AWS Control Tower AWS Security Hub Integration Error

1

Even though the status indicates Compliant, I am getting the following error on my OUs and accounts in AWS Control Tower after updating to Landing Zone 3.0:

"The status of controls owned by AWS Security Hub are unknown in AWS Control Tower. Controls owned by AWS Security Hub are not aggregated in the compliance status of accounts and OUs in AWS Control Tower."

The error before was not showing or I can't remember seeing such error before the upgrade to Landing Zone 3.0. I will appreciate any help on this.

Thanks!

3 Antworten
1
Akzeptierte Antwort

The AWS Security Hub integration with AWS Control Tower is in preview. Controls owned by Security Hub are not aggregated in the compliance status of accounts and OUs in AWS Control Tower. This is a standard warning on all accounts, but it means that if you enable a Control thats owned by Security Hub on an OU, and that control is non-compliant in Security Hub, Control Tower will still show the Account and OU as Compliant on the dashboard. That is why you receive the warning, you need to check both Control Tower and Security Hub for an accurate compliance status.

https://docs.aws.amazon.com/controltower/latest/userguide/security-hub-controls.html

AWS
debbie
beantwortet vor einem Jahr
1

I am also seeing this same compliance status warning and wondering what it means.

beantwortet vor einem Jahr
0

I ran into the same issue using AWS CT 3.0, wondering if you figured it out ?

rgogan
beantwortet vor einem Jahr
  • No solution yet.

Du bist nicht angemeldet. Anmelden um eine Antwort zu veröffentlichen.

Eine gute Antwort beantwortet die Frage klar, gibt konstruktives Feedback und fördert die berufliche Weiterentwicklung des Fragenstellers.

Richtlinien für die Beantwortung von Fragen