Anomaly in AWS Security Hub Findings

-1

I have enabled AWS Security Hub CIS AWS foundations benchmark 1.4.0 for my account.

The findings have passed the check IAM users' access keys should be rotated every 90 days or less.

But my account has many IAM users with access keys older then 90 days. So why is security Hub not able to catch those accounts in the scan. It has been more than week the security hub is enabled.

Can you please explain why status is passed even after compliance failure?

Enter image description here

질문됨 일 년 전372회 조회
2개 답변
1
수락된 답변

Hi,

When you enable CIS AWS Foundations Benchmark v1.4.0, AWS Security Hub will perform security checks against specific controls. Some of this controls can be custom rules that AWS Security Hub itself develops, but others use AWS Config managed rules. The latter is the case of the control [IAM.3] 'IAM user's access keys should be rotated every 90 days or less'.

To enable checks against this AWS Config rule, you will need to (1) enable AWS Config in your account, and (2) enable resource recording for required resources -see section Required AWS Config resources for CIS v1.4.0-.

Additionally, please note that [IAM.3] control is not supported in the following AWS regions: Cape Town, Hyderabad, Melbourne, Milan, Zurich, Spain, UAE.

Hope this fixes the issue,

Best!

awsfer
답변함 일 년 전
profile picture
전문가
검토됨 13일 전
profile picture
전문가
검토됨 2달 전
  • Please check update to the question with Screenshot so it is clear what anomaly I am facing

0

In response to your edited message,

AWS Security Hub uses the Compliance Status of all the controls you have enabled to determine the overall Control Status. If one or more controls present a Compliance Status of FAILED, then the overall Control Status should be marked as FAILED, too.

The only reason I can think of causing this misalignment is that the statuses have been updated at different times (4 hours ago vs. 6 hours ago). Thus, they should sync in the next run, and the overall Control Status will be marked as FAILED.

Kind regards

AWS
awsfer
답변함 일 년 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인