🛡️ AWS SNS Topic auto-provisioning status🟢
- Contextual name: 🛡️ SNS Topic auto-provisioning status🟢
- ID:
/ce/ca/automated-provisioning/aws-sns-topic - Tags:
- Policy Type:
COMPLIANCE_POLICY - Policy Categories:
RELIABILITY
Stats
not available
Logic
Description
Description
Identify AWS SNS Topics that appear to be associated with AWS CloudFormation or AWS Service Catalog provisioning.
This policy checks for AWS-managed tag signals that can help identify an SNS topic as associated with AWS CloudFormation or AWS Service Catalog.
Rationale
AWS-managed provisioning tags provide evidence that an SNS topic is associated with a CloudFormation stack or a Service Catalog provisioned product. This allows to distinguish topics with supported AWS-managed provisioning indicators from topics that are not identified by this tag-based method.
Audit
This policy classifies an AWS SNS Topic as identified by automated provisioning evidence when the topic has at least one of the following AWS-managed tag keys:
aws:cloudformation:logical-idaws:cloudformation:stack-idaws:cloudformation:stack-nameaws:servicecatalog:portfolioArnaws:servicecatalog:productArnaws:servicecatalog:provisioningPrincipalArnaws:servicecatalog:provisionedProductArnaws:servicecatalog:provisioningArtifactIdentifier... see more
Remediation
Remediation
Review the SNS topic and confirm its provisioning source.
Validate whether the topic is associated with a CloudFormation stack, a Service Catalog provisioned product, another automation workflow, or a manual process. If the provisioning source is known, document the ownership and lifecycle expectations. If the topic is no longer needed, remove it through the appropriate operational process.