Security Hub controls marked as RESOLVED do not go away.

0

I have lots of findings in different controls that have been resolved. So I set their workflow as RESOLVED. Days latter I am still seeing them marked RESOLVED and they are truly resolved.

Why are they not getting marked as PASSED?

질문됨 5달 전174회 조회
1개 답변
0
수락된 답변

Security Hub uses the Compliance.Status value from each control's findings to determine the overall control status. The Overall control status is Passed when all findings have a Compliance.Status of PASSED.

Security Hub > Controls > Search for the control ID eg. EC2.19 > Check the Compliance Status of all the Checks

For administrator accounts, the control status reflects the aggregated status across both the administrator account and all of the member accounts.

If you have set an aggregation Region, control statuses in the aggregation Region reflect control statuses across all of your linked Regions. Specifically, the overall status of a control appears as Failed if the control has one or more failed findings in at least one account and one linked Region.

Also Security Hub updates the control status every 24 hours based on the findings from the previous 24 hours.

[+] Determining the overall status of a control from its findings - https://docs.aws.amazon.com/securityhub/latest/userguide/controls-overall-status.html

profile picture
답변함 5달 전
profile picture
전문가
검토됨 한 달 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠