AWS config medium security documentation change
Summary
Added documentation for updated AWSConfigServiceRolePolicy and AWS_ConfigRole policies
Security assessment
Documents expanded IAM policy permissions for configuration recording across 100+ AWS services including security, networking, and compute services. This directly relates to security posture management through enhanced monitoring capabilities. The policies govern access to security-sensitive resources.
Diff
diff --git a/config/latest/developerguide/security-iam-awsmanpol.md b/config/latest/developerguide/security-iam-awsmanpol.md index a03fabd20..e5ff4731e 100644 --- a//config/latest/developerguide/security-iam-awsmanpol.md +++ b//config/latest/developerguide/security-iam-awsmanpol.md @@ -179,0 +180,2 @@ Change | Description | Date +AWSConfigServiceRolePolicy – Updated managed policy with comprehensive permissions for AWS resource configuration recording across over 100 AWS services including compute, storage, networking, security, analytics, and machine learning services. | This policy now provides enhanced documentation of service permissions and supports comprehensive monitoring across all AWS services that AWS Config supports for configuration recording. | January 27, 2026 +AWS_ConfigRole – Updated managed policy with comprehensive permissions for AWS resource configuration recording across over 100 AWS services including compute, storage, networking, security, analytics, and machine learning services. | This policy now provides enhanced documentation of service permissions and supports comprehensive monitoring across all AWS services that AWS Config supports for configuration recording. | January 27, 2026