turbot / steampipe-mod-aws-compliance

Run individual controls or full compliance benchmarks for CIS, PCI, NIST, HIPAA and more across all of your AWS accounts using Powerpipe and Steampipe.
https://hub.steampipe.io/mods/turbot/aws_compliance
Apache License 2.0
369 stars 59 forks source link

Bug: Remove deprecated/obsolete AWS Foundational Security Best Practices Benchmark Controls #667

Closed sfunkernw closed 1 year ago

sfunkernw commented 1 year ago

Some AWS Foundational Benchmark Controls were removed, see https://docs.aws.amazon.com/securityhub/latest/userguide/doc-history.html

For example, https://hub.steampipe.io/mods/turbot/aws_compliance/controls/control.foundational_security_ec2_27?context=benchmark.foundational_security/benchmark.foundational_security_ec2 should be removed because it got removed from the officiel benchmark in 20. July 2020 (see EC2.27 is retired in benchmark history above) with the comment “Security Hub has retired EC2.27 - Running EC2 Instances should not use key pairs, a former control in the AWS Foundational Security Best Practices (FSBP) standard.”

It would make imho a lot of sense to remove the "retired" controls from the benchmark of the compliance mod as well.

rajlearner17 commented 1 year ago

@sfunkernw, Thanks for using Steampipe!

We appreciate your notifying us; we will include further checking our monthly update cycle.

Cheers! 👍