Skip to main content

πŸ’Ό [Config.1] AWS Config should be enabled and use the service-linked role for resource recording

  • Contextual name: πŸ’Ό [Config.1] AWS Config should be enabled and use the service-linked role for resource recording

  • ID: /frameworks/aws-fsbp-v1.0.0/config/01

  • Located in: πŸ’Ό Config

Description​

The AWS Config service performs configuration management of supported AWS resources in your account and delivers log files to you. The recorded information includes the configuration item (AWS resource), relationships between configuration items, and any configuration changes within resources. Global resources are resources that are available in any Region.

Similar​

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CM-3 Configuration Change Control81521
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CM-6(1) Configuration Settings _ Automated Management, Application, and Verification1
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CM-8 System Component Inventory91
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CM-8(2) System Component Inventory _ Automated Maintenance1
πŸ’Ό PCI DSS v3.2.1 β†’ πŸ’Ό 10.5.2 Protect audit trail files from unauthorized modifications.24
πŸ’Ό PCI DSS v3.2.1 β†’ πŸ’Ό 11.5 Deploy a change-detection mechanism to alert personnel to unauthorized modification of critical system files, configuration files, or content files.11

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags

Policies (1)​

PolicyLogic CountFlags
πŸ“ AWS Account Config is not enabled in all regions 🟒1🟒 x6