GSA-TTS / tts-tech-operations

TTS Technology Operations
https://handbook.tts.gsa.gov/tech-operations/
Other
6 stars 0 forks source link

Evaluate using AWS Guardduty/Config for baseline monitoring for all accounts #739

Closed JJediny closed 3 years ago

JJediny commented 4 years ago

Background

These services provide automated monitoring of security settings/incidents/best practices

Implementation

Acceptance

JJediny commented 3 years ago

In accordance with GSA Security Engineering Requirements for AWS - PL-8: Information Security Architecture:

Required

Optional

Background on these services:

GuardDuty ($$) - is a threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect your AWS accounts and workloads. With the cloud, the collection and aggregation of account and network activities is simplified.

Config ($) - is a service that enables you to assess, audit, and evaluate the configurations of your AWS resources. Config continuously monitors and records your AWS resource configurations and allows you to automate the evaluation of recorded configurations against desired configurations.

Next Steps (TBD):

afeld commented 3 years ago

That all sounds good! In addition, let's split out issues to:

JJediny commented 3 years ago

Closing in favor of https://github.com/18F/tts-tech-portfolio/issues/1044