "TargetVpcId" ✓ I call "{vpcService}" with "EvaluateVpcFlowLogsControl" using argument "{TargetVpcId}" ✗ "{result.FlowLogCount}" should be greater than "0" - Error: expected {result.FlowLogCount} (0) to be greater than 0 ⊘ "{result.NonCompliantCount}" is "0" (skipped)
vpc-03e0763d329ec1a53
vpc
Main check (config): flow logs are active and capture all traffic
PASS
Main check: no default VPC exists
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I call "{vpcService}" with "CountDefaultVpcs" ✓ "{result}" is "0"
vpc-00ceb92e81affe793
vpc
Main check: no default VPC exists
FAIL
Main check (config): public subnets do not auto-assign external IPs
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I refer to "{UID}" as "TargetVpcId" ✓ I call "{vpcService}" with "EvaluatePublicSubnetDefaultIPControl" using argument "{TargetVpcId}" ✓ "{result.ViolatingSubnetCount}" is "0" ✗ "{result.Reason}" contains "disable default public IP" - Error: expected {result.Reason} to contain 'disable default public IP', but got 'no public subnets found for in-scope VPC'
vpc-00ceb92e81affe793
vpc
Main check (config): public subnets do not auto-assign external IPs
FAIL
Main check (config): flow logs are active and capture all traffic
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I refer to "{UID}" as "TargetVpcId" ✓ I call "{vpcService}" with "EvaluateVpcFlowLogsControl" using argument "{TargetVpcId}" ✗ "{result.FlowLogCount}" should be greater than "0" - Error: expected {result.FlowLogCount} (0) to be greater than 0 ⊘ "{result.NonCompliantCount}" is "0" (skipped)
vpc-00ceb92e81affe793
vpc
Main check (config): flow logs are active and capture all traffic
PASS
Main check: no default VPC exists
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I call "{vpcService}" with "CountDefaultVpcs" ✓ "{result}" is "0"
vpc-0f691db8cf3afae09
vpc
Main check: no default VPC exists
FAIL
Main check (config): public subnets do not auto-assign external IPs
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I refer to "{UID}" as "TargetVpcId" ✓ I call "{vpcService}" with "EvaluatePublicSubnetDefaultIPControl" using argument "{TargetVpcId}" ✓ "{result.ViolatingSubnetCount}" is "0" ✗ "{result.Reason}" contains "disable default public IP" - Error: expected {result.Reason} to contain 'disable default public IP', but got 'no public subnets found for in-scope VPC'
vpc-0f691db8cf3afae09
vpc
Main check (config): public subnets do not auto-assign external IPs
FAIL
Main check (config): flow logs are active and capture all traffic
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I refer to "{UID}" as "TargetVpcId" ✓ I call "{vpcService}" with "EvaluateVpcFlowLogsControl" using argument "{TargetVpcId}" ✗ "{result.FlowLogCount}" should be greater than "0" - Error: expected {result.FlowLogCount} (0) to be greater than 0 ⊘ "{result.NonCompliantCount}" is "0" (skipped)
vpc-0f691db8cf3afae09
vpc
Main check (config): flow logs are active and capture all traffic
PASS
Main check: no default VPC exists
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I call "{vpcService}" with "CountDefaultVpcs" ✓ "{result}" is "0"
vpc-027ef85c88b9d68c2
vpc
Main check: no default VPC exists
PASS
Main check (config): public subnets do not auto-assign external IPs
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I refer to "{UID}" as "TargetVpcId" ✓ I call "{vpcService}" with "EvaluatePublicSubnetDefaultIPControl" using argument "{TargetVpcId}" ✓ "{result.ViolatingSubnetCount}" is "0" ✓ "{result.Reason}" contains "disable default public IP"
vpc-027ef85c88b9d68c2
vpc
Main check (config): public subnets do not auto-assign external IPs
PASS
Main check (config): flow logs are active and capture all traffic
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I refer to "{UID}" as "TargetVpcId" ✓ I call "{vpcService}" with "EvaluateVpcFlowLogsControl" using argument "{TargetVpcId}" ✓ "{result.FlowLogCount}" should be greater than "0" ✓ "{result.NonCompliantCount}" is "0"
vpc-027ef85c88b9d68c2
vpc
Main check (config): flow logs are active and capture all traffic
PASS
Main check: no default VPC exists
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I call "{vpcService}" with "CountDefaultVpcs" ✓ "{result}" is "0"
vpc-0c697ba86026b9c59
vpc
Main check: no default VPC exists
FAIL
Main check (config): public subnets do not auto-assign external IPs
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I refer to "{UID}" as "TargetVpcId" ✓ I call "{vpcService}" with "EvaluatePublicSubnetDefaultIPControl" using argument "{TargetVpcId}" ✓ "{result.ViolatingSubnetCount}" is "0" ✗ "{result.Reason}" contains "disable default public IP" - Error: expected {result.Reason} to contain 'disable default public IP', but got 'no public subnets found for in-scope VPC'
vpc-0c697ba86026b9c59
vpc
Main check (config): public subnets do not auto-assign external IPs
FAIL
Main check (config): flow logs are active and capture all traffic
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I refer to "{UID}" as "TargetVpcId" ✓ I call "{vpcService}" with "EvaluateVpcFlowLogsControl" using argument "{TargetVpcId}" ✗ "{result.FlowLogCount}" should be greater than "0" - Error: expected {result.FlowLogCount} (0) to be greater than 0 ⊘ "{result.NonCompliantCount}" is "0" (skipped)
vpc-0c697ba86026b9c59
vpc
Main check (config): flow logs are active and capture all traffic
PASS
Main check: no default VPC exists
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I call "{vpcService}" with "CountDefaultVpcs" ✓ "{result}" is "0"
vpc-0b622dcd5eee1a986
vpc
Main check: no default VPC exists
FAIL
Main check (config): public subnets do not auto-assign external IPs
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I refer to "{UID}" as "TargetVpcId" ✓ I call "{vpcService}" with "EvaluatePublicSubnetDefaultIPControl" using argument "{TargetVpcId}" ✓ "{result.ViolatingSubnetCount}" is "0" ✗ "{result.Reason}" contains "disable default public IP" - Error: expected {result.Reason} to contain 'disable default public IP', but got 'no public subnets found for in-scope VPC'
vpc-0b622dcd5eee1a986
vpc
Main check (config): public subnets do not auto-assign external IPs
FAIL
Main check (config): flow logs are active and capture all traffic
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I refer to "{UID}" as "TargetVpcId" ✓ I call "{vpcService}" with "EvaluateVpcFlowLogsControl" using argument "{TargetVpcId}" ✗ "{result.FlowLogCount}" should be greater than "0" - Error: expected {result.FlowLogCount} (0) to be greater than 0 ⊘ "{result.NonCompliantCount}" is "0" (skipped)
vpc-0b622dcd5eee1a986
vpc
Main check (config): flow logs are active and capture all traffic
PASS
Main check: no default VPC exists
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I call "{vpcService}" with "CountDefaultVpcs" ✓ "{result}" is "0"
vpc-03e0763d329ec1a53
vpc
Main check: no default VPC exists
FAIL
Main check (config): public subnets do not auto-assign external IPs
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I refer to "{UID}" as "TargetVpcId" ✓ I call "{vpcService}" with "EvaluatePublicSubnetDefaultIPControl" using argument "{TargetVpcId}" ✓ "{result.ViolatingSubnetCount}" is "0" ✗ "{result.Reason}" contains "disable default public IP" - Error: expected {result.Reason} to contain 'disable default public IP', but got 'no public subnets found for in-scope VPC'
vpc-03e0763d329ec1a53
vpc
Main check (config): public subnets do not auto-assign external IPs
FAIL
Main check (config): flow logs are active and capture all traffic
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I refer to "{UID}" as "TargetVpcId" ✓ I call "{vpcService}" with "EvaluateVpcFlowLogsControl" using argument "{TargetVpcId}" ✗ "{result.FlowLogCount}" should be greater than "0" - Error: expected {result.FlowLogCount} (0) to be greater than 0 ⊘ "{result.NonCompliantCount}" is "0" (skipped)
vpc-03e0763d329ec1a53
vpc
Main check (config): flow logs are active and capture all traffic
PASS
Main check: no default VPC exists
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I call "{vpcService}" with "CountDefaultVpcs" ✓ "{result}" is "0"
vpc-00ceb92e81affe793
vpc
Main check: no default VPC exists
FAIL
Main check (config): public subnets do not auto-assign external IPs
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I refer to "{UID}" as "TargetVpcId" ✓ I call "{vpcService}" with "EvaluatePublicSubnetDefaultIPControl" using argument "{TargetVpcId}" ✓ "{result.ViolatingSubnetCount}" is "0" ✗ "{result.Reason}" contains "disable default public IP" - Error: expected {result.Reason} to contain 'disable default public IP', but got 'no public subnets found for in-scope VPC'
vpc-00ceb92e81affe793
vpc
Main check (config): public subnets do not auto-assign external IPs
FAIL
Main check (config): flow logs are active and capture all traffic
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I refer to "{UID}" as "TargetVpcId" ✓ I call "{vpcService}" with "EvaluateVpcFlowLogsControl" using argument "{TargetVpcId}" ✗ "{result.FlowLogCount}" should be greater than "0" - Error: expected {result.FlowLogCount} (0) to be greater than 0 ⊘ "{result.NonCompliantCount}" is "0" (skipped)
vpc-00ceb92e81affe793
vpc
Main check (config): flow logs are active and capture all traffic
PASS
Main check: no default VPC exists
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I call "{vpcService}" with "CountDefaultVpcs" ✓ "{result}" is "0"
vpc-0f691db8cf3afae09
vpc
Main check: no default VPC exists
FAIL
Main check (config): public subnets do not auto-assign external IPs
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I refer to "{UID}" as "TargetVpcId" ✓ I call "{vpcService}" with "EvaluatePublicSubnetDefaultIPControl" using argument "{TargetVpcId}" ✓ "{result.ViolatingSubnetCount}" is "0" ✗ "{result.Reason}" contains "disable default public IP" - Error: expected {result.Reason} to contain 'disable default public IP', but got 'no public subnets found for in-scope VPC'
vpc-0f691db8cf3afae09
vpc
Main check (config): public subnets do not auto-assign external IPs
FAIL
Main check (config): flow logs are active and capture all traffic
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I refer to "{UID}" as "TargetVpcId" ✓ I call "{vpcService}" with "EvaluateVpcFlowLogsControl" using argument "{TargetVpcId}" ✗ "{result.FlowLogCount}" should be greater than "0" - Error: expected {result.FlowLogCount} (0) to be greater than 0 ⊘ "{result.NonCompliantCount}" is "0" (skipped)
vpc-0f691db8cf3afae09
vpc
Main check (config): flow logs are active and capture all traffic
PASS
Main check: no default VPC exists
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I call "{vpcService}" with "CountDefaultVpcs" ✓ "{result}" is "0"
vpc-027ef85c88b9d68c2
vpc
Main check: no default VPC exists
PASS
Main check (config): public subnets do not auto-assign external IPs
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I refer to "{UID}" as "TargetVpcId" ✓ I call "{vpcService}" with "EvaluatePublicSubnetDefaultIPControl" using argument "{TargetVpcId}" ✓ "{result.ViolatingSubnetCount}" is "0" ✓ "{result.Reason}" contains "disable default public IP"
vpc-027ef85c88b9d68c2
vpc
Main check (config): public subnets do not auto-assign external IPs
PASS
Main check (config): flow logs are active and capture all traffic
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I refer to "{UID}" as "TargetVpcId" ✓ I call "{vpcService}" with "EvaluateVpcFlowLogsControl" using argument "{TargetVpcId}" ✓ "{result.FlowLogCount}" should be greater than "0" ✓ "{result.NonCompliantCount}" is "0"
vpc-027ef85c88b9d68c2
vpc
Main check (config): flow logs are active and capture all traffic