AWS config high security documentation change
Summary
Added multiple new AWS Config managed rules across various services (e.g., API Gateway, AppRunner, Lightsail, Route53 Resolver) and removed some existing rule references
Security assessment
Added security-focused rules like 'lightsail-bucket-allow-public-overrides-disabled' (prevents public bucket access), 'cognito-identity-pool-unauthenticated-logins' (controls unauthenticated access), and Route53 Resolver firewall rules. These enforce security best practices but no explicit mention of patching vulnerabilities.
Diff
diff --git a/config/latest/developerguide/managed-rules-by-evaluation-mode.md b/config/latest/developerguide/managed-rules-by-evaluation-mode.md index 7ecb9f03d..3ca29557b 100644 --- a//config/latest/developerguide/managed-rules-by-evaluation-mode.md +++ b//config/latest/developerguide/managed-rules-by-evaluation-mode.md @@ -19,2 +18,0 @@ Proactive rules do not remediate resources that are flagged as NON_COMPLIANT or - * [autoscaling-group-elb-healthcheck-required](./autoscaling-group-elb-healthcheck-required.html) - @@ -31,4 +28,0 @@ Proactive rules do not remediate resources that are flagged as NON_COMPLIANT or - * [rds-instance-public-access-check](./rds-instance-public-access-check.html) - - * [rds-multi-az-support](./rds-multi-az-support.html) - @@ -39,2 +32,0 @@ Proactive rules do not remediate resources that are flagged as NON_COMPLIANT or - * [redshift-cluster-public-access-check](./redshift-cluster-public-access-check.html) - @@ -93,0 +86,2 @@ Currently, all AWS Config rules support detective evaluation. + * [apigateway-stage-access-logs-enabled](./apigateway-stage-access-logs-enabled.html) + @@ -123,0 +118,2 @@ Currently, all AWS Config rules support detective evaluation. + * [appconfig-deployment-strategy-minimum-final-bake-time](./appconfig-deployment-strategy-minimum-final-bake-time.html) + @@ -137,0 +134,2 @@ Currently, all AWS Config rules support detective evaluation. + * [appflow-flow-trigger-type-check](./appflow-flow-trigger-type-check.html) + @@ -157,0 +156,4 @@ Currently, all AWS Config rules support detective evaluation. + * [appmesh-virtual-node-cloud-map-ip-pref-check](./appmesh-virtual-node-cloud-map-ip-pref-check.html) + + * [appmesh-virtual-node-dns-ip-pref-check](./appmesh-virtual-node-dns-ip-pref-check.html) + @@ -171,0 +174,4 @@ Currently, all AWS Config rules support detective evaluation. + * [apprunner-service-ip-address-type-check](./apprunner-service-ip-address-type-check.html) + + * [apprunner-service-max-unhealthy-threshold](./apprunner-service-max-unhealthy-threshold.html) + @@ -195,0 +202,2 @@ Currently, all AWS Config rules support detective evaluation. + * [aps-rule-groups-namespace-tagged](./aps-rule-groups-namespace-tagged.html) + @@ -209,0 +218,2 @@ Currently, all AWS Config rules support detective evaluation. + * [auditmanager-assessment-tagged](./auditmanager-assessment-tagged.html) + @@ -257,0 +268,2 @@ Currently, all AWS Config rules support detective evaluation. + * [batch-managed-compute-env-allocation-strategy-check](./batch-managed-compute-env-allocation-strategy-check.html) + @@ -259,0 +272,2 @@ Currently, all AWS Config rules support detective evaluation. + * [batch-managed-spot-compute-environment-max-bid](./batch-managed-spot-compute-environment-max-bid.html) + @@ -371,0 +386,2 @@ Currently, all AWS Config rules support detective evaluation. + * [cognito-identity-pool-unauthenticated-logins](./cognito-identity-pool-unauthenticated-logins.html) + @@ -379,0 +396,2 @@ Currently, all AWS Config rules support detective evaluation. + * [customerprofiles-domain-tagged](./customerprofiles-domain-tagged.html) + @@ -531,0 +550,2 @@ Currently, all AWS Config rules support detective evaluation. + * [ec2-network-insights-analysis-tagged](./ec2-network-insights-analysis-tagged.html) + @@ -651,0 +672,2 @@ Currently, all AWS Config rules support detective evaluation. + * [eks-fargate-profile-tagged](./eks-fargate-profile-tagged.html) + @@ -789,0 +812,2 @@ Currently, all AWS Config rules support detective evaluation. + * [glue-ml-transform-tagged](./glue-ml-transform-tagged.html) + @@ -905,0 +930,2 @@ Currently, all AWS Config rules support detective evaluation. + * [iot-scheduled-audit-tagged](./iot-scheduled-audit-tagged.html) + @@ -919,0 +946,2 @@ Currently, all AWS Config rules support detective evaluation. + * [kinesis-video-stream-minimum-data-retention](./kinesis-video-stream-minimum-data-retention.html) + @@ -939,0 +968,2 @@ Currently, all AWS Config rules support detective evaluation. + * [lightsail-bucket-allow-public-overrides-disabled](./lightsail-bucket-allow-public-overrides-disabled.html) + @@ -1181,0 +1212,10 @@ Currently, all AWS Config rules support detective evaluation. + * [route53-resolver-firewall-domain-list-tagged](./route53-resolver-firewall-domain-list-tagged.html) + + * [route53-resolver-firewall-rule-group-association-tagged](./route53-resolver-firewall-rule-group-association-tagged.html) + + * [route53-resolver-firewall-rule-group-tagged](./route53-resolver-firewall-rule-group-tagged.html) + + * [route53-resolver-resolver-rule-tagged](./route53-resolver-resolver-rule-tagged.html) + + * [rum-app-monitor-tagged](./rum-app-monitor-tagged.html) +