Skip to content

Amazon Bedrock AI governance security checks

AI assistants, agents and model access inside the tenant — what they can read, who can publish them, and how autonomously they act.

On Amazon Bedrock, Black Cat runs 5 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Amazon Bedrock connector needs.

Checks (5)

severity: high Bedrock Action Group Code Interpreter fix difficulty: medium #

Review if code interpreter capability is necessary

  1. Assess the agent's use case and whether code execution is required
  2. If not needed, disable or remove the code interpreter action group

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: critical Bedrock Action Group Computer Use / Bash fix difficulty: medium #

Remove or restrict computer use and bash execution capabilities

  1. Open AWS Bedrock Console > Agents
  2. Remove the Computer or Bash action group
  3. If required, implement strict guardrails

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: low Bedrock Agent Custom Orchestration fix difficulty: hard #

Review custom orchestration logic for security implications

  1. Review the Lambda function implementing the custom orchestration
  2. Verify input validation and output sanitization

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: medium Bedrock Agent Supervisor Mode fix difficulty: medium #

Review the supervisor's sub-agent delegation and scope

  1. Open AWS Bedrock Console > Agents
  2. Review which sub-agents the supervisor can invoke
  3. Ensure sub-agents follow least-privilege

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: high Bedrock Agent High Risk Unblocked fix difficulty: easy #

Block or restrict high-risk agents with scores above 70

  1. Navigate to AI Agent Governance in SSPM
  2. Review the agent risk factors
  3. Block the agent until risks are mitigated

Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

More Amazon Bedrock checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial