# nozaq/terraform-aws-secure-baseline

Terraform module to set up your AWS account with the secure baseline configuration based on CIS Amazon Web Services Foundations and AWS Foundational Security Best Practices.

Repository: https://github.com/nozaq/terraform-aws-secure-baseline
Canonical: https://ross.abutalabs.com/products/terraform-aws-secure-baseline
Language: HCL
License: MIT
License Family: permissive
Topics: terraform, aws, security, security-hardening, terraform-modules, hardening, cis-benchmark, aws-auditing, security-tools, devops, terraform-module
Last push: 2026-07-08T09:36:36+00:00

## Health v2 (maintenance only)
Score: 64/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 91, release rhythm 8, longevity 100
- inputs: {"age_days": 3124, "days_push": 56, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1200, forks 379 (observed 2026-08-28T04:03:57.989293+00:00)

## What it is
A Terraform module that applies a secure baseline configuration to AWS accounts based on CIS Foundations and AWS Foundational Security Best Practices benchmarks. It automates IAM hardening, CloudTrail logging, GuardDuty, SecurityHub, AWS Config, and VPC security defaults across regions.

## Use cases
- harden a new AWS account against CIS benchmarks
- enable CloudTrail and GuardDuty across all regions with Terraform
- set up AWS Config and SecurityHub automatically
- apply IAM password policies and access analyzer to an AWS account
- audit and secure default VPCs and security groups
- centralize encrypted audit logs in S3 with Glacier archiving

## When to choose
- you want a repeatable, code-defined security baseline for AWS accounts
- you need CIS benchmark compliance coverage applied via Terraform
- you are bootstrapping multi-region AWS security tooling

## When to avoid
- you use a cloud provider other than AWS
- you need a runtime security monitoring product rather than infrastructure provisioning
- your organization requires a custom security framework not covered by CIS or AWS FSBP

## Facets
- artifact type: infra-config
- maturity: active
- function: security, monitoring, logging, alerting, infrastructure-as-code, configuration-management
- domain: security, cloud-computing, infrastructure-as-code, self-hosted
- platform: cloud
- tags: terraform-module, aws, cis-benchmark, security-hardening, cloudtrail, guardduty, securityhub, aws-config, baseline-configuration, devops, terraform

## Member repositories
- nozaq/terraform-aws-secure-baseline (main) score 64

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:57.989293+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:20:50.450710+00:00, confidence not recorded.
  - readme: https://github.com/nozaq/terraform-aws-secure-baseline (fetched 2026-08-28T04:03:57.989293+00:00, sha 6cc2d2858190)
- Data as of 2026-08-30T08:39:29.467469+00:00.
