Monitoring Compliance
AWS Config enables organizations to monitor compliance with security and operational policies by continuously tracking resource configurations. When integrated with AWS Security Hub, it provides a unified view of compliance status and security findings. This section explains how to use AWS Config to track compliance, generate reports, and synchronize findings with Security Hub for centralized monitoring.
Tracking Compliance Status¶
AWS Config evaluates resources against rules (custom or managed) and reports their compliance status in real time. Rules define conditions that resources must meet, such as IAM password policy requirements or VPC flow log configurations. Non-compliant resources trigger alerts, enabling proactive remediation.
Example: Enforce IAM Password Policies¶
aws config put-configuration-rule \
--configuration-rule-name "IAMPasswordPolicyRule" \
--source '{"owner": "AWS", "sourceIdentifier": "IAM_PASSWORD_POLICY"}' \
--scope '{"complianceResourceTypes": ["AWS::IAM::PasswordPolicy"]}'
aws config get-compliance-status \
--resource-type AWS::IAM::PasswordPolicy \
--resource-id arn:aws:iam::123456789012:password-policy/MyPasswordPolicy
Compliance States:
- COMPLIANT: Resource meets all rule requirements.
- NON_COMPLIANT: Resource violates at least one rule.
- NOT_APPLICABLE: Resource type is not covered by the rule.
Generating Compliance Reports¶
AWS Config generates detailed reports showing compliance status over time. Reports can be exported to Amazon S3 or Amazon CloudWatch Logs for audit purposes. Use the AWS CLI to customize report formats and time ranges.
Example: Generate a JSON Report¶
aws config get-compliance-summary \
--compliance-resources "arn:aws:ec2:us-west-2:123456789012:volume/vol-1234567890abcdef0" \
--output json > compliance_report.json
Report Contents: - Resource ARN and type. - Compliance status. - Rule details and violation messages. - Timestamps for state changes.
Integrating with AWS Security Hub¶
To synchronize Config findings with Security Hub, enable the integration in the AWS Management Console. This allows Security Hub to aggregate Config findings alongside other security alerts (e.g., from GuardDuty or Macie).
Steps to Enable Integration¶
- Navigate to Security Hub > Settings > Integration.
- Enable AWS Config under the Findings section.
- Configure the source to use AWS Config findings.
Example: View Config Findings in Security Hub¶
aws securityhub list-findings \
--findings-filter "AwsResourceType=AWS::IAM::PasswordPolicy" \
--output table
Findings in Security Hub:
- Each Config finding is tagged with aws:cloudformation:stack and aws:cloudformation:logical-id for traceability.
- Findings are categorized under Security Hub > Findings > AWS Config.
Key takeaways¶
- Use AWS Config to enforce compliance rules and monitor resource states in real time.
- Generate structured reports for audits using AWS CLI or CloudWatch Logs.
- Integrate Config with Security Hub to centralize compliance and security findings for unified monitoring.