AWS Security ChangesHomeSearch

AWS config medium security documentation change

Service: config · 2025-10-01 · Security-related medium

File: config/latest/developerguide/managing-rules-by-region-availability.md

Summary

Added multiple new AWS Config managed rules to the documentation, including rules related to access logging, resource tagging, deployment strategies, security configurations, and service health checks.

Security assessment

Several added rules explicitly address security controls: 'apigateway-stage-access-logs-enabled' enforces access logging (auditing), 'lightsail-bucket-allow-public-overrides-disabled' prevents public bucket overrides (data exposure risk), 'cognito-identity-pool-unauthenticated-logins' relates to authentication controls, and 'ec2-imdsv2-check' enforces Instance Metadata Service v2 (mitigates SSRF vulnerabilities). These directly impact security posture.

Diff

diff --git a/config/latest/developerguide/managing-rules-by-region-availability.md b/config/latest/developerguide/managing-rules-by-region-availability.md
index 20c05db35..5669b4c46 100644
--- a//config/latest/developerguide/managing-rules-by-region-availability.md
+++ b//config/latest/developerguide/managing-rules-by-region-availability.md
@@ -50,0 +51,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [apigateway-stage-access-logs-enabled](./apigateway-stage-access-logs-enabled.html)
+
@@ -80,0 +83,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [appconfig-deployment-strategy-minimum-final-bake-time](./appconfig-deployment-strategy-minimum-final-bake-time.html)
+
@@ -94,0 +99,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [appflow-flow-trigger-type-check](./appflow-flow-trigger-type-check.html)
+
@@ -110,0 +117,4 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [appmesh-virtual-node-cloud-map-ip-pref-check](./appmesh-virtual-node-cloud-map-ip-pref-check.html)
+
+  * [appmesh-virtual-node-dns-ip-pref-check](./appmesh-virtual-node-dns-ip-pref-check.html)
+
@@ -124,0 +135,4 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [apprunner-service-ip-address-type-check](./apprunner-service-ip-address-type-check.html)
+
+  * [apprunner-service-max-unhealthy-threshold](./apprunner-service-max-unhealthy-threshold.html)
+
@@ -144,0 +159,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [aps-rule-groups-namespace-tagged](./aps-rule-groups-namespace-tagged.html)
+
@@ -158,0 +175,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [auditmanager-assessment-tagged](./auditmanager-assessment-tagged.html)
+
@@ -206,0 +225,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [batch-managed-compute-env-allocation-strategy-check](./batch-managed-compute-env-allocation-strategy-check.html)
+
@@ -208,0 +229,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [batch-managed-spot-compute-environment-max-bid](./batch-managed-spot-compute-environment-max-bid.html)
+
@@ -290,0 +313,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [cognito-identity-pool-unauthenticated-logins](./cognito-identity-pool-unauthenticated-logins.html)
+
@@ -444,0 +469,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [ec2-network-insights-analysis-tagged](./ec2-network-insights-analysis-tagged.html)
+
@@ -560,0 +587,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [eks-fargate-profile-tagged](./eks-fargate-profile-tagged.html)
+
@@ -698,0 +727,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [glue-ml-transform-tagged](./glue-ml-transform-tagged.html)
+
@@ -790,0 +821,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [iot-scheduled-audit-tagged](./iot-scheduled-audit-tagged.html)
+
@@ -796,0 +829,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [kinesis-video-stream-minimum-data-retention](./kinesis-video-stream-minimum-data-retention.html)
+
@@ -816,0 +851,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [lightsail-bucket-allow-public-overrides-disabled](./lightsail-bucket-allow-public-overrides-disabled.html)
+
@@ -1050,0 +1087,10 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [route53-resolver-firewall-domain-list-tagged](./route53-resolver-firewall-domain-list-tagged.html)
+
+  * [route53-resolver-firewall-rule-group-association-tagged](./route53-resolver-firewall-rule-group-association-tagged.html)
+
+  * [route53-resolver-firewall-rule-group-tagged](./route53-resolver-firewall-rule-group-tagged.html)
+
+  * [route53-resolver-resolver-rule-tagged](./route53-resolver-resolver-rule-tagged.html)
+
+  * [rum-app-monitor-tagged](./rum-app-monitor-tagged.html)
+
@@ -1289,0 +1336,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [apigateway-stage-access-logs-enabled](./apigateway-stage-access-logs-enabled.html)
+
@@ -1319,0 +1368,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [appconfig-deployment-strategy-minimum-final-bake-time](./appconfig-deployment-strategy-minimum-final-bake-time.html)
+
@@ -1333,0 +1384,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [appflow-flow-trigger-type-check](./appflow-flow-trigger-type-check.html)
+
@@ -1353,0 +1406,4 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [appmesh-virtual-node-cloud-map-ip-pref-check](./appmesh-virtual-node-cloud-map-ip-pref-check.html)
+
+  * [appmesh-virtual-node-dns-ip-pref-check](./appmesh-virtual-node-dns-ip-pref-check.html)
+
@@ -1367,0 +1424,4 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [apprunner-service-ip-address-type-check](./apprunner-service-ip-address-type-check.html)
+
+  * [apprunner-service-max-unhealthy-threshold](./apprunner-service-max-unhealthy-threshold.html)
+
@@ -1391,0 +1452,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [aps-rule-groups-namespace-tagged](./aps-rule-groups-namespace-tagged.html)
+
@@ -1405,0 +1468,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [auditmanager-assessment-tagged](./auditmanager-assessment-tagged.html)
+
@@ -1453,0 +1518,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [batch-managed-compute-env-allocation-strategy-check](./batch-managed-compute-env-allocation-strategy-check.html)
+
@@ -1455,0 +1522,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [batch-managed-spot-compute-environment-max-bid](./batch-managed-spot-compute-environment-max-bid.html)
+
@@ -1567,0 +1636,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [cognito-identity-pool-unauthenticated-logins](./cognito-identity-pool-unauthenticated-logins.html)
+
@@ -1575,0 +1646,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [customerprofiles-domain-tagged](./customerprofiles-domain-tagged.html)
+
@@ -1727,0 +1800,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [ec2-network-insights-analysis-tagged](./ec2-network-insights-analysis-tagged.html)
+
@@ -1847,0 +1922,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [eks-fargate-profile-tagged](./eks-fargate-profile-tagged.html)
+
@@ -1985,0 +2062,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [glue-ml-transform-tagged](./glue-ml-transform-tagged.html)
+
@@ -2101,0 +2180,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [iot-scheduled-audit-tagged](./iot-scheduled-audit-tagged.html)
+
@@ -2115,0 +2196,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [kinesis-video-stream-minimum-data-retention](./kinesis-video-stream-minimum-data-retention.html)
+
@@ -2135,0 +2218,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [lightsail-bucket-allow-public-overrides-disabled](./lightsail-bucket-allow-public-overrides-disabled.html)
+
@@ -2377,0 +2462,10 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [route53-resolver-firewall-domain-list-tagged](./route53-resolver-firewall-domain-list-tagged.html)
+
+  * [route53-resolver-firewall-rule-group-association-tagged](./route53-resolver-firewall-rule-group-association-tagged.html)
+
+  * [route53-resolver-firewall-rule-group-tagged](./route53-resolver-firewall-rule-group-tagged.html)
+
+  * [route53-resolver-resolver-rule-tagged](./route53-resolver-resolver-rule-tagged.html)
+
+  * [rum-app-monitor-tagged](./rum-app-monitor-tagged.html)
+
@@ -2638,0 +2733,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [apigateway-stage-access-logs-enabled](./apigateway-stage-access-logs-enabled.html)
+
@@ -2668,0 +2765,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [appconfig-deployment-strategy-minimum-final-bake-time](./appconfig-deployment-strategy-minimum-final-bake-time.html)
+
@@ -2682,0 +2781,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [appflow-flow-trigger-type-check](./appflow-flow-trigger-type-check.html)
+
@@ -2698,0 +2799,4 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [appmesh-virtual-node-cloud-map-ip-pref-check](./appmesh-virtual-node-cloud-map-ip-pref-check.html)
+
+  * [appmesh-virtual-node-dns-ip-pref-check](./appmesh-virtual-node-dns-ip-pref-check.html)
+
@@ -2734,0 +2839,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [auditmanager-assessment-tagged](./auditmanager-assessment-tagged.html)
+
@@ -2782,0 +2889,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [batch-managed-compute-env-allocation-strategy-check](./batch-managed-compute-env-allocation-strategy-check.html)
+
@@ -2784,0 +2893,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [batch-managed-spot-compute-environment-max-bid](./batch-managed-spot-compute-environment-max-bid.html)
+
@@ -2862,0 +2973,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [cognito-identity-pool-unauthenticated-logins](./cognito-identity-pool-unauthenticated-logins.html)
+
@@ -3002,0 +3115,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [ec2-network-insights-analysis-tagged](./ec2-network-insights-analysis-tagged.html)
+
@@ -3120,0 +3235,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [eks-fargate-profile-tagged](./eks-fargate-profile-tagged.html)
+
@@ -3238,0 +3355,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [glue-ml-transform-tagged](./glue-ml-transform-tagged.html)
+
@@ -3312,0 +3431,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [iot-scheduled-audit-tagged](./iot-scheduled-audit-tagged.html)
+
@@ -3564,0 +3685,10 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [route53-resolver-firewall-domain-list-tagged](./route53-resolver-firewall-domain-list-tagged.html)
+
+  * [route53-resolver-firewall-rule-group-association-tagged](./route53-resolver-firewall-rule-group-association-tagged.html)
+
+  * [route53-resolver-firewall-rule-group-tagged](./route53-resolver-firewall-rule-group-tagged.html)
+
+  * [route53-resolver-resolver-rule-tagged](./route53-resolver-resolver-rule-tagged.html)
+
+  * [rum-app-monitor-tagged](./rum-app-monitor-tagged.html)
+
@@ -3801,0 +3932,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [apigateway-stage-access-logs-enabled](./apigateway-stage-access-logs-enabled.html)
+
@@ -3831,0 +3964,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [appconfig-deployment-strategy-minimum-final-bake-time](./appconfig-deployment-strategy-minimum-final-bake-time.html)
+
@@ -3845,0 +3980,2 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [appflow-flow-trigger-type-check](./appflow-flow-trigger-type-check.html)
+
@@ -3865,0 +4002,4 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [appmesh-virtual-node-cloud-map-ip-pref-check](./appmesh-virtual-node-cloud-map-ip-pref-check.html)
+
+  * [appmesh-virtual-node-dns-ip-pref-check](./appmesh-virtual-node-dns-ip-pref-check.html)
+
@@ -3879,0 +4020,4 @@ AWS Config currently supports the following managed rules. Before using these ru
+  * [apprunner-service-ip-address-type-check](./apprunner-service-ip-address-type-check.html)
+
+  * [apprunner-service-max-unhealthy-threshold](./apprunner-service-max-unhealthy-threshold.html)