Ross ROSS = Recommend OSS · open-source software intelligence for agents

nozaq/terraform-aws-secure-baseline resource

Terraform module to set up your AWS account with the secure baseline configuration based on CIS Amazon Web Services Foundations and AWS Foundational Security Best Practices. observed · 2026-08-28

github.com/nozaq/terraform-aws-secure-baseline · HCL · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

64/100

  • Activity 91
  • Release rhythm 8
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 3124
  • days_rel: n/a
  • days_push: 56
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1200 stars · 379 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A Terraform module that applies a secure baseline configuration to AWS accounts based on CIS Foundations and AWS Foundational Security Best Practices benchmarks. It automates IAM hardening, CloudTrail logging, GuardDuty, SecurityHub, AWS Config, and VPC security defaults across regions.

Use cases

  • harden a new AWS account against CIS benchmarks
  • enable CloudTrail and GuardDuty across all regions with Terraform
  • set up AWS Config and SecurityHub automatically
  • apply IAM password policies and access analyzer to an AWS account
  • audit and secure default VPCs and security groups
  • centralize encrypted audit logs in S3 with Glacier archiving

When to choose

  • you want a repeatable, code-defined security baseline for AWS accounts
  • you need CIS benchmark compliance coverage applied via Terraform
  • you are bootstrapping multi-region AWS security tooling

When to avoid

  • you use a cloud provider other than AWS
  • you need a runtime security monitoring product rather than infrastructure provisioning
  • your organization requires a custom security framework not covered by CIS or AWS FSBP

Facets

infra-config · maturity active

security monitoring logging alerting infrastructure-as-code configuration-management security cloud-computing infrastructure-as-code self-hosted cloud terraform-module aws cis-benchmark security-hardening cloudtrail guardduty securityhub aws-config baseline-configuration devops terraform

1 source

Member repositories

RepositoryRoleHealth v2
nozaq/terraform-aws-secure-baselinemain64

For agents

markdown · JSON · MCP: product_card(name="nozaq/terraform-aws-secure-baseline")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem