AWS Security ChangesHomeSearch

AWS config high security documentation change

Service: config · 2025-10-01 · Security-related high

File: config/latest/developerguide/managed-rules-by-evaluation-mode.md

Summary

Added multiple new AWS Config managed rules across various services (e.g., API Gateway, AppRunner, Lightsail, Route53 Resolver) and removed some existing rule references

Security assessment

Added security-focused rules like 'lightsail-bucket-allow-public-overrides-disabled' (prevents public bucket access), 'cognito-identity-pool-unauthenticated-logins' (controls unauthenticated access), and Route53 Resolver firewall rules. These enforce security best practices but no explicit mention of patching vulnerabilities.

Diff

diff --git a/config/latest/developerguide/managed-rules-by-evaluation-mode.md b/config/latest/developerguide/managed-rules-by-evaluation-mode.md
index 7ecb9f03d..3ca29557b 100644
--- a//config/latest/developerguide/managed-rules-by-evaluation-mode.md
+++ b//config/latest/developerguide/managed-rules-by-evaluation-mode.md
@@ -19,2 +18,0 @@ Proactive rules do not remediate resources that are flagged as NON_COMPLIANT or
-  * [autoscaling-group-elb-healthcheck-required](./autoscaling-group-elb-healthcheck-required.html)
-
@@ -31,4 +28,0 @@ Proactive rules do not remediate resources that are flagged as NON_COMPLIANT or
-  * [rds-instance-public-access-check](./rds-instance-public-access-check.html)
-
-  * [rds-multi-az-support](./rds-multi-az-support.html)
-
@@ -39,2 +32,0 @@ Proactive rules do not remediate resources that are flagged as NON_COMPLIANT or
-  * [redshift-cluster-public-access-check](./redshift-cluster-public-access-check.html)
-
@@ -93,0 +86,2 @@ Currently, all AWS Config rules support detective evaluation.
+  * [apigateway-stage-access-logs-enabled](./apigateway-stage-access-logs-enabled.html)
+
@@ -123,0 +118,2 @@ Currently, all AWS Config rules support detective evaluation.
+  * [appconfig-deployment-strategy-minimum-final-bake-time](./appconfig-deployment-strategy-minimum-final-bake-time.html)
+
@@ -137,0 +134,2 @@ Currently, all AWS Config rules support detective evaluation.
+  * [appflow-flow-trigger-type-check](./appflow-flow-trigger-type-check.html)
+
@@ -157,0 +156,4 @@ Currently, all AWS Config rules support detective evaluation.
+  * [appmesh-virtual-node-cloud-map-ip-pref-check](./appmesh-virtual-node-cloud-map-ip-pref-check.html)
+
+  * [appmesh-virtual-node-dns-ip-pref-check](./appmesh-virtual-node-dns-ip-pref-check.html)
+
@@ -171,0 +174,4 @@ Currently, all AWS Config rules support detective evaluation.
+  * [apprunner-service-ip-address-type-check](./apprunner-service-ip-address-type-check.html)
+
+  * [apprunner-service-max-unhealthy-threshold](./apprunner-service-max-unhealthy-threshold.html)
+
@@ -195,0 +202,2 @@ Currently, all AWS Config rules support detective evaluation.
+  * [aps-rule-groups-namespace-tagged](./aps-rule-groups-namespace-tagged.html)
+
@@ -209,0 +218,2 @@ Currently, all AWS Config rules support detective evaluation.
+  * [auditmanager-assessment-tagged](./auditmanager-assessment-tagged.html)
+
@@ -257,0 +268,2 @@ Currently, all AWS Config rules support detective evaluation.
+  * [batch-managed-compute-env-allocation-strategy-check](./batch-managed-compute-env-allocation-strategy-check.html)
+
@@ -259,0 +272,2 @@ Currently, all AWS Config rules support detective evaluation.
+  * [batch-managed-spot-compute-environment-max-bid](./batch-managed-spot-compute-environment-max-bid.html)
+
@@ -371,0 +386,2 @@ Currently, all AWS Config rules support detective evaluation.
+  * [cognito-identity-pool-unauthenticated-logins](./cognito-identity-pool-unauthenticated-logins.html)
+
@@ -379,0 +396,2 @@ Currently, all AWS Config rules support detective evaluation.
+  * [customerprofiles-domain-tagged](./customerprofiles-domain-tagged.html)
+
@@ -531,0 +550,2 @@ Currently, all AWS Config rules support detective evaluation.
+  * [ec2-network-insights-analysis-tagged](./ec2-network-insights-analysis-tagged.html)
+
@@ -651,0 +672,2 @@ Currently, all AWS Config rules support detective evaluation.
+  * [eks-fargate-profile-tagged](./eks-fargate-profile-tagged.html)
+
@@ -789,0 +812,2 @@ Currently, all AWS Config rules support detective evaluation.
+  * [glue-ml-transform-tagged](./glue-ml-transform-tagged.html)
+
@@ -905,0 +930,2 @@ Currently, all AWS Config rules support detective evaluation.
+  * [iot-scheduled-audit-tagged](./iot-scheduled-audit-tagged.html)
+
@@ -919,0 +946,2 @@ Currently, all AWS Config rules support detective evaluation.
+  * [kinesis-video-stream-minimum-data-retention](./kinesis-video-stream-minimum-data-retention.html)
+
@@ -939,0 +968,2 @@ Currently, all AWS Config rules support detective evaluation.
+  * [lightsail-bucket-allow-public-overrides-disabled](./lightsail-bucket-allow-public-overrides-disabled.html)
+
@@ -1181,0 +1212,10 @@ Currently, all AWS Config rules support detective evaluation.
+  * [route53-resolver-firewall-domain-list-tagged](./route53-resolver-firewall-domain-list-tagged.html)
+
+  * [route53-resolver-firewall-rule-group-association-tagged](./route53-resolver-firewall-rule-group-association-tagged.html)
+
+  * [route53-resolver-firewall-rule-group-tagged](./route53-resolver-firewall-rule-group-tagged.html)
+
+  * [route53-resolver-resolver-rule-tagged](./route53-resolver-resolver-rule-tagged.html)
+
+  * [rum-app-monitor-tagged](./rum-app-monitor-tagged.html)
+