Skip to main content

CCC-Complete 0.1

Test results for this specific product, vendor, and version combination

VendorFINOS
ProductCCC-Complete
Version0.1

Download Raw Results

Download the original OCSF or HTML result files used to generate this page

File NameDownload
aws-vpc-cfi-1776044303-vpc-bad
aws-vpc-cfi-1776044303-vpc
aws-vpc-combined
aws-vpc-prowler
aws-vpc-summary

Test Summary

Aggregate summary of all tests for this configuration result

Resources In Configuration2
Count of Tests8
Passing Tests4
Failing Tests4
Catalogs Tested

Control Catalog Summary

Summary of test results grouped by control catalog and resource

Control CatalogResourcesTotal TestsPassingFailingTested RequirementsMissing RequirementsUnused Core Requirements
CCC.VPC
vpc-0232d940ac1e052f...vpc-08d29b9a77c3a193...
844
None

Test Mapping Summary

Summary of test mappings showing how event codes map to test requirements

Control CatalogTest RequirementMapped Tests (Event Code | Total | Passing | Failing)
CCC.VPC
CCC.VPC.CN03.AR01
When a VPC peering connection is requested, the service MUST prevent connections from VPCs that are not explicitly allowed.
Enforcement proof (dry-run): all disallowed requesters are denied against in-scope receiver VPC
422
Enforcement proof (dry-run): non-allowlisted requester is denied even when not explicitly listed as disallowed
422

Resource Summary

Summary of all resources mentioned in OCSF results

Resource NameResource TypeControl CatalogsTotal TestsPassingFailing
vpc-0232d940ac1e052fc
vpc440
vpc-08d29b9a77c3a1931
vpc404

Test Results

OCSF test results filtered for entries with CCC compliance mappings

StatusFindingResource NameResource TypeMessageTest Requirements
FAIL
Enforcement proof (dry-run): all disallowed requesters are denied against in-scope receiver VPC
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I refer to "{UID}" as "ReceiverVpcId" ✓ I refer to "{Cn03NonAllowlistedRequesterVpcId}" as "NonAllowlistedRequesterVpcId" ✓ I load environment variable "CN03_PEER_TRIAL_MATRIX_FILE" as "PeerTrialMatrixFile" ✓ "{ReceiverVpcId}" is not nil ✓ I call "{vpcService}" with "ValidateDisallowListEnforcement" using argument "{ReceiverVpcId}" ✓ I attach "{result.Summary}" to the test output as "Disallow-list Enforcement Summary" ✓ I attach "{result.Results}" to the test output as "Disallow-list Enforcement" ✓ "{result.ListDefined}" is true ✓ "{result.TestedCount}" should be greater than "0" ✗ "{result.AllCorrect}" is true - Error: expected {result.AllCorrect} to be truthy, got false (type: bool) ⊘ "{result.ViolationCount}" is "0" (skipped)
vpc-08d29b9a77c3a1931
vpc
Enforcement proof (dry-run): all disallowed requesters are denied against in-scope receiver VPC
FAIL
Enforcement proof (dry-run): non-allowlisted requester is denied even when not explicitly listed as disallowed
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I refer to "{UID}" as "ReceiverVpcId" ✓ I refer to "{Cn03NonAllowlistedRequesterVpcId}" as "NonAllowlistedRequesterVpcId" ✓ I load environment variable "CN03_PEER_TRIAL_MATRIX_FILE" as "PeerTrialMatrixFile" ✓ "{ReceiverVpcId}" is not nil ✓ "{NonAllowlistedRequesterVpcId}" is not nil ✓ I call "{vpcService}" with "EvaluatePeerAgainstAllowList" using argument "{NonAllowlistedRequesterVpcId}" ✓ "{result.AllowedListDefined}" is true ✓ "{result.Allowed}" is false ✓ I call "{vpcService}" with "AttemptVpcPeeringDryRun" using arguments "{NonAllowlistedRequesterVpcId}" and "{ReceiverVpcId}" ✗ "{result.DryRunAllowed}" is false - Error: expected {result.DryRunAllowed} to be falsy, got true (type: bool) ⊘ "{result.AllowListDefined}" is true (skipped) ⊘ "{result.RequesterInAllowList}" is false (skipped) ⊘ "{result.GuardrailExpectation}" is "deny" (skipped) ⊘ "{result.GuardrailMismatch}" is false (skipped) ⊘ "{result.ExitCode}" should be greater than "0" (skipped) ⊘ "{result.Reason}" contains "guardrail aligned" (skipped) ⊘ "{result.ConflictType}" is "" (skipped)
vpc-08d29b9a77c3a1931
vpc
Enforcement proof (dry-run): non-allowlisted requester is denied even when not explicitly listed as disallowed
PASS
Enforcement proof (dry-run): all disallowed requesters are denied against in-scope receiver VPC
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I refer to "{UID}" as "ReceiverVpcId" ✓ I refer to "{Cn03NonAllowlistedRequesterVpcId}" as "NonAllowlistedRequesterVpcId" ✓ I load environment variable "CN03_PEER_TRIAL_MATRIX_FILE" as "PeerTrialMatrixFile" ✓ "{ReceiverVpcId}" is not nil ✓ I call "{vpcService}" with "ValidateDisallowListEnforcement" using argument "{ReceiverVpcId}" ✓ I attach "{result.Summary}" to the test output as "Disallow-list Enforcement Summary" ✓ I attach "{result.Results}" to the test output as "Disallow-list Enforcement" ✓ "{result.ListDefined}" is true ✓ "{result.TestedCount}" should be greater than "0" ✓ "{result.AllCorrect}" is true ✓ "{result.ViolationCount}" is "0"
vpc-0232d940ac1e052fc
vpc
Enforcement proof (dry-run): all disallowed requesters are denied against in-scope receiver VPC
PASS
Enforcement proof (dry-run): non-allowlisted requester is denied even when not explicitly listed as disallowed
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I refer to "{UID}" as "ReceiverVpcId" ✓ I refer to "{Cn03NonAllowlistedRequesterVpcId}" as "NonAllowlistedRequesterVpcId" ✓ I load environment variable "CN03_PEER_TRIAL_MATRIX_FILE" as "PeerTrialMatrixFile" ✓ "{ReceiverVpcId}" is not nil ✓ "{NonAllowlistedRequesterVpcId}" is not nil ✓ I call "{vpcService}" with "EvaluatePeerAgainstAllowList" using argument "{NonAllowlistedRequesterVpcId}" ✓ "{result.AllowedListDefined}" is true ✓ "{result.Allowed}" is false ✓ I call "{vpcService}" with "AttemptVpcPeeringDryRun" using arguments "{NonAllowlistedRequesterVpcId}" and "{ReceiverVpcId}" ✓ "{result.DryRunAllowed}" is false ✓ "{result.AllowListDefined}" is true ✓ "{result.RequesterInAllowList}" is false ✓ "{result.GuardrailExpectation}" is "deny" ✓ "{result.GuardrailMismatch}" is false ✓ "{result.ExitCode}" should be greater than "0" ✓ "{result.Reason}" contains "guardrail aligned" ✓ "{result.ConflictType}" is ""
vpc-0232d940ac1e052fc
vpc
Enforcement proof (dry-run): non-allowlisted requester is denied even when not explicitly listed as disallowed
FAIL
Enforcement proof (dry-run): all disallowed requesters are denied against in-scope receiver VPC
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I refer to "{UID}" as "ReceiverVpcId" ✓ I refer to "{Cn03NonAllowlistedRequesterVpcId}" as "NonAllowlistedRequesterVpcId" ✓ I load environment variable "CN03_PEER_TRIAL_MATRIX_FILE" as "PeerTrialMatrixFile" ✓ "{ReceiverVpcId}" is not nil ✓ I call "{vpcService}" with "ValidateDisallowListEnforcement" using argument "{ReceiverVpcId}" ✓ I attach "{result.Summary}" to the test output as "Disallow-list Enforcement Summary" ✓ I attach "{result.Results}" to the test output as "Disallow-list Enforcement" ✓ "{result.ListDefined}" is true ✓ "{result.TestedCount}" should be greater than "0" ✗ "{result.AllCorrect}" is true - Error: expected {result.AllCorrect} to be truthy, got false (type: bool) ⊘ "{result.ViolationCount}" is "0" (skipped)
vpc-08d29b9a77c3a1931
vpc
Enforcement proof (dry-run): all disallowed requesters are denied against in-scope receiver VPC
FAIL
Enforcement proof (dry-run): non-allowlisted requester is denied even when not explicitly listed as disallowed
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I refer to "{UID}" as "ReceiverVpcId" ✓ I refer to "{Cn03NonAllowlistedRequesterVpcId}" as "NonAllowlistedRequesterVpcId" ✓ I load environment variable "CN03_PEER_TRIAL_MATRIX_FILE" as "PeerTrialMatrixFile" ✓ "{ReceiverVpcId}" is not nil ✓ "{NonAllowlistedRequesterVpcId}" is not nil ✓ I call "{vpcService}" with "EvaluatePeerAgainstAllowList" using argument "{NonAllowlistedRequesterVpcId}" ✓ "{result.AllowedListDefined}" is true ✓ "{result.Allowed}" is false ✓ I call "{vpcService}" with "AttemptVpcPeeringDryRun" using arguments "{NonAllowlistedRequesterVpcId}" and "{ReceiverVpcId}" ✗ "{result.DryRunAllowed}" is false - Error: expected {result.DryRunAllowed} to be falsy, got true (type: bool) ⊘ "{result.AllowListDefined}" is true (skipped) ⊘ "{result.RequesterInAllowList}" is false (skipped) ⊘ "{result.GuardrailExpectation}" is "deny" (skipped) ⊘ "{result.GuardrailMismatch}" is false (skipped) ⊘ "{result.ExitCode}" should be greater than "0" (skipped) ⊘ "{result.Reason}" contains "guardrail aligned" (skipped) ⊘ "{result.ConflictType}" is "" (skipped)
vpc-08d29b9a77c3a1931
vpc
Enforcement proof (dry-run): non-allowlisted requester is denied even when not explicitly listed as disallowed
PASS
Enforcement proof (dry-run): all disallowed requesters are denied against in-scope receiver VPC
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I refer to "{UID}" as "ReceiverVpcId" ✓ I refer to "{Cn03NonAllowlistedRequesterVpcId}" as "NonAllowlistedRequesterVpcId" ✓ I load environment variable "CN03_PEER_TRIAL_MATRIX_FILE" as "PeerTrialMatrixFile" ✓ "{ReceiverVpcId}" is not nil ✓ I call "{vpcService}" with "ValidateDisallowListEnforcement" using argument "{ReceiverVpcId}" ✓ I attach "{result.Summary}" to the test output as "Disallow-list Enforcement Summary" ✓ I attach "{result.Results}" to the test output as "Disallow-list Enforcement" ✓ "{result.ListDefined}" is true ✓ "{result.TestedCount}" should be greater than "0" ✓ "{result.AllCorrect}" is true ✓ "{result.ViolationCount}" is "0"
vpc-0232d940ac1e052fc
vpc
Enforcement proof (dry-run): all disallowed requesters are denied against in-scope receiver VPC
PASS
Enforcement proof (dry-run): non-allowlisted requester is denied even when not explicitly listed as disallowed
✓ a cloud api for "{Instance}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "vpc" ✓ I refer to "{result}" as "vpcService" ✓ I refer to "{UID}" as "ReceiverVpcId" ✓ I refer to "{Cn03NonAllowlistedRequesterVpcId}" as "NonAllowlistedRequesterVpcId" ✓ I load environment variable "CN03_PEER_TRIAL_MATRIX_FILE" as "PeerTrialMatrixFile" ✓ "{ReceiverVpcId}" is not nil ✓ "{NonAllowlistedRequesterVpcId}" is not nil ✓ I call "{vpcService}" with "EvaluatePeerAgainstAllowList" using argument "{NonAllowlistedRequesterVpcId}" ✓ "{result.AllowedListDefined}" is true ✓ "{result.Allowed}" is false ✓ I call "{vpcService}" with "AttemptVpcPeeringDryRun" using arguments "{NonAllowlistedRequesterVpcId}" and "{ReceiverVpcId}" ✓ "{result.DryRunAllowed}" is false ✓ "{result.AllowListDefined}" is true ✓ "{result.RequesterInAllowList}" is false ✓ "{result.GuardrailExpectation}" is "deny" ✓ "{result.GuardrailMismatch}" is false ✓ "{result.ExitCode}" should be greater than "0" ✓ "{result.Reason}" contains "guardrail aligned" ✓ "{result.ConflictType}" is ""
vpc-0232d940ac1e052fc
vpc
Enforcement proof (dry-run): non-allowlisted requester is denied even when not explicitly listed as disallowed