AWS security-ir medium security documentation change
Summary
Expanded case creation scope to include security capability inquiries, added note about GuardDuty/suppression rule questions, updated case type to 'Investigations and Inquiries', and corrected console URL.
Security assessment
The change explicitly adds documentation for security-related inquiries (GuardDuty, suppression rules, proactive response) under the Investigations case type. This clarifies security support channels and capabilities, potentially improving security posture through better utilization of AWS security services.
Diff
diff --git a/security-ir/latest/userguide/create-an-aws-supported-case.md b/security-ir/latest/userguide/create-an-aws-supported-case.md index 92cc68a5f..ea0484504 100644 --- a//security-ir/latest/userguide/create-an-aws-supported-case.md +++ b//security-ir/latest/userguide/create-an-aws-supported-case.md @@ -12,0 +13,4 @@ AWS Security Incident Response engineers will respond to your case within 15 min +###### Note + +You can create AWS supported cases not only for active security incidents and investigations, but also for inquiries about AWS Security Incident Response capabilities. This includes questions about GuardDuty suppression rules, alert triaging configurations, proactive response workflows, and general guidance on security posture. Select the **Investigations and Inquiries** case type for these purposes. + @@ -25 +29 @@ The following example covers use of the console. - 2. **Investigations** : Investigations allow you to get support for perceived security incidents where the AWS Security Incident Response engineers can support in log dive and secondary confirmation of incident response investigation. + 2. **Investigations and Inquiries** : Use this type for perceived security incidents where AWS Security Incident Response engineers can support in log analysis and secondary confirmation of incident response investigation. You can also use this type for inquiries about GuardDuty findings, suppression rules, alert triaging configurations, proactive response workflows, and general security posture questions related to AWS Security Incident Response capabilities. @@ -86 +90 @@ After a AWS supported case has been created, the AWS Security Incident Response - 1. Open the AWS Security Incident Response console at [console.aws.amazon.com/security-ir/](https://docs.aws.amazon.com/console.aws.amazon.com). + 1. Open the AWS Security Incident Response console at [console.aws.amazon.com/](https://console.aws.amazon.com/). @@ -132 +136 @@ Cases -Create a self-managed case +When to contact AWS Security Incident Response