Asterrr's Handbook

Evaluating compliance

AWS Config rules, conformance packs, aggregators and automatic remediation, Security Hub CSPM standards, audit evidence with Audit Manager and AWS Artifact, Well-Architected security reviews, Trusted Advisor and the shared responsibility model.

Exam tasks: 6.3 (skills 6.3.1 detect, remediate and notify on non-compliant resources, 6.3.2 collect and organize audit evidence, 6.3.3 evaluate architecture against AWS security best practices)

The decision: is the question about your resources' configuration (Config, Security Hub CSPM), proof for an auditor (conformance packs, Audit Manager, Artifact), or the design itself (Well-Architected Tool)?

Which service answers which question

ServiceEvaluatesOutputFixes things?
AWS ConfigResource configuration against rulesCompliant or non-compliant per resource, with historyYes, remediation actions
Security Hub CSPMControls grouped into standards (it uses service-linked Config rules)Control findings, security score, severityThrough EventBridge or automation rules
Audit ManagerEvidence mapped to framework controlsAssessment reportsNo
AWS ArtifactNothing in your account: AWS's own complianceThird-party audit reports, agreementsNo
Well-Architected ToolYour answers about a workload's designHigh and medium risk issues, improvement planNo
Trusted AdvisorA fixed set of best-practice checksRed, yellow, green resultsNo

AWS Config rules

Config records the configuration of supported resources (the configuration recorder, one per account per Region) and delivers history and snapshots to S3 through a delivery channel. Rules evaluate those records.

Rule typeHow you write itPick it when
Managed rulePick from 400+ AWS rules and set parametersA rule exists. Always the least-effort answer
Custom policy ruleGuard DSL, no code to hostYour own logic, expressible as property checks
Custom Lambda ruleYour Lambda function returns the evaluationLogic needs API calls or data Config doesn't record
  • Triggers: configuration change (scoped by resource type, ID or tag), periodic (1, 3, 6, 12 or 24 hours), or both.
  • Evaluation modes: detective evaluates resources that exist. Proactive evaluates a proposed resource configuration before deployment, through the StartResourceEvaluation API or a Hook. Proactive evaluation reports only; it doesn't block or remediate on its own.
  • Results are COMPLIANT, NON_COMPLIANT, NOT_APPLICABLE or ERROR.
  • Organization rules deploy a rule to every account from the management account or a Config delegated admin.

Exam signal

If a managed rule matches the requirement (s3-bucket-public-read-prohibited, encrypted-volumes, restricted-ssh, iam-root-access-key-check, required-tags), it beats any custom Lambda. The exam rewards "least operational overhead".

Remediation

  • A remediation action runs a Systems Manager Automation runbook, either an AWS one (for example AWS-DisableS3BucketPublicReadWrite or AWS-EnableS3BucketEncryption) or your own.
  • Manual remediation waits for someone to click. Automatic remediation runs when the rule reports non-compliance, with a configurable number of retries.
  • The runbook needs an automation assume role with permission to make the fix. A missing or under-privileged role is the usual reason remediation "doesn't work".
  • For notifications, send Config compliance change events through EventBridge to SNS. Config's own SNS topic on the delivery channel sends every configuration change, which is usually too noisy.

Remediation that fights IaC

If CloudFormation owns the resource, automatic remediation changes it outside the stack and causes drift. The next deployment may put the bad setting back. Fix the template, and use remediation as the safety net.

Conformance packs and aggregators

  • A conformance pack is a YAML template of Config rules and optional remediation actions, deployed and reported as one unit. AWS provides sample packs such as Operational Best Practices for PCI DSS 4.0, HIPAA Security, NIST 800-53 and CIS.
  • Deploy organization conformance packs from the management account or Config delegated admin to put the same pack in every account. Each pack gets a compliance score.
  • An aggregator collects Config data and rule results from many accounts and Regions into one account. Use an organization aggregator so new accounts are included automatically. It's read-only: it doesn't deploy rules or remediate.
  • Run advanced queries (SQL) on the aggregator for questions like "every unencrypted EBS volume in the org".

The aggregator enforces nothing

An aggregator only shows results for rules that already exist in each source account. "Evaluate every account" needs organization rules or conformance packs first, then an aggregator to view them.

Security Hub CSPM

Legacy: use AWS Security Hub CSPM instead

The service long known as AWS Security Hub is now Security Hub CSPM (cloud security posture management). The name "AWS Security Hub" now belongs to a newer service that correlates CSPM, GuardDuty, Inspector, Macie and IAM Access Analyzer findings into exposures, in OCSF format. See Security findings hub.

  • Runs controls grouped into standards, using service-linked Config rules. AWS Config must be recording in each account and Region for most controls.
  • Standards you should know:
    • AWS Foundational Security Best Practices (FSBP): AWS's own, broadest set. The default choice.
    • CIS AWS Foundations Benchmark: industry baseline, several versions.
    • PCI DSS: for cardholder data environments.
    • NIST SP 800-53 Rev. 5 and NIST SP 800-171: common in government and regulated work.
    • AWS Resource Tagging Standard and the service-managed Control Tower standard.
  • Consolidated control findings give one finding per control across standards, instead of one per standard.
  • Central configuration from the delegated admin applies configuration policies (which standards and controls are on) to the organization, OUs or accounts. Add a home Region with linked Regions to aggregate findings.
  • Act on findings with automation rules (suppress, change severity, add notes) or EventBridge for response.

Exam signal

"Continuously check all accounts against CIS or PCI DSS and show a compliance score" is Security Hub CSPM with that standard enabled through central configuration. "Check our own internal rule" is a Config rule.

Audit evidence

AWS Audit Manager

  • Maps AWS evidence to the controls of a framework (prebuilt ones for SOC 2, PCI DSS, HIPAA, GDPR, CIS and AWS best practices, or custom). An assessment runs a framework over chosen accounts and collects evidence continuously.
  • Evidence sources: Config rule results, Security Hub CSPM control checks, CloudTrail user activity, direct API call snapshots, and manual uploads for procedural controls.
  • Delegate control sets to reviewers, then generate an assessment report for the auditor.
  • Availability change: Audit Manager is in maintenance mode. From 30 April 2026 it can't be set up in new accounts, organizations or Regions. Existing users continue as before. AWS points new users to Config conformance packs (plus partner tools for procedural controls). Expect exam questions written before this change still to name Audit Manager for "collect and organize audit evidence".

AWS Artifact

  • Reports: AWS's own third-party audit reports and certifications (SOC 1, 2 and 3, ISO 27001, PCI DSS Attestation of Compliance and more), downloaded on demand. Many are under confidentiality terms you accept before downloading.
  • Agreements: review and accept agreements such as the Business Associate Addendum (BAA) for HIPAA. An account agreement covers one account. An organization agreement, accepted from the management account, covers every current and future member.
  • Artifact proves what AWS does (security of the cloud). It says nothing about how you configured your resources. Artifact also hosts some independent software vendors' reports for Marketplace products.

Artifact versus Audit Manager

"The auditor wants evidence that AWS's data centers meet SOC 2" is Artifact. "The auditor wants evidence that our accounts meet SOC 2 controls" is Audit Manager (or conformance packs). Mixing them up is the common mistake.

Evaluating the architecture

Well-Architected Framework and Tool

  • The security pillar covers security foundations, identity and access management, detection, infrastructure protection, data protection, incident response and application security.
  • Design principles: strong identity foundation, traceability, security at every layer, automated best practices, protecting data in transit and at rest, keeping people away from data, and preparing for security events.
  • The Well-Architected Tool records a workload, walks you through the questions of each lens, and flags high and medium risk issues with an improvement plan.
    • Lenses: the Framework lens, the lens catalog (serverless, SaaS, financial services and others) and custom lenses for your own internal standards.
    • Milestones snapshot a review so you can show improvement over time. Review templates and profiles pre-fill answers and prioritize questions.
    • Share workloads and custom lenses with other accounts or the organization. Trusted Advisor data can be shown alongside the review.

Trusted Advisor

  • Every account gets the core security checks: S3 bucket permissions, security groups with unrestricted access to specific ports, IAM use, MFA on the root user, and public EBS and RDS snapshots.
  • Business, Enterprise On-Ramp and Enterprise Support plans unlock the full check set, the API, and organizational views across accounts.
  • Good for a quick baseline. For continuous, customizable, org-wide compliance, the answer is Config or Security Hub CSPM.

Shared responsibility

  • The line moves with the service. On EC2 you patch the guest OS and configure security groups. On RDS AWS patches the engine and you control access and encryption. On Lambda or S3 you own code, data, permissions and configuration only.
  • Inherited controls (physical and environmental) come fully from AWS, and Artifact is how you prove them. Customer-specific controls (data classification, application security) are always yours.
1 per Region
Config configuration recorder per account per Region. Security Hub CSPM needs it on.
24 h
Longest periodic trigger interval for a Config rule (options are 1, 3, 6, 12 and 24 hours).
30 Apr 2026
Date after which Audit Manager can't be set up in new accounts, organizations or Regions.
Management account
Where an Artifact organization agreement is accepted to cover every member account.

Scenarios

Scenario
An insurance company runs 90 accounts in AWS Organizations. The compliance team must ensure that every EBS volume in every account, including accounts created next year, is encrypted. The team must be notified whenever a volume becomes non-compliant, and wants one dashboard showing compliance across all accounts and Regions. Which combination of steps meets these requirements with the LEAST operational overhead?
Scenario · choose 2
A payments startup is preparing for its first PCI DSS assessment. The QSA asks for (1) proof that the AWS infrastructure hosting the cardholder data environment is PCI DSS compliant, and (2) a continuous view of how the startup's own accounts measure against PCI DSS technical requirements. Which TWO actions should the security team take?
Scenario
A Config rule flags S3 buckets that allow public read access. The team configured automatic remediation with the AWS-DisableS3BucketPublicReadWrite runbook, but non-compliant buckets stay non-compliant and the remediation shows as failed. Config recording and the rule itself are working. What is the MOST likely cause?

Further reading

On this page