AWS Config Rules
AWS Config rules are foundational for enforcing security and compliance standards across AWS resources. By defining rules that evaluate resource configurations, you can detect deviations from desired states, such as misconfigured security groups or unauthorized resource tagging. This section explains how to create custom AWS Config rules, leveraging both managed rules for common security policies and custom logic for tailored compliance requirements.
Creating Custom AWS Config Rules¶
Custom rules allow you to define specific compliance checks using AWS Lambda functions. These rules are ideal for enforcing unique organizational policies or complex security requirements.
Step-by-Step Process¶
- Design the Evaluation Logic: Write a Lambda function that checks resource properties against your compliance criteria. For example, a rule might verify that all EC2 instances have a specific tag.
- Deploy the Lambda Function: Package and upload the function to AWS Lambda, ensuring it has the necessary IAM permissions to access AWS resources.
- Create the Config Rule: Use the AWS Management Console, CLI, or SDK to define the rule, specifying the Lambda function as the evaluation logic.
Example: Lambda Function for Security Group Compliance
import json
import boto3
def lambda_handler(event, context):
ec2 = boto3.client('ec2')
response = ec2.describe_security_groups()
for sg in response['SecurityGroups']:
if '0.0.0.0/0' in sg['IpPermissions']:
return {
'ComplianceStatus': 'NON_COMPLIANT',
'Annotation': 'Security group allows unrestricted access'
}
return {
'ComplianceStatus': 'COMPLIANT',
'Annotation': 'Security group compliance verified'
}
CLI Command to Create a Custom Rule
aws configservice put-config-rule --config-rule '{
"Name": "SecurityGroupAccessRule",
"Scope": {
"ComplianceResourceTypes": ["AWS::EC2::SecurityGroup"]
},
"ConfigRuleTriggerTypes": ["AWS_API_CALL"],
"RuleMetadata": {
"Description": "Detects security groups allowing unrestricted internet access",
"InputParameters": {
"CheckInboundRules": "true"
},
"RuleParameters": {
"CheckInboundRules": "true"
}
},
"Source": {
"LambdaSource": {
"Arn": "arn:aws:lambda:region:account-id:function:SecurityGroupChecker"
}
}
}'
Using AWS Managed Rules for Common Security Policies¶
AWS provides pre-built managed rules for standard compliance checks, such as IAM password policies or VPC flow logs. These rules are regularly updated and reduce the need for custom development.
Enabling Managed Rules¶
- Console: Navigate to AWS Config > Rules, search for managed rules (e.g.,
security-group-does-not-allow-internet-access), and enable them. - CLI: Use the
put-config-rulecommand with the managed rule ARN.
Example: Enabling a Managed Rule via CLI
aws configservice put-config-rule --config-rule '{
"Name": "SecurityGroupNoInternetAccess",
"Source": {
"AWSManagedRules": {
"RuleIdentifier": "security-group-does-not-allow-internet-access"
}
}
}'
Managed Rule Examples
- iam-password-policy-compliance: Ensures IAM passwords meet complexity requirements.
- vpc-flow-logs-enabled: Verifies VPC flow logs are active for network monitoring.
- s3-bucket-public-access-blocked: Prevents public access to S3 buckets.
Best Practices for Config Rule Creation¶
- Use IAM Roles: Assign minimal permissions to Lambda functions to avoid privilege escalation.
- Test in Non-Production: Validate rules in a staging environment to prevent false positives/negatives.
- Monitor and Log: Enable CloudWatch logging for Lambda functions to debug rule evaluations.
- Version Control: Track changes to rules using CI/CD pipelines to ensure auditability.
Key takeaways¶
- Custom rules use AWS Lambda to enforce unique compliance policies.
- Managed rules simplify enforcement of common security standards.
- Always test rules in non-production environments and use IAM best practices.
- Combine Config rules with AWS Security Hub for centralized compliance monitoring.
- Automate rule creation and updates using Infrastructure as Code (IaC) tools.