AWS Security ChangesHomeSearch

AWS config high security documentation change

Service: config · 2025-10-01 · Security-related high

File: config/latest/developerguide/managed-rules-by-aws-config.md

Summary

Added multiple new managed rules including security-related controls

Security assessment

Added security-focused rules like 'apigateway-stage-access-logs-enabled', 'lightsail-bucket-allow-public-overrides-disabled', and 'apprunner-service-ip-address-type-check' that directly document security controls

Diff

diff --git a/config/latest/developerguide/managed-rules-by-aws-config.md b/config/latest/developerguide/managed-rules-by-aws-config.md
index bffb5cfa7..aa525100e 100644
--- a//config/latest/developerguide/managed-rules-by-aws-config.md
+++ b//config/latest/developerguide/managed-rules-by-aws-config.md
@@ -48,0 +49,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [apigateway-stage-access-logs-enabled](./apigateway-stage-access-logs-enabled.html)
+
@@ -78,0 +81,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [appconfig-deployment-strategy-minimum-final-bake-time](./appconfig-deployment-strategy-minimum-final-bake-time.html)
+
@@ -92,0 +97,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [appflow-flow-trigger-type-check](./appflow-flow-trigger-type-check.html)
+
@@ -112,0 +119,4 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [appmesh-virtual-node-cloud-map-ip-pref-check](./appmesh-virtual-node-cloud-map-ip-pref-check.html)
+
+  * [appmesh-virtual-node-dns-ip-pref-check](./appmesh-virtual-node-dns-ip-pref-check.html)
+
@@ -126,0 +137,4 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [apprunner-service-ip-address-type-check](./apprunner-service-ip-address-type-check.html)
+
+  * [apprunner-service-max-unhealthy-threshold](./apprunner-service-max-unhealthy-threshold.html)
+
@@ -150,0 +165,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [aps-rule-groups-namespace-tagged](./aps-rule-groups-namespace-tagged.html)
+
@@ -164,0 +181,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [auditmanager-assessment-tagged](./auditmanager-assessment-tagged.html)
+
@@ -212,0 +231,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [batch-managed-compute-env-allocation-strategy-check](./batch-managed-compute-env-allocation-strategy-check.html)
+
@@ -214,0 +235,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [batch-managed-spot-compute-environment-max-bid](./batch-managed-spot-compute-environment-max-bid.html)
+
@@ -326,0 +349,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [cognito-identity-pool-unauthenticated-logins](./cognito-identity-pool-unauthenticated-logins.html)
+
@@ -334,0 +359,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [customerprofiles-domain-tagged](./customerprofiles-domain-tagged.html)
+
@@ -486,0 +513,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [ec2-network-insights-analysis-tagged](./ec2-network-insights-analysis-tagged.html)
+
@@ -606,0 +635,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [eks-fargate-profile-tagged](./eks-fargate-profile-tagged.html)
+
@@ -744,0 +775,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [glue-ml-transform-tagged](./glue-ml-transform-tagged.html)
+
@@ -860,0 +893,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [iot-scheduled-audit-tagged](./iot-scheduled-audit-tagged.html)
+
@@ -874,0 +909,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [kinesis-video-stream-minimum-data-retention](./kinesis-video-stream-minimum-data-retention.html)
+
@@ -894,0 +931,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [lightsail-bucket-allow-public-overrides-disabled](./lightsail-bucket-allow-public-overrides-disabled.html)
+
@@ -1136,0 +1175,10 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [route53-resolver-firewall-domain-list-tagged](./route53-resolver-firewall-domain-list-tagged.html)
+
+  * [route53-resolver-firewall-rule-group-association-tagged](./route53-resolver-firewall-rule-group-association-tagged.html)
+
+  * [route53-resolver-firewall-rule-group-tagged](./route53-resolver-firewall-rule-group-tagged.html)
+
+  * [route53-resolver-resolver-rule-tagged](./route53-resolver-resolver-rule-tagged.html)
+
+  * [rum-app-monitor-tagged](./rum-app-monitor-tagged.html)
+