AWS Security ChangesHomeSearch

AWS securityhub high security documentation change

Service: securityhub · 2025-12-10 · Security-related high

File: securityhub/latest/userguide/fsbp-standard.md

Summary

Added new controls for CloudFormation termination protection, Cognito threat protection/MFA/deletion protection, EC2 EBS snapshot public access prevention, ECS in-transit encryption, and SES email TLS

Security assessment

The change adds documentation for 6 new security controls covering critical security features: resource deletion protection (CloudFormation/Cognito), MFA enforcement (Cognito), threat detection (Cognito), public access prevention (EC2 EBS), encryption in transit (ECS), and email security (SES TLS). These directly address security vulnerabilities like unauthorized deletions, account compromise, data exposure, and unencrypted communications.

Diff

diff --git a/securityhub/latest/userguide/fsbp-standard.md b/securityhub/latest/userguide/fsbp-standard.md
index c684c7472..2a04b5cd9 100644
--- a//securityhub/latest/userguide/fsbp-standard.md
+++ b//securityhub/latest/userguide/fsbp-standard.md
@@ -60,0 +61,2 @@ The following list specifies which AWS Security Hub CSPM controls apply to the A
+[[CloudFormation.3] CloudFormation stacks should have termination protection enabled](./cloudformation-controls.html#cloudformation-3)
+
@@ -108,0 +111,6 @@ The following list specifies which AWS Security Hub CSPM controls apply to the A
+[[Cognito.4] Cognito user pools should have threat protection activated with full function enforcement mode for custom authentication](./cognito-controls.html#cognito-4)
+
+[[Cognito.5] MFA should be enabled for Cognito user pools](./cognito-controls.html#cognito-5)
+
+[[Cognito.6] Cognito user pools should have deletion protection enabled](./cognito-controls.html#cognito-6)
+
@@ -218,0 +227,2 @@ The following list specifies which AWS Security Hub CSPM controls apply to the A
+[[EC2.182] Amazon EBS Snapshots should not be publicly accessible ](./ec2-controls.html#ec2-182)
+
@@ -244,0 +255,2 @@ The following list specifies which AWS Security Hub CSPM controls apply to the A
+[[ECS.18] ECS Task Definitions should use in-transit encryption for EFS volumes](./ecs-controls.html#ecs-18)
+
@@ -642,0 +655,2 @@ The following list specifies which AWS Security Hub CSPM controls apply to the A
+[[SES.3] SES configuration sets should have TLS enabled for sending emails](./ses-controls.html#ses-3)
+