Skill 31 · Prompt Library For Startups
Subchapter 31.20
references/prompt-library/multi-region-assessment.mdMarkdown49 KBView on GitHub
Automate comprehensive security assessments across all 33+ AWS regions using AI-driven analysis to identify vulnerabilities, compliance gaps, and misconfigurations
Prerequisite: this prompt is built on the AWS Well-Architected Security Assessment Tool MCP server and its ExploreAwsResources tool. That server is not bundled with this plugin and is not the same as the unified AWS MCP Server (aws-mcp) that ships here — install and configure it in your AI tool separately before running this prompt (see the Prerequisites list under “How to use?”).
Conduct a comprehensive multi-region AWS security assessment using the Well-Architected Security MCP server. Generate detailed markdown reports following this workflow:
Scan ALL AWS Regions Explicitly
US Regions:
Europe Regions:
Asia Pacific Regions:
Canada Region:
South America Region:
Middle East Regions:
Africa Region:
Israel Region:
Document Findings for Each Region
Verify Region Coverage
For EACH ACTIVE region identified in Phase 1, perform complete analysis:
Important: Do not skip any region with resources. Assess ALL active regions individually.
Date: [Date] | Account: [ID] | Region: [Code - Full Name]
Resource Distribution:
Security Services Status:
| Service | Status | Findings | Notes |
|---|---|---|---|
| GuardDuty | ✅/❌ | [#] | [details] |
| Security Hub | ✅/❌ | [#] | [details] |
| Inspector | ✅/❌ | [#] | [details] |
| Access Analyzer | ✅/❌ | [#] | [details] |
[List all high findings]
Violations by Standard:
Encryption Status:
EC2:
Lambda:
Containers:
[Region-specific strategic guidance]
Filename: AWS_Security_Assessment_[REGION-CODE]_[YYYY-MM-DD].md
Generate this report for EVERY active region - do not consolidate or skip regions.
Date: [Date] | Account: [ID]
| Region Code | Region Name | Status | Resources | Critical | High | Medium | Low | Compliance % |
|---|---|---|---|---|---|---|---|---|
| us-east-1 | N. Virginia | ✅ Active | [#] | [#] | [#] | [#] | [#] | [%] |
| us-east-2 | Ohio | ✅ Active | [#] | [#] | [#] | [#] | [#] | [%] |
| us-west-1 | N. California | ✅ Active | [#] | [#] | [#] | [#] | [#] | [%] |
| us-west-2 | Oregon | ✅ Active | [#] | [#] | [#] | [#] | [#] | [%] |
| eu-west-1 | Ireland | ✅ Active | [#] | [#] | [#] | [#] | [#] | [%] |
| eu-west-2 | London | ⚪ Inactive | 0 | - | - | - | - | - |
| eu-west-3 | Paris | ✅ Active | [#] | [#] | [#] | [#] | [#] | [%] |
| eu-central-1 | Frankfurt | ✅ Active | [#] | [#] | [#] | [#] | [#] | [%] |
| eu-central-2 | Zurich | ⚪ Inactive | 0 | - | - | - | - | - |
| eu-north-1 | Stockholm | ⚪ Inactive | 0 | - | - | - | - | - |
| eu-south-1 | Milan | ⚪ Inactive | 0 | - | - | - | - | - |
| eu-south-2 | Spain | ⚪ Inactive | 0 | - | - | - | - | - |
| ap-south-1 | Mumbai | ✅ Active | [#] | [#] | [#] | [#] | [#] | [%] |
| ap-south-2 | Hyderabad | ⚪ Inactive | 0 | - | - | - | - | - |
| ap-northeast-1 | Tokyo | ✅ Active | [#] | [#] | [#] | [#] | [#] | [%] |
| ap-northeast-2 | Seoul | ✅ Active | [#] | [#] | [#] | [#] | [#] | [%] |
| ap-northeast-3 | Osaka | ⚪ Inactive | 0 | - | - | - | - | - |
| ap-southeast-1 | Singapore | ✅ Active | [#] | [#] | [#] | [#] | [#] | [%] |
| ap-southeast-2 | Sydney | ✅ Active | [#] | [#] | [#] | [#] | [#] | [%] |
| ap-southeast-3 | Jakarta | ⚪ Inactive | 0 | - | - | - | - | - |
| ap-southeast-4 | Melbourne | ⚪ Inactive | 0 | - | - | - | - | - |
| ap-east-1 | Hong Kong | ⚪ Inactive | 0 | - | - | - | - | - |
| ca-central-1 | Canada Central | ✅ Active | [#] | [#] | [#] | [#] | [#] | [%] |
| ca-west-1 | Calgary | ⚪ Inactive | 0 | - | - | - | - | - |
| sa-east-1 | São Paulo | ✅ Active | [#] | [#] | [#] | [#] | [#] | [%] |
| me-south-1 | Bahrain | ⚪ Inactive | 0 | - | - | - | - | - |
| me-central-1 | UAE | ⚪ Inactive | 0 | - | - | - | - | - |
| af-south-1 | Cape Town | ⚪ Inactive | 0 | - | - | - | - | - |
| il-central-1 | Tel Aviv | ⚪ Inactive | 0 | - | - | - | - | - |
| TOTAL ACTIVE | [sum] | [sum] | [sum] | [sum] | [sum] | [avg] |
| Region | EC2 | RDS | S3 | Lambda | VPC | ECS | EKS | Other | Total | % of Global |
|---|---|---|---|---|---|---|---|---|---|---|
| us-east-1 | [#] | [#] | [#] | [#] | [#] | [#] | [#] | [#] | [#] | [%] |
| us-west-2 | [#] | [#] | [#] | [#] | [#] | [#] | [#] | [#] | [#] | [%] |
| eu-west-1 | [#] | [#] | [#] | [#] | [#] | [#] | [#] | [#] | [#] | [%] |
| [continue for all active regions] |
| Service | Total Count | Active Regions | Region Distribution |
|---|---|---|---|
| EC2 | [#] | [#] | [list regions] |
| RDS | [#] | [#] | [list regions] |
| S3 | [#] | [#] | [list regions] |
| Lambda | [#] | [#] | [list regions] |
| VPC | [#] | [#] | [list regions] |
| ECS | [#] | [#] | [list regions] |
| EKS | [#] | [#] | [list regions] |
| DynamoDB | [#] | [#] | [list regions] |
| [continue for all services] |
| Service | Enabled in Active Regions | Disabled in Active Regions | Not Applicable (Inactive) | Total Findings |
|---|---|---|---|---|
| GuardDuty | [list regions] | [list regions] | [#] inactive | [#] |
| Security Hub | [list regions] | [list regions] | [#] inactive | [#] |
| Inspector | [list regions] | [list regions] | [#] inactive | [#] |
| Access Analyzer | [list regions] | [list regions] | [#] inactive | [#] |
Regions with NO security services enabled:
Regions with partial coverage:
[Continue for top 20]
Issue patterns found in 5+ regions:
| Region | Total | Compliant | Non-Compliant | % Compliant | Status |
|---|---|---|---|---|---|
| [each active region] |
Unencrypted by Region:
| Region | Total Buckets | Unencrypted | Bucket Names |
|---|---|---|---|
| [each region with unencrypted buckets] |
Unencrypted by Region:
| Region | Total Volumes | Unencrypted | Volume IDs (attached to) |
|---|---|---|---|
| [each region with unencrypted volumes] |
Unencrypted by Region:
| Region | Total DBs | Unencrypted | DB Identifiers |
|---|---|---|---|
| [each region with unencrypted DBs] |
Regions with Most Permissive SGs:
| Region | Total SGs | Permissive | % |
|---|---|---|---|
| [ranked list] |
[Region] - Score: [#]/100
[Region] - Score: [#]/100 [Continue for top 5]
[Region] - Risk Level: CRITICAL
[Region] - Risk Level: HIGH [Continue for top 5]
| Region | Security Score | Maturity Level | Trend |
|---|---|---|---|
| [all active regions ranked] | Advanced/Intermediate/Basic | ⬆️⬇️➡️ |
| Region | GuardDuty | Security Hub | Inspector | Config | CloudTrail | Total |
|---|---|---|---|---|---|---|
| us-east-1 | $[amt] | $[amt] | $[amt] | $[amt] | $[amt] | $[amt] |
| [each active region] | ||||||
| GLOBAL TOTAL | $[sum] | $[sum] | $[sum] | $[sum] | $[sum] | $[sum] |
| Region | IAM | Detection | Infrastructure | Data Protection | Incident Response | Overall |
|---|---|---|---|---|---|---|
| us-east-1 | [/10] | [/10] | [/10] | [/10] | [/10] | [/10] |
| [all active regions] | ||||||
| GLOBAL AVG | [avg] | [avg] | [avg] | [avg] | [avg] | [avg] |
| Region | Action | Resources | Owner | Deadline |
|---|---|---|---|---|
| [critical actions per region] |
[Prioritized actions across regions]
[Strategic improvements]
[Architectural improvements and standardization]
By Region:
Centralized Security Monitoring
Standardized Security Baselines
Cross-Region Incident Response
Target State: All active regions should have:
Current Gaps by Region:
| Region | GuardDuty | Security Hub | Inspector | Access Analyzer | Gap Count |
|---|---|---|---|---|---|
| [regions with gaps] |
Cross-Region EventBridge Rules:
Critical (All Regions):
High Priority (Specific Regions):
Infrastructure (Per Region):
Application Security (Per Region):
[List all regions with 0 resources]
[Comprehensive list from all active regions]
[Comprehensive list from all active regions]
[Comprehensive list from all active regions]
us-east-1:
us-west-2:
[Continue for all active regions]
EC2 Instances:
[Detailed mappings per region]
[Detailed mappings per region]
[Detailed mappings per region]
Filename: AWS_Security_Assessment_CONSOLIDATED_[YYYY-MM-DD].md
Assessment Date: [Date] AWS Account: [Account ID] Assessment ID: [Unique ID]
📊 Main Report: AWS_Security_Assessment_CONSOLIDATED_[DATE].md
✅ US Regions:
AWS_Security_Assessment_us-east-1_[DATE].md - N. Virginia ([#] resources)AWS_Security_Assessment_us-east-2_[DATE].md - Ohio ([#] resources)AWS_Security_Assessment_us-west-1_[DATE].md - N. California ([#] resources)AWS_Security_Assessment_us-west-2_[DATE].md - Oregon ([#] resources)✅ Europe Regions:
AWS_Security_Assessment_eu-west-1_[DATE].md - Ireland ([#] resources)AWS_Security_Assessment_eu-west-2_[DATE].md - London ([#] resources)AWS_Security_Assessment_eu-west-3_[DATE].md - Paris ([#] resources)AWS_Security_Assessment_eu-central-1_[DATE].md - Frankfurt ([#] resources)AWS_Security_Assessment_eu-central-2_[DATE].md - Zurich ([#] resources)AWS_Security_Assessment_eu-north-1_[DATE].md - Stockholm ([#] resources)AWS_Security_Assessment_eu-south-1_[DATE].md - Milan ([#] resources)AWS_Security_Assessment_eu-south-2_[DATE].md - Spain ([#] resources)✅ Asia Pacific Regions:
AWS_Security_Assessment_ap-south-1_[DATE].md - Mumbai ([#] resources)AWS_Security_Assessment_ap-south-2_[DATE].md - Hyderabad ([#] resources)AWS_Security_Assessment_ap-northeast-1_[DATE].md - Tokyo ([#] resources)AWS_Security_Assessment_ap-northeast-2_[DATE].md - Seoul ([#] resources)AWS_Security_Assessment_ap-northeast-3_[DATE].md - Osaka ([#] resources)AWS_Security_Assessment_ap-southeast-1_[DATE].md - Singapore ([#] resources)AWS_Security_Assessment_ap-southeast-2_[DATE].md - Sydney ([#] resources)AWS_Security_Assessment_ap-southeast-3_[DATE].md - Jakarta ([#] resources)AWS_Security_Assessment_ap-southeast-4_[DATE].md - Melbourne ([#] resources)AWS_Security_Assessment_ap-east-1_[DATE].md - Hong Kong ([#] resources)✅ Other Regions:
AWS_Security_Assessment_ca-central-1_[DATE].md - Canada Central ([#] resources)AWS_Security_Assessment_ca-west-1_[DATE].md - Calgary ([#] resources)AWS_Security_Assessment_sa-east-1_[DATE].md - São Paulo ([#] resources)AWS_Security_Assessment_me-south-1_[DATE].md - Bahrain ([#] resources)AWS_Security_Assessment_me-central-1_[DATE].md - UAE ([#] resources)AWS_Security_Assessment_af-south-1_[DATE].md - Cape Town ([#] resources)AWS_Security_Assessment_il-central-1_[DATE].md - Tel Aviv ([#] resources)⚪ Regions with 0 Resources:
| Region | Resources | % of Total | Status |
|---|---|---|---|
| [all active regions listed with stats] |
Filename: README.md
aws-security-assessment-[YYYY-MM-DD]/ │ ├── README.md (this index file) │ ├── AWS_Security_Assessment_CONSOLIDATED_[YYYY-MM-DD].md │ └── regional-reports/ ├── us-east-1/ │ └── AWS_Security_Assessment_us-east-1_[YYYY-MM-DD].md ├── us-east-2/ │ └── AWS_Security_Assessment_us-east-2_[YYYY-MM-DD].md ├── us-west-1/ │ └── AWS_Security_Assessment_us-west-1_[YYYY-MM-DD].md ├── us-west-2/ │ └── AWS_Security_Assessment_us-west-2_[YYYY-MM-DD].md ├── eu-west-1/ │ └── AWS_Security_Assessment_eu-west-1_[YYYY-MM-DD].md ├── eu-west-2/ │ └── AWS_Security_Assessment_eu-west-2_[YYYY-MM-DD].md ├── eu-west-3/ │ └── AWS_Security_Assessment_eu-west-3_[YYYY-MM-DD].md ├── eu-central-1/ │ └── AWS_Security_Assessment_eu-central-1_[YYYY-MM-DD].md ├── eu-central-2/ │ └── AWS_Security_Assessment_eu-central-2_[YYYY-MM-DD].md ├── eu-north-1/ │ └── AWS_Security_Assessment_eu-north-1_[YYYY-MM-DD].md ├── eu-south-1/ │ └── AWS_Security_Assessment_eu-south-1_[YYYY-MM-DD].md ├── eu-south-2/ │ └── AWS_Security_Assessment_eu-south-2_[YYYY-MM-DD].md ├── ap-south-1/ │ └── AWS_Security_Assessment_ap-south-1_[YYYY-MM-DD].md ├── ap-south-2/ │ └── AWS_Security_Assessment_ap-south-2_[YYYY-MM-DD].md ├── ap-northeast-1/ │ └── AWS_Security_Assessment_ap-northeast-1_[YYYY-MM-DD].md ├── ap-northeast-2/ │ └── AWS_Security_Assessment_ap-northeast-2_[YYYY-MM-DD].md ├── ap-northeast-3/ │ └── AWS_Security_Assessment_ap-northeast-3_[YYYY-MM-DD].md ├── ap-southeast-1/ │ └── AWS_Security_Assessment_ap-southeast-1_[YYYY-MM-DD].md ├── ap-southeast-2/ │ └── AWS_Security_Assessment_ap-southeast-2_[YYYY-MM-DD].md ├── ap-southeast-3/ │ └── AWS_Security_Assessment_ap-southeast-3_[YYYY-MM-DD].md ├── ap-southeast-4/ │ └── AWS_Security_Assessment_ap-southeast-4_[YYYY-MM-DD].md ├── ap-east-1/ │ └── AWS_Security_Assessment_ap-east-1_[YYYY-MM-DD].md ├── ca-central-1/ │ └── AWS_Security_Assessment_ca-central-1_[YYYY-MM-DD].md ├── ca-west-1/ │ └── AWS_Security_Assessment_ca-west-1_[YYYY-MM-DD].md ├── sa-east-1/ │ └── AWS_Security_Assessment_sa-east-1_[YYYY-MM-DD].md ├── me-south-1/ │ └── AWS_Security_Assessment_me-south-1_[YYYY-MM-DD].md ├── me-central-1/ │ └── AWS_Security_Assessment_me-central-1_[YYYY-MM-DD].md ├── af-south-1/ │ └── AWS_Security_Assessment_af-south-1_[YYYY-MM-DD].md └── il-central-1/ └── AWS_Security_Assessment_il-central-1_[YYYY-MM-DD].md
CRITICAL: Ensure ALL 33+ regions are scanned in Phase 1.
ExploreAwsResources tool explicitly for each region listed aboveVerification Checklist:
Generate comprehensive, complete reports with real data from MCP tools. Do not skip or summarize any active regions.
Expected business outcomes:
Problem & Financial Impact
Organizations face critical challenges with manual security assessments that are expensive, slow, and incomplete. Current manual processes expose the business to significant financial and operational risks:
• Prohibitive Costs: Manual assessments cost $12,000 per region, totaling $180,000-$720,000 annually for multi-region operations, consuming security budgets without delivering continuous protection • Incomplete Coverage: Manual assessments cover only 20-30% of infrastructure across 33+ AWS regions, leaving critical blind spots that attackers can exploit • Severe Time Delays: Each assessment takes 60-80 hours, with compliance reporting delayed by weeks or months, creating audit risks and slowing customer acquisition • Massive Risk Exposure: Average data breach costs $4.45M (IBM 2023), compliance violations result in $50K-$1M+ fines, and undetected vulnerabilities remain exploitable for extended periods • Resource Drain: Security teams spend 80+ hours monthly on manual assessments instead of strategic initiatives, threat hunting, or security architecture improvements
Solution & Business Value
Implementing GenAI-powered automated security assessment using AWS Well-Architected Security MCP Server delivers transformative business outcomes with minimal investment:
• Dramatic Cost Reduction: Annual savings of $758,100 (98% reduction) by automating assessments, reducing cost per region from $12,000 to $1,600 with only $40,400 Year 1 investment • 99% Time Efficiency Gain: Assessment time drops from 83 hours to under 1 hour, enabling monthly instead of quarterly assessments with 100% region coverage across all 33+ AWS regions • Immediate ROI: 13,310% return on investment in Year 1, 0.3-month payback period, and $4.66M in annual risk avoidance through early detection of critical vulnerabilities • Competitive Advantage: Accelerates customer security evaluations from 1 week to 24 hours, improves enterprise deal win rates by 15%, and demonstrates security maturity for certifications (SOC 2, ISO 27001) • Strategic Capabilities: Real-time compliance reporting (CIS, AWS FSB, PCI DSS), executive dashboards with security posture metrics, and automated remediation guidance prioritized by business impact • Enhanced Detection: Mean Time to Detection reduced from weeks to minutes, identifying critical misconfigurations, unencrypted data, and compliance violations before they become incidents
Recommendation & Strategic Alignment
This investment aligns with organizational digital transformation goals while delivering measurable security improvements and enabling proactive risk management:
• Low Risk, High Reward: Minimal implementation risk with human-in-the-loop validation, ability to prevent just 1% of one breach justifies entire investment, and proven AWS Well-Architected Framework methodology • Scalable Foundation: Starts with 3-region pilot in Month 1 ($8,000), scales to all regions in Month 2, and extends to multi-account/multi-cloud in Month 6+ • Team Empowerment: Frees security team for strategic work (80+ hours/month), provides data-driven decision making, and enables “security-as-code” practices across engineering teams • Compliance Confidence: Audit-ready reports generated on-demand, continuous monitoring vs. point-in-time assessments, and regulatory alignment with GDPR, SOC 2, ISO 27001 • Innovation Leadership: Demonstrates AI/GenAI adoption, modernizes security operations, and positions organization as security-mature for enterprise customers and partners
Technical documentation:
Prerequisites:
Use case examples:
Output example
You are an expert AWS security analyst and technical writer specializing in cloud security assessments, compliance frameworks, and the AWS Well-Architected Framework.
Your primary function is to conduct comprehensive multi-region AWS security assessments using the Well-Architected Security MCP server tools and generate detailed, actionable markdown reports.
Core Competencies:
- Deep expertise in AWS security services including GuardDuty, Security Hub, Inspector, IAM Access Analyzer, CloudTrail, and Config
- Thorough understanding of AWS networking constructs including VPCs, security groups, NACLs, and network exposure patterns
- Proficiency in compliance frameworks including CIS AWS Foundations Benchmark, AWS Foundational Security Best Practices, and PCI DSS
- Expert knowledge of data protection mechanisms across AWS services including encryption at rest and in transit
- Familiarity with the AWS Well-Architected Security Pillar and its five focus areas: Identity and Access Management, Detection, Infrastructure Protection, Data Protection, and Incident Response
Assessment Methodology:
When conducting assessments, you must systematically scan every specified AWS region without exception. You categorize regions as Active when resources are present or Inactive when empty, noting any opt-in regions that cannot be accessed due to account configuration.
For each active region, you perform deep analysis across all security dimensions: security service status and findings, resource inventory by service type, finding categorization by severity, compliance posture against relevant standards, encryption status for data stores, network security configuration including overly permissive rules, compute security settings, and Well-Architected alignment scoring.
Report Generation Standards:
You generate three categories of deliverables. First, individual regional reports for every active region following the specified template structure with all ten required sections plus remediation planning. Second, a consolidated cross-region report that synthesizes findings across all regions with global analysis, regional comparisons, and phased remediation strategy. Third, an index README that provides navigation and quick access to critical information.
# AWS Multi-Region Security Assessment
Conduct a comprehensive security assessment across all AWS regions using the Well-Architected Security MCP server. Generate detailed markdown reports.
## Phase 1: Discovery
Scan ALL regions using ExploreAwsResources:
**Regions to scan:**
us-east-1, us-east-2, us-west-1, us-west-2, eu-west-1, eu-west-2, eu-west-3, eu-central-1, eu-central-2, eu-north-1, eu-south-1, eu-south-2, ap-south-1, ap-south-2, ap-northeast-1, ap-northeast-2, ap-northeast-3, ap-southeast-1, ap-southeast-2, ap-southeast-3, ap-southeast-4, ap-east-1, ca-central-1, ca-west-1, sa-east-1, me-south-1, me-central-1, af-south-1, il-central-1
Classify each region as Active (has resources) or Inactive (empty). Note any opt-in regions that cannot be accessed.
## Phase 2: Per-Region Assessment
For each ACTIVE region, analyze:
1. **Security Services**: GuardDuty, Security Hub, Inspector, IAM Access Analyzer status and findings
2. **Resources**: Inventory by service (EC2, RDS, S3, Lambda, ECS, EKS, DynamoDB, etc.)
3. **Findings**: Categorize by severity (Critical/High/Medium/Low)
4. **Compliance**: Check against CIS, AWS FSB, PCI DSS standards
5. **Data Protection**: Encryption status for S3, EBS, RDS, EFS, DynamoDB
6. **Network**: VPCs, security groups (flag 0.0.0.0/0), NACLs, Flow Logs, public exposure
7. **Compute**: EC2 (IMDSv2, SSM), Lambda, containers configuration
8. **Well-Architected**: Score against Security Pillar (IAM, Detection, Infrastructure, Data Protection, Incident Response)
## Phase 3: Report Generation
### Regional Report Template (one per active region)
Filename: `AWS_Security_Assessment_[REGION]_[YYYY-MM-DD].md`
```markdown
## Security Assessment - [REGION]
**Date:** [Date] | **Account:** [ID] | **Region:** [Code]
## Executive Summary (Consolidated Overview)
Security Rating | Total Resources | Critical/High/Medium/Low Findings | Compliance Rate | Overall Risk
## Sections
1. Resource Distribution (counts by service)
2. Security Services Status (table: Service | Status | Findings)
3. Critical & High Findings (Resource, Description, Risk, Remediation)
4. Compliance Assessment (violations by standard)
5. Data Protection (encryption status per service, list unencrypted resources)
6. Network Security (VPCs, permissive SGs, public exposure)
7. IAM (roles, policies, Access Analyzer findings)
8. Logging (CloudTrail, CloudWatch, Flow Logs, access logging)
9. Compute Security (EC2, Lambda, containers)
10. Well-Architected Scores (/10 per category)
11. Remediation Plan (Immediate 0-24h, Short 1-7d, Medium 1-4w, Long 1-3m)Filename: AWS_Security_Assessment_CONSOLIDATED_[YYYY-MM-DD].md
## Multi-Region Security Assessment - Consolidated
**Date:** [Date] | **Account:** [ID]
## Executive Summary (Consolidated Detail)
- Regions: Total scanned | Active | Inactive
- Global totals: Resources, Critical/High findings, Avg compliance
- Highest/Lowest risk regions
## Region Status Table
| Region | Status | Resources | Critical | High | Medium | Low | Compliance % |
## Cross-Region Analysis
1. Global Resource Distribution (by region, by service)
2. Security Services Coverage (enabled/disabled per region, gaps)
3. Top 20 Critical Issues (ranked, with affected regions/resources)
4. Global Compliance Metrics
5. Data Protection Summary (encryption rates per service, unencrypted by region)
6. Network Security Overview (permissive SGs, public exposure by region)
7. Regional Comparison (top 5 best/worst secured, maturity scores)
8. Cost Analysis (security service costs by region)
9. Well-Architected Scores (by region, global averages)
10. Common Patterns (recurring issues across 5+ regions)
## Global Remediation Strategy
- Phase 1 (0-7d): Critical actions across all regions
- Phase 2 (1-4w): High priority fixes
- Phase 3 (1-3m): Strategic improvements
- Phase 4 (3-6m): Architectural standardization
## Recommendations
- Global security initiatives
- Region-specific actions
- Standardization plan (target state for security services)
- Monitoring strategy
## Appendices
- Regional report links
- Complete findings export
- Full resource inventory
- Compliance mappings
- Methodology and limitationsFilename: README.md
## AWS Security Assessment Index
**Date:** [Date] | **Account:** [ID]
## Overview
Regions scanned | Active | Inactive | Total resources | Critical findings | Compliance %
## Reports
- Consolidated: [link]
- Regional (Active): [list with resource counts]
- Inactive regions: [list]
## Quick Access
- Critical issues: Consolidated Section 3
- Compliance: Consolidated Section 4
- Cost: Consolidated Section 8
- Top 5 risk regions: [ranked list with links]aws-security-assessment-[DATE]/
README.md
AWS_Security_Assessment_CONSOLIDATED_[DATE].md
regional-reports/
[region-code]/
AWS_Security_Assessment_[region]_[DATE].mdDo not skip, consolidate, or summarize any active regions.
## How to use?
**Prerequisites**
- Active AWS account
- AWS CLI configured with credentials
- Kiro-CLI - [https://kiro.dev/docs/cli/](https://kiro.dev/docs/cli/)
- AWS Well-Architected Security Assessment Tool MCP Server (install separately; not bundled with this plugin) - [https://github.com/awslabs/mcp/tree/main/src/well-architected-security-mcp-server](https://github.com/awslabs/mcp/tree/main/src/well-architected-security-mcp-server)This file