Overview
This report evaluates AWS cost-management guardrails and resource-hygiene practices that help control avoidable spend, improve lifecycle management, and reduce stale or inefficient infrastructure. It checks organization-wide cost controls alongside resource-level configuration across compute, storage, networking, identity, backup, certificates, and data lifecycle services.
The report helps teams:
- Establish budgets and cost-anomaly notifications
- Improve tagging and lifecycle governance
- Identify inefficient or stale EC2, EBS, ENI, AMI, and IAM configurations
- Validate storage, backup, log-retention, and repository lifecycle policies
- Detect certificate, domain-renewal, and subnet-capacity hygiene risks
Services and Evaluation Criteria
AWS Billing and Organizations
- AWS cost budgets and notifications are defined
- Cost Anomaly Detection monitors and subscriptions are configured
- AWS Organizations tag policies are enabled
Backup, Logging, and Lifecycle Management
- Backup plans include lifecycle policies
- CloudWatch log groups have retention configured
- ECR, EFS, and S3 lifecycle policies are configured
- DLM snapshot lifecycle policies are enabled
Amazon EC2 and VPC
- Attached EBS volumes use delete-on-termination where appropriate
- gp2 volumes are identified for gp3 review
- Previous-generation instance types are identified
- AMIs older than 90 days and unused network interfaces are identified
- VPC subnets retain adequate IP capacity
Identity and Edge Resources
- Unattached IAM policies are identified
- Classic WAF web ACL associations are checked
Certificates and Domains
- Expired DMS certificates are identified
- RDS CA certificate expiry is checked
- Route 53 domain expiration and auto-renewal are checked
Each finding includes the rule and affected-resource details returned by the assessment engine so teams can prioritize cleanup and governance improvements.