AWS config medium security documentation change
Summary
Added multiple new AWS Config managed rules to the documentation, including rules related to access logging, resource tagging, deployment strategies, security configurations, and service health checks.
Security assessment
Several added rules explicitly address security controls: 'apigateway-stage-access-logs-enabled' enforces access logging (auditing), 'lightsail-bucket-allow-public-overrides-disabled' prevents public bucket overrides (data exposure risk), 'cognito-identity-pool-unauthenticated-logins' relates to authentication controls, and 'ec2-imdsv2-check' enforces Instance Metadata Service v2 (mitigates SSRF vulnerabilities). These directly impact security posture.
Diff
diff --git a/config/latest/developerguide/managing-rules-by-region-availability.md b/config/latest/developerguide/managing-rules-by-region-availability.md index 20c05db35..5669b4c46 100644 --- a//config/latest/developerguide/managing-rules-by-region-availability.md +++ b//config/latest/developerguide/managing-rules-by-region-availability.md @@ -50,0 +51,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [apigateway-stage-access-logs-enabled](./apigateway-stage-access-logs-enabled.html) + @@ -80,0 +83,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [appconfig-deployment-strategy-minimum-final-bake-time](./appconfig-deployment-strategy-minimum-final-bake-time.html) + @@ -94,0 +99,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [appflow-flow-trigger-type-check](./appflow-flow-trigger-type-check.html) + @@ -110,0 +117,4 @@ AWS Config currently supports the following managed rules. Before using these ru + * [appmesh-virtual-node-cloud-map-ip-pref-check](./appmesh-virtual-node-cloud-map-ip-pref-check.html) + + * [appmesh-virtual-node-dns-ip-pref-check](./appmesh-virtual-node-dns-ip-pref-check.html) + @@ -124,0 +135,4 @@ AWS Config currently supports the following managed rules. Before using these ru + * [apprunner-service-ip-address-type-check](./apprunner-service-ip-address-type-check.html) + + * [apprunner-service-max-unhealthy-threshold](./apprunner-service-max-unhealthy-threshold.html) + @@ -144,0 +159,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [aps-rule-groups-namespace-tagged](./aps-rule-groups-namespace-tagged.html) + @@ -158,0 +175,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [auditmanager-assessment-tagged](./auditmanager-assessment-tagged.html) + @@ -206,0 +225,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [batch-managed-compute-env-allocation-strategy-check](./batch-managed-compute-env-allocation-strategy-check.html) + @@ -208,0 +229,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [batch-managed-spot-compute-environment-max-bid](./batch-managed-spot-compute-environment-max-bid.html) + @@ -290,0 +313,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [cognito-identity-pool-unauthenticated-logins](./cognito-identity-pool-unauthenticated-logins.html) + @@ -444,0 +469,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [ec2-network-insights-analysis-tagged](./ec2-network-insights-analysis-tagged.html) + @@ -560,0 +587,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [eks-fargate-profile-tagged](./eks-fargate-profile-tagged.html) + @@ -698,0 +727,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [glue-ml-transform-tagged](./glue-ml-transform-tagged.html) + @@ -790,0 +821,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [iot-scheduled-audit-tagged](./iot-scheduled-audit-tagged.html) + @@ -796,0 +829,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [kinesis-video-stream-minimum-data-retention](./kinesis-video-stream-minimum-data-retention.html) + @@ -816,0 +851,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [lightsail-bucket-allow-public-overrides-disabled](./lightsail-bucket-allow-public-overrides-disabled.html) + @@ -1050,0 +1087,10 @@ AWS Config currently supports the following managed rules. Before using these ru + * [route53-resolver-firewall-domain-list-tagged](./route53-resolver-firewall-domain-list-tagged.html) + + * [route53-resolver-firewall-rule-group-association-tagged](./route53-resolver-firewall-rule-group-association-tagged.html) + + * [route53-resolver-firewall-rule-group-tagged](./route53-resolver-firewall-rule-group-tagged.html) + + * [route53-resolver-resolver-rule-tagged](./route53-resolver-resolver-rule-tagged.html) + + * [rum-app-monitor-tagged](./rum-app-monitor-tagged.html) + @@ -1289,0 +1336,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [apigateway-stage-access-logs-enabled](./apigateway-stage-access-logs-enabled.html) + @@ -1319,0 +1368,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [appconfig-deployment-strategy-minimum-final-bake-time](./appconfig-deployment-strategy-minimum-final-bake-time.html) + @@ -1333,0 +1384,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [appflow-flow-trigger-type-check](./appflow-flow-trigger-type-check.html) + @@ -1353,0 +1406,4 @@ AWS Config currently supports the following managed rules. Before using these ru + * [appmesh-virtual-node-cloud-map-ip-pref-check](./appmesh-virtual-node-cloud-map-ip-pref-check.html) + + * [appmesh-virtual-node-dns-ip-pref-check](./appmesh-virtual-node-dns-ip-pref-check.html) + @@ -1367,0 +1424,4 @@ AWS Config currently supports the following managed rules. Before using these ru + * [apprunner-service-ip-address-type-check](./apprunner-service-ip-address-type-check.html) + + * [apprunner-service-max-unhealthy-threshold](./apprunner-service-max-unhealthy-threshold.html) + @@ -1391,0 +1452,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [aps-rule-groups-namespace-tagged](./aps-rule-groups-namespace-tagged.html) + @@ -1405,0 +1468,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [auditmanager-assessment-tagged](./auditmanager-assessment-tagged.html) + @@ -1453,0 +1518,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [batch-managed-compute-env-allocation-strategy-check](./batch-managed-compute-env-allocation-strategy-check.html) + @@ -1455,0 +1522,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [batch-managed-spot-compute-environment-max-bid](./batch-managed-spot-compute-environment-max-bid.html) + @@ -1567,0 +1636,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [cognito-identity-pool-unauthenticated-logins](./cognito-identity-pool-unauthenticated-logins.html) + @@ -1575,0 +1646,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [customerprofiles-domain-tagged](./customerprofiles-domain-tagged.html) + @@ -1727,0 +1800,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [ec2-network-insights-analysis-tagged](./ec2-network-insights-analysis-tagged.html) + @@ -1847,0 +1922,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [eks-fargate-profile-tagged](./eks-fargate-profile-tagged.html) + @@ -1985,0 +2062,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [glue-ml-transform-tagged](./glue-ml-transform-tagged.html) + @@ -2101,0 +2180,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [iot-scheduled-audit-tagged](./iot-scheduled-audit-tagged.html) + @@ -2115,0 +2196,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [kinesis-video-stream-minimum-data-retention](./kinesis-video-stream-minimum-data-retention.html) + @@ -2135,0 +2218,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [lightsail-bucket-allow-public-overrides-disabled](./lightsail-bucket-allow-public-overrides-disabled.html) + @@ -2377,0 +2462,10 @@ AWS Config currently supports the following managed rules. Before using these ru + * [route53-resolver-firewall-domain-list-tagged](./route53-resolver-firewall-domain-list-tagged.html) + + * [route53-resolver-firewall-rule-group-association-tagged](./route53-resolver-firewall-rule-group-association-tagged.html) + + * [route53-resolver-firewall-rule-group-tagged](./route53-resolver-firewall-rule-group-tagged.html) + + * [route53-resolver-resolver-rule-tagged](./route53-resolver-resolver-rule-tagged.html) + + * [rum-app-monitor-tagged](./rum-app-monitor-tagged.html) + @@ -2638,0 +2733,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [apigateway-stage-access-logs-enabled](./apigateway-stage-access-logs-enabled.html) + @@ -2668,0 +2765,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [appconfig-deployment-strategy-minimum-final-bake-time](./appconfig-deployment-strategy-minimum-final-bake-time.html) + @@ -2682,0 +2781,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [appflow-flow-trigger-type-check](./appflow-flow-trigger-type-check.html) + @@ -2698,0 +2799,4 @@ AWS Config currently supports the following managed rules. Before using these ru + * [appmesh-virtual-node-cloud-map-ip-pref-check](./appmesh-virtual-node-cloud-map-ip-pref-check.html) + + * [appmesh-virtual-node-dns-ip-pref-check](./appmesh-virtual-node-dns-ip-pref-check.html) + @@ -2734,0 +2839,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [auditmanager-assessment-tagged](./auditmanager-assessment-tagged.html) + @@ -2782,0 +2889,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [batch-managed-compute-env-allocation-strategy-check](./batch-managed-compute-env-allocation-strategy-check.html) + @@ -2784,0 +2893,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [batch-managed-spot-compute-environment-max-bid](./batch-managed-spot-compute-environment-max-bid.html) + @@ -2862,0 +2973,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [cognito-identity-pool-unauthenticated-logins](./cognito-identity-pool-unauthenticated-logins.html) + @@ -3002,0 +3115,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [ec2-network-insights-analysis-tagged](./ec2-network-insights-analysis-tagged.html) + @@ -3120,0 +3235,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [eks-fargate-profile-tagged](./eks-fargate-profile-tagged.html) + @@ -3238,0 +3355,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [glue-ml-transform-tagged](./glue-ml-transform-tagged.html) + @@ -3312,0 +3431,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [iot-scheduled-audit-tagged](./iot-scheduled-audit-tagged.html) + @@ -3564,0 +3685,10 @@ AWS Config currently supports the following managed rules. Before using these ru + * [route53-resolver-firewall-domain-list-tagged](./route53-resolver-firewall-domain-list-tagged.html) + + * [route53-resolver-firewall-rule-group-association-tagged](./route53-resolver-firewall-rule-group-association-tagged.html) + + * [route53-resolver-firewall-rule-group-tagged](./route53-resolver-firewall-rule-group-tagged.html) + + * [route53-resolver-resolver-rule-tagged](./route53-resolver-resolver-rule-tagged.html) + + * [rum-app-monitor-tagged](./rum-app-monitor-tagged.html) + @@ -3801,0 +3932,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [apigateway-stage-access-logs-enabled](./apigateway-stage-access-logs-enabled.html) + @@ -3831,0 +3964,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [appconfig-deployment-strategy-minimum-final-bake-time](./appconfig-deployment-strategy-minimum-final-bake-time.html) + @@ -3845,0 +3980,2 @@ AWS Config currently supports the following managed rules. Before using these ru + * [appflow-flow-trigger-type-check](./appflow-flow-trigger-type-check.html) + @@ -3865,0 +4002,4 @@ AWS Config currently supports the following managed rules. Before using these ru + * [appmesh-virtual-node-cloud-map-ip-pref-check](./appmesh-virtual-node-cloud-map-ip-pref-check.html) + + * [appmesh-virtual-node-dns-ip-pref-check](./appmesh-virtual-node-dns-ip-pref-check.html) + @@ -3879,0 +4020,4 @@ AWS Config currently supports the following managed rules. Before using these ru + * [apprunner-service-ip-address-type-check](./apprunner-service-ip-address-type-check.html) + + * [apprunner-service-max-unhealthy-threshold](./apprunner-service-max-unhealthy-threshold.html)