Remediate Non Compliant Resources AWS Config Archives - Anuj Varma, Hands-On Technology Architect, Clean Air Activist https://www.anujvarma.com/tag/remediate-non-compliant-resources-aws-config/ Production Grade Technical Solutions | Data Encryption and Public Cloud Expert Mon, 24 Aug 2020 01:29:02 +0000 en-US hourly 1 https://wordpress.org/?v=7.0.2 https://www.anujvarma.com/wp-content/uploads/anujtech.png Remediate Non Compliant Resources AWS Config Archives - Anuj Varma, Hands-On Technology Architect, Clean Air Activist https://www.anujvarma.com/tag/remediate-non-compliant-resources-aws-config/ 32 32 Remediate Non Compliant Resources using Custom AWS Config https://www.anujvarma.com/remediate-non-compliant-resources-using-custom-aws-config/ https://www.anujvarma.com/remediate-non-compliant-resources-using-custom-aws-config/#respond Wed, 27 Nov 2019 00:21:44 +0000 https://www.anujvarma.com/?p=6297 Using System Manager Documents (SSM Docs) To remediate non compliant resources, one could leverage existing Systems Manager documents to accomplish this. Clicking on ‘Edit Config Rule’ –> ‘Manage remediation’ by […]

The post Remediate Non Compliant Resources using Custom AWS Config appeared first on Anuj Varma, Hands-On Technology Architect, Clean Air Activist.

]]>
Using System Manager Documents (SSM Docs)

To remediate non compliant resources, one could leverage existing Systems Manager documents to accomplish this.

  1. Clicking on ‘Edit Config Rule’ –> ‘Manage remediation’ by selecting the name of the rule, select the appropriate remediation action from the recommended list. The remediation actions are related to AWS Systems Manager automation documents.
  2. Depending on the selected remediation action, you will see either specific parameters or no parameters.

Firewall Rules Automatic Remediation (via AWS Config)

This is a new service from AWS. Firewall Manager can be used to manage ALL your security groups (i.e. throughout all the VPCs, in all the regions within your ORG).

Auditing existing security groups: There is an audit security group policy that can validate existing firewall rules within your security groups. The scope of the policy can be to audit across all accounts, a specific account, or even specific VPCs (tagged appropriately) within your organization. Firewall Manager is able to detect new accounts added to your organization as well as new resources (with the specified tag). Once detected, Firewall Manager is able to audit them.

  • Guardrails – Audit rules can be used to set guardrails on which security group rules to allow or disallow within your organization
  • Unused or Redundant security groups can be detected and placed into the audit report or be alerted upon.
  • Reports of non-compliant resources – reports and alerts for non-compliant resources for your baseline and audit policies
  • Remediate Resources : Auto-remediation workflows can be created in AWS Config, to remediate any non-compliant resources that Firewall Manager detects.
Setup a time to chat with Anuj Varma today or to schedule an AWS Security Audit. Security cannot be an afterthought (™)

The post Remediate Non Compliant Resources using Custom AWS Config appeared first on Anuj Varma, Hands-On Technology Architect, Clean Air Activist.

]]>
https://www.anujvarma.com/remediate-non-compliant-resources-using-custom-aws-config/feed/ 0