Marketplace Vendor Insights - AWS Audit Manager automated assessments not well designed / AWSVendorInsightsConformancePackv1

0

Hi, As a SaaS ISV selling a product on the AWS Marketplace, I decided to use the AWS Audit Manager continuous automated assessment documented in Step 4 here: https://docs.aws.amazon.com/marketplace/latest/userguide/vendor-insights-setting-up.html.

However, the stacks and stacksets that it references (Github repo) (associated with conformance pack "AWSVendorInsightsConformancePackv1") , create AWS resources that themselves violate the checks/postures embodied in the said automated assessment, creating a downward spiral of work that never reaches a finish line:

Example of non-compliant S3 buckets created by AWSVendorInsightsConformancePackv1 that are flagged as non-compliant

Another head-scratcher rule is "no inline policies" in IAM User, Roles, or Groups; when AWS's first-party configuration wizards routinely use this. Inline Policies are impossible to avoid: shown here created by AWS Systems Manager easy configuration wizard, and the VendorInsights CF stackset

Please recall the AWSVendorInsightsConformancePackv1 scripts if they are so clearly unhelpful to a Marketplace ISV to reach any reasonable finish line.

Thanks, Sid

profile picture
Sid M
已提問 1 個月前檢視次數 115 次
沒有答案

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南