Skip to main content

Claude/ChatGPT Prompt to Run an AWS Security Best-Practices Audit

Run an AWS security audit: review IAM, MFA, key rotation, network, encryption, and logging, then close CIS AWS Foundations Benchmark gaps with least-privilege.

Fill in the placeholders

Edit the values, then copy your finished prompt.

Your Prompt
prompt.txt

                                

What this prompt does

This prompt runs the AI through a structured AWS security audit across an estate of [account_count] accounts. It moves in sequence through IAM, network security, encryption, logging, compliance, detective controls, and secrets management, then closes with a prioritized remediation plan. You point it at your [iam_concerns], [network_issues], and [encryption_scope], and it surfaces the usual exposure points — root account usage, missing MFA, stale access keys, overly permissive policies, and public resources that should be private.

The structure works because walking each domain in order keeps an audit from collapsing into an unactionable wall of findings. It generates least-privilege policy replacements for [critical_roles], checks against your [compliance_framework] with a gap analysis, and recommends GuardDuty, Security Hub, and Config rules for [config_rules]. The closing remediation plan ranks issues with effort estimates, which is what makes the output something a team can actually work through rather than file and forget.

When to use it

  • You inherited an AWS account and need to know where the real exposure is before anything else
  • You suspect IAM sprawl — developers with AdministratorAccess or service roles that are over-permissioned
  • You need least-privilege policy replacements drafted for [critical_roles]
  • You want a gap analysis against [compliance_framework] such as the CIS AWS Foundations Benchmark
  • You need to confirm CloudTrail, VPC flow logs, and centralized logging to [log_destination] are in place
  • You are scanning for hardcoded credentials across [code_locations] and Lambda environment variables

Example output

Expect a sectioned audit report: IAM findings with proposed least-privilege policies for your critical roles, a network review of security groups and NACLs, an encryption audit across data at rest and in transit, a logging-coverage check, a compliance gap analysis against your chosen framework, detective-control recommendations, and a closing remediation plan that ranks every finding by priority with effort estimates.

Pro tips

  • Be candid in [iam_concerns] — admitting that several developers hold AdministratorAccess produces far more useful findings than a sanitized description
  • Name your real [critical_roles] so the least-privilege replacements target the policies that actually matter, like CI/CD and Lambda execution roles
  • Set [compliance_framework] to the exact version you are measured against; CIS v3.0 controls differ from earlier revisions
  • The model cannot scan your live account, so it produces a checklist and policy drafts you must verify against actual IAM, Config, and CloudTrail state
  • Treat generated least-privilege policies as starting points — test them in a non-production role before applying, since over-tightening can break deployments
  • Work the remediation plan top-down by priority and effort rather than trying to fix everything at once; the ranking exists to sequence the work
  • Confirm CloudTrail is enabled in every region, not just your active ones, since attackers often operate in regions you never use
  • Re-run the audit after remediation so the gap analysis against [compliance_framework] reflects your hardened state, not the original findings

Frequently Asked Questions

Can this prompt actually scan my AWS account for vulnerabilities?
No. It cannot connect to your environment, so it produces a structured audit checklist, least-privilege policy drafts, and a remediation plan based on the concerns you describe. You then verify each item against your real IAM, Config, GuardDuty, and CloudTrail state. Pair it with native tooling for live scanning.
Which compliance frameworks does it support?
Whatever you set in `[compliance_framework]`. The default is the CIS AWS Foundations Benchmark, but you can target other frameworks your organization follows. It generates a gap analysis against the controls, though you should confirm the control list matches the exact version you are audited against.
Are the least-privilege policies it generates safe to apply directly?
Use them as starting points, not final policies. The model drafts scoped policies for your `[critical_roles]`, but it cannot see actual runtime access patterns. Test each replacement in a non-production role first, because over-tightening can break deployments or service functions that rely on permissions the draft removed.
How should I prioritize the findings it returns?
Follow the closing remediation plan, which ranks findings by priority with effort estimates. Address high-impact, low-effort items like enabling MFA and rotating keys first, then sequence the harder network and encryption work. The ranking exists precisely so an audit becomes an ordered task list rather than an overwhelming dump.
Engr Mejba Ahmed

Need this built for real?

Engr Mejba Ahmed

AI Developer · Software Engineer

I'm Mejba — I design and ship production AI systems, automations, and full-stack apps. If you want this turned into a working solution for your team, let's talk.

More in AWS & Cloud Architecture Prompts

Engr Mejba Ahmed

Engr Mejba Ahmed

Claude Code Expert · Online

👋

Hey there!

Quick Actions

WhatsApp Instant reply

Chat on WhatsApp

+880 1723 741224 · Instant reply

Popular Questions

Engr Mejba Ahmed is connected
Engr Mejba Ahmed is typing...
Engr Mejba Ahmed avatar

✉ Want me to follow up? Drop your email

Engr Mejba Ahmed avatar

📞 Connect Directly

Choose how you'd like to reach me

WhatsApp

+880 1723 741224

Email

[email protected]

✓ Details sent! I'll get back to you shortly.

Powered by OpenAI

335+

Blog Posts

25

AI Courses

63

Projects

Services & Expertise

Pricing & Process

Learning & Resources

Connect & Support