AWS Security ChangesHomeSearch

AWS config high security documentation change

Service: config · 2025-10-01 · Security-related high

File: config/latest/developerguide/managed-rules-by-trigger-type.md

Summary

Added new change-triggered AWS Config rules mirroring the additions in evaluation-mode.md, including security-related rules for services like Lightsail, Cognito, and Route53 Resolver

Security assessment

Same security-focused rules added as in evaluation-mode.md, including 'lightsail-bucket-allow-public-overrides-disabled' and Route53 Resolver firewall rules. These document security controls but don't reference specific vulnerabilities.

Diff

diff --git a/config/latest/developerguide/managed-rules-by-trigger-type.md b/config/latest/developerguide/managed-rules-by-trigger-type.md
index 40c1007ce..d191d4429 100644
--- a//config/latest/developerguide/managed-rules-by-trigger-type.md
+++ b//config/latest/developerguide/managed-rules-by-trigger-type.md
@@ -42,0 +43,2 @@ _Change-triggered rules_ are rules that AWS Config evaluates in response to conf
+  * [apigateway-stage-access-logs-enabled](./apigateway-stage-access-logs-enabled.html)
+
@@ -70,0 +73,2 @@ _Change-triggered rules_ are rules that AWS Config evaluates in response to conf
+  * [appconfig-deployment-strategy-minimum-final-bake-time](./appconfig-deployment-strategy-minimum-final-bake-time.html)
+
@@ -84,0 +89,2 @@ _Change-triggered rules_ are rules that AWS Config evaluates in response to conf
+  * [appflow-flow-trigger-type-check](./appflow-flow-trigger-type-check.html)
+
@@ -104,0 +111,4 @@ _Change-triggered rules_ are rules that AWS Config evaluates in response to conf
+  * [appmesh-virtual-node-cloud-map-ip-pref-check](./appmesh-virtual-node-cloud-map-ip-pref-check.html)
+
+  * [appmesh-virtual-node-dns-ip-pref-check](./appmesh-virtual-node-dns-ip-pref-check.html)
+
@@ -118,0 +129,4 @@ _Change-triggered rules_ are rules that AWS Config evaluates in response to conf
+  * [apprunner-service-ip-address-type-check](./apprunner-service-ip-address-type-check.html)
+
+  * [apprunner-service-max-unhealthy-threshold](./apprunner-service-max-unhealthy-threshold.html)
+
@@ -138,0 +153,2 @@ _Change-triggered rules_ are rules that AWS Config evaluates in response to conf
+  * [aps-rule-groups-namespace-tagged](./aps-rule-groups-namespace-tagged.html)
+
@@ -152,0 +169,2 @@ _Change-triggered rules_ are rules that AWS Config evaluates in response to conf
+  * [auditmanager-assessment-tagged](./auditmanager-assessment-tagged.html)
+
@@ -190,0 +209,2 @@ _Change-triggered rules_ are rules that AWS Config evaluates in response to conf
+  * [batch-managed-compute-env-allocation-strategy-check](./batch-managed-compute-env-allocation-strategy-check.html)
+
@@ -192,0 +213,2 @@ _Change-triggered rules_ are rules that AWS Config evaluates in response to conf
+  * [batch-managed-spot-compute-environment-max-bid](./batch-managed-spot-compute-environment-max-bid.html)
+
@@ -274,0 +297,2 @@ _Change-triggered rules_ are rules that AWS Config evaluates in response to conf
+  * [cognito-identity-pool-unauthenticated-logins](./cognito-identity-pool-unauthenticated-logins.html)
+
@@ -282,0 +307,2 @@ _Change-triggered rules_ are rules that AWS Config evaluates in response to conf
+  * [customerprofiles-domain-tagged](./customerprofiles-domain-tagged.html)
+
@@ -388,0 +415,2 @@ _Change-triggered rules_ are rules that AWS Config evaluates in response to conf
+  * [ec2-network-insights-analysis-tagged](./ec2-network-insights-analysis-tagged.html)
+
@@ -478,0 +507,2 @@ _Change-triggered rules_ are rules that AWS Config evaluates in response to conf
+  * [eks-fargate-profile-tagged](./eks-fargate-profile-tagged.html)
+
@@ -562,0 +593,2 @@ _Change-triggered rules_ are rules that AWS Config evaluates in response to conf
+  * [glue-ml-transform-tagged](./glue-ml-transform-tagged.html)
+
@@ -632,0 +665,2 @@ _Change-triggered rules_ are rules that AWS Config evaluates in response to conf
+  * [iot-scheduled-audit-tagged](./iot-scheduled-audit-tagged.html)
+
@@ -644,0 +679,2 @@ _Change-triggered rules_ are rules that AWS Config evaluates in response to conf
+  * [kinesis-video-stream-minimum-data-retention](./kinesis-video-stream-minimum-data-retention.html)
+
@@ -662,0 +699,2 @@ _Change-triggered rules_ are rules that AWS Config evaluates in response to conf
+  * [lightsail-bucket-allow-public-overrides-disabled](./lightsail-bucket-allow-public-overrides-disabled.html)
+
@@ -840,0 +879,10 @@ _Change-triggered rules_ are rules that AWS Config evaluates in response to conf
+  * [route53-resolver-firewall-domain-list-tagged](./route53-resolver-firewall-domain-list-tagged.html)
+
+  * [route53-resolver-firewall-rule-group-association-tagged](./route53-resolver-firewall-rule-group-association-tagged.html)
+
+  * [route53-resolver-firewall-rule-group-tagged](./route53-resolver-firewall-rule-group-tagged.html)
+
+  * [route53-resolver-resolver-rule-tagged](./route53-resolver-resolver-rule-tagged.html)
+
+  * [rum-app-monitor-tagged](./rum-app-monitor-tagged.html)
+