Skip to content

How do I use Security Hub CSPM to check Firewall Manager security group policy findings?

2 minute read
0

I want to use AWS Security Hub CSPM to check my AWS Firewall Manager security group policy findings.

Short description

Firewall Manager creates findings for resources that are out of compliance and for detected attacks and then sends the findings to Security Hub CSPM. Firewall Manager is integrated with Security Hub CSPM to receive security group policy findings including, common policies, content audit policies, and group usage audit policies.

Note: If you already use Firewall Manager, then Security Hub CSPM automatically turns on this integration. You don't need to take any additional action to receive findings from Firewall Manager.

Resolution

Filter with findings

Complete the following steps:

  1. Open the Security Hub CSPM console in the same AWS Region where the security group policy was created.
  2. From the navigation pane, choose Findings.
  3. In Search and add filter, choose Product name from the dropdown list.
  4. In Edit filter, for operator, choose is. For value, enter Firewall Manager. Then, choose Apply.
    Note: Search values are case sensitive.

Filter with integrations

Complete the following steps:

  1. Open the Security Hub CSPM console in the same Region where the security group policy was created.
  2. From the navigation pane, choose Integrations.
  3. In the Integrations search pane, enter Firewall Manager. If you're already using Firewall Manager, the Status of this integration should be Accepting findings.
    Note: Search values are case sensitive.
  4. Choose See findings.

(Optional) Disable integration

To disable the integration of Firewall Manager findings with Security Hub CSPM, complete the following steps:

  1. Open the Security Hub CSPM console.
  2. From the navigation pane, choose Integrations.
  3. In the Integrations search pane, enter Firewall Manager.
  4. Choose Stop accepting findings.
  5. Select I want to stop accepting findings and then, choose Stop accepting findings.

For more information, see AWS Firewall Manager integration with AWS Security Hub CSPM and Creating and updating findings in Security Hub.

Related information

How can I use Security Hub to monitor security issues for my AWS environment?

How do I set up AWS Firewall Manager for my AWS account?

AWS OFFICIALUpdated 2 months ago