AWS govcloud-us medium security documentation change
Summary
Restructured and expanded documentation about AMS Accelerate limitations in AWS GovCloud (US) Regions. Added detailed lists of unavailable features, differences in features, and other service-specific limitations.
Security assessment
The change documents missing security features including Amazon Macie, Route 53 DNS firewall monitoring, Trusted Remediator, and GuardDuty differences. While not fixing a vulnerability, it highlights security capability gaps in GovCloud environments that could impact security posture.
Diff
diff --git a/govcloud-us/latest/UserGuide/govcloud-ams-acc.md b/govcloud-us/latest/UserGuide/govcloud-ams-acc.md index 25fc08407..1128cbffb 100644 --- a//govcloud-us/latest/UserGuide/govcloud-ams-acc.md +++ b//govcloud-us/latest/UserGuide/govcloud-ams-acc.md @@ -17 +17,35 @@ The following differences apply to AMS Accelerate: -Some services available in other AWS Regions are not available or have limitations. * Not supported in AWS GovCloud (US) Regions: + * The following features are not available in AWS GovCloud (US) Regions: + + * [Amazon Macie](https://docs.aws.amazon.com/macie/latest/user/what-is-macie.html) + + * [Self-service reporting](https://docs.aws.amazon.com/managedservices/latest/accelerate-guide/self-service-reporting.html) \- Patch and Backup daily reports are available. All other self-service reports are not available. + + * [Enable AMS to use your own CloudTrail trail](https://docs.aws.amazon.com/managedservices/latest/accelerate-guide/acc-onb-trail-choices.html) + + * [Cost optimization with AMS Resource Scheduler](https://docs.aws.amazon.com/managedservices/latest/accelerate-guide/acc-resource-scheduler.html) + + * [Customer-provided tags](https://docs.aws.amazon.com/managedservices/latest/accelerate-guide/acc-tag-cust-provided.html) + + * [Amazon Route 53 DNS firewall event monitoring in Service Incident Response](https://docs.aws.amazon.com/managedservices/latest/accelerate-guide/security-incident-response.html) + + * [Trusted Remediator](https://docs.aws.amazon.com/managedservices/latest/accelerate-guide/trusted-remediator.html) + + * [Amazon Route 53 Resolver DNS Firewall](https://docs.aws.amazon.com/managedservices/latest/accelerate-guide/acc-sec-data-protect.html#acc-sec-data-protect-r53) + + * [Monitoring and Incident Management for Amazon EKS](https://docs.aws.amazon.com/managedservices/latest/accelerate-guide/acc-what-is-mon-inc-eks.html) + + * [AWS Config periodic recording for the AWS::EC2::Instance resource type](https://docs.aws.amazon.com/managedservices/latest/accelerate-guide/acc-sec-compliance.html#acc-sec-compliance-reduct-config-spend) + + * [Application aware incident notifications in AMS](https://docs.aws.amazon.com/managedservices/latest/accelerate-guide/app-aware-inc-notifications.html) + + * The following features differ in AWS GovCloud (US) Regions: + + * Outbound [Service notifications](https://docs.aws.amazon.com/managedservices/latest/accelerate-guide/service-notices.html) are not sent to AWS account primary emails. Reports go to smaller, more targeted lists. + + * Accelerate [Compliance and conformance](https://docs.aws.amazon.com/managedservices/latest/accelerate-guide/acc-sec-compliance.html) is limited by the AWS Config managed rules available in your AWS Region. + + * Other AWS service differences that affect AMS Accelerate: + + * Not all [AWS Config in AWS GovCloud (US)](./govcloud-config.html) managed rules are available in all Regions. The [Developer Guide](https://docs.aws.amazon.com/config/latest/developerguide/managed-rules-by-aws-config.html) lists all managed rules, and the applicable Regions for each rule. + + * GuardDuty: For information about the differences in AWS GovCloud (US) Regions, see [Amazon GuardDuty in AWS GovCloud (US)](./govcloud-guardduty.html). @@ -19 +52,0 @@ Some services available in other AWS Regions are not available or have limitatio -\+ **[Amazon Macie](https://docs.aws.amazon.com/macie/latest/user/what-is-macie.html) ** [Self-service reporting](https://docs.aws.amazon.com/managedservices/latest/accelerate-guide/self-service-reporting.html) \- Patch and Backup daily reports are available. All other self-service reports are not available. **[Enable AMS to use your own CloudTrail trail](https://docs.aws.amazon.com/managedservices/latest/accelerate-guide/acc-onb-trail-choices.html) ** [Cost optimization with AMS Resource Scheduler](https://docs.aws.amazon.com/managedservices/latest/accelerate-guide/acc-resource-scheduler.html) **[Customer-provided tags](https://docs.aws.amazon.com/managedservices/latest/accelerate-guide/acc-tag-cust-provided.html) ** [Amazon Route 53 DNS firewall event monitoring in Service Incident Response](https://docs.aws.amazon.com/managedservices/latest/accelerate-guide/security-incident-response.html) **[Trusted Remediator](https://docs.aws.amazon.com/managedservices/latest/accelerate-guide/trusted-remediator.html) ** [Amazon Route 53 Resolver DNS Firewall](https://docs.aws.amazon.com/managedservices/latest/accelerate-guide/acc-sec-data-protect.html#acc-sec-data-protect-r53) **[Monitoring and Incident Management for Amazon EKS](https://docs.aws.amazon.com/managedservices/latest/accelerate-guide/acc-what-is-mon-inc-eks.html) ** [AWS Config periodic recording for the AWS::EC2::Instance resource type](https://docs.aws.amazon.com/managedservices/latest/accelerate-guide/acc-sec-compliance.html#acc-sec-compliance-reduct-config-spend) ** [Application aware incident notifications in AMS](https://docs.aws.amazon.com/managedservices/latest/accelerate-guide/app-aware-inc-notifications.html) * Different in AWS GovCloud (US) Regions: @@ -21 +53,0 @@ Some services available in other AWS Regions are not available or have limitatio -\+ **Outbound[Service notifications](https://docs.aws.amazon.com/managedservices/latest/accelerate-guide/service-notices.html) are not sent to AWS account primary emails. Reports go to smaller, more targeted lists. ** Accelerate [Compliance and conformance](https://docs.aws.amazon.com/managedservices/latest/accelerate-guide/acc-sec-compliance.html) is limited by the AWS Config managed rules available in your AWS Region. * Differences in other AWS services. Some examples: @@ -23 +54,0 @@ Some services available in other AWS Regions are not available or have limitatio -\+ **Not all[AWS Config in AWS GovCloud (US)](./govcloud-config.html) managed rules are available in all Regions. The [Developer Guide](https://docs.aws.amazon.com/config/latest/developerguide/managed-rules-by-aws-config.html) lists all managed rules, and the applicable Regions for each rule. ** GuardDuty: For information about the differences in AWS GovCloud (US) Regions, see [Amazon GuardDuty in AWS GovCloud (US)](./govcloud-guardduty.html).