Closed acouch closed 8 months ago
IIRC its just a single button click in the UI, very easy!
@coilysiren thanks. Config is enabled but the Security Hub Check doesn't acknowledge that. Hopefully it is as simple as a button click!
I think the issue is that we don't have AWS Config enabled in us-east-2, I'm going to click it on now.
Ah nope, it's failing on both regions. Somehow?!?!?! 😆 I'll investigate.
We're currently excluding AWS IAM from AWS Config reporting. That might be the issue?
The exclusion for AWS IAM from AWS Config reporting can be removed here:
The control document says:
This control checks whether AWS Config is enabled in your account in the current Region and is recording all resources. The control fails if AWS Config isn't enabled or isn't recording all resources.
So I'm pretty confident that removing the IAM exclusion will fix this.
Summary
Currently the AWS Config should be enabled check does not pass.
This issue is to investigate the current AWS Config settings and determine the necessary steps to pass the check.
A separate implementation can be created after the steps are determined. It is possible that there is some reason why we can disable this check or the remediation step can be addressed through documentation.
Acceptance criteria