ControlTower Compliance Status

0

Hi,

In my ControlTower settings I see the following message.

"The status of controls owned by AWS Security Hub are unknown in AWS Control Tower. Controls owned by AWS Security Hub are not aggregated in the compliance status of accounts and OUs in AWS Control Tower."

I don't know how to solve it.

Enter image description here

Regards

1 Answer
0

That is the expected behavior as documented here. The detective controls from Security Hub can be enabled and enforced via Control Tower but the status can only be viewed via Security Hub. You can think of Control Tower as showing you the status of "preventive controls" and Security Hub showing you the status of "detective controls".

AWS
conor_c
answered a year ago
profile pictureAWS
EXPERT
Matt-B
reviewed a year ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.

Guidelines for Answering Questions