Verisight Help Center Support ticket Open portal

Connect AWS and run a Security Review

Create a read-only IAM role with one click, choose a permission profile and run the AWS Security Review.

The AWS Security Review uses a read-only cross-account IAM role that you create in your own AWS account. Verisight can assume it only with a secret ExternalId generated for your organization. It can't create, change or delete anything.

1. Choose a permission profile

Both profiles use AWS-managed, read-only policies only:

Profile Policies Trade-off
Standard (default) SecurityAudit Security metadata only. Some deep-scan checks can't run.
Extended SecurityAudit + ViewOnlyAccess The full deep scan. Can also list resource names, such as S3 object names and CloudTrail events, but never object contents.

You can switch profile while setup is pending. You can also upgrade a Standard role later with one attach-role-policy command shown in the portal; the next review uses it automatically.

2. Create the role

Start from Settings → Connectors → AWS, or from the setup card on an AWS assessment.

Option A: one-click CloudFormation (recommended)

  1. Choose Launch stack in AWS. The AWS console opens with every field pre-filled.
  2. Make sure you're signed in to the account you want reviewed.
  3. Tick the IAM acknowledgement and choose Create stack.
  4. When the stack completes, copy RoleArn from its Outputs tab.

Option B: one command

Expand Prefer the CLI?, copy the one-liner and run it in AWS CloudShell or any terminal with admin credentials for the account. It creates the same role and prints its ARN.

3. Connect

Paste the role ARN (arn:aws:iam::123456789012:role/…) and choose Connect and start. If you have already ordered an AWS Security Review, it starts automatically.

If the ARN is wrong, or the stack didn't finish, the review fails with a connector error instead of producing results. Fix the role, then retry the assessment at no extra cost.

What it checks

Core checks:

  • S3 buckets that are publicly accessible, through bucket policies or because Block Public Access is off;
  • security groups that allow inbound traffic from the whole internet;
  • IAM users with console access but no MFA;
  • an account password policy below baseline.

Deep configuration scan: about 660 checks across every AWS service and enabled region. Each failure becomes one finding with the affected resources, the risk, remediation and related CIS, ISO 27001 and NIST CSF controls.

The review also builds your Infrastructure map, showing attack paths such as an internet-exposed instance whose role can reach account-admin.

Removing access

Delete the CloudFormation stack (or the IAM role, if you used the CLI) in your AWS account. Access ends immediately. You can also remove the connection from Connectors.