Evaluating compliance
AWS Config rules, conformance packs, aggregators and automatic remediation, Security Hub CSPM standards, audit evidence with Audit Manager and AWS Artifact, Well-Architected security reviews, Trusted Advisor and the shared responsibility model.
Exam tasks: 6.3 (skills 6.3.1 detect, remediate and notify on non-compliant resources, 6.3.2 collect and organize audit evidence, 6.3.3 evaluate architecture against AWS security best practices)
The decision: is the question about your resources' configuration (Config, Security Hub CSPM), proof for an auditor (conformance packs, Audit Manager, Artifact), or the design itself (Well-Architected Tool)?
Which service answers which question
| Service | Evaluates | Output | Fixes things? |
|---|---|---|---|
| AWS Config | Resource configuration against rules | Compliant or non-compliant per resource, with history | Yes, remediation actions |
| Security Hub CSPM | Controls grouped into standards (it uses service-linked Config rules) | Control findings, security score, severity | Through EventBridge or automation rules |
| Audit Manager | Evidence mapped to framework controls | Assessment reports | No |
| AWS Artifact | Nothing in your account: AWS's own compliance | Third-party audit reports, agreements | No |
| Well-Architected Tool | Your answers about a workload's design | High and medium risk issues, improvement plan | No |
| Trusted Advisor | A fixed set of best-practice checks | Red, yellow, green results | No |
AWS Config rules
Config records the configuration of supported resources (the configuration recorder, one per account per Region) and delivers history and snapshots to S3 through a delivery channel. Rules evaluate those records.
| Rule type | How you write it | Pick it when |
|---|---|---|
| Managed rule | Pick from 400+ AWS rules and set parameters | A rule exists. Always the least-effort answer |
| Custom policy rule | Guard DSL, no code to host | Your own logic, expressible as property checks |
| Custom Lambda rule | Your Lambda function returns the evaluation | Logic needs API calls or data Config doesn't record |
- Triggers: configuration change (scoped by resource type, ID or tag), periodic (1, 3, 6, 12 or 24 hours), or both.
- Evaluation modes: detective evaluates resources that exist. Proactive evaluates a proposed resource
configuration before deployment, through the
StartResourceEvaluationAPI or a Hook. Proactive evaluation reports only; it doesn't block or remediate on its own. - Results are
COMPLIANT,NON_COMPLIANT,NOT_APPLICABLEorERROR. - Organization rules deploy a rule to every account from the management account or a Config delegated admin.
Exam signal
If a managed rule matches the requirement (s3-bucket-public-read-prohibited, encrypted-volumes,
restricted-ssh, iam-root-access-key-check, required-tags), it beats any custom Lambda. The exam rewards "least
operational overhead".
Remediation
- A remediation action runs a Systems Manager Automation runbook, either an AWS one (for example
AWS-DisableS3BucketPublicReadWriteorAWS-EnableS3BucketEncryption) or your own. - Manual remediation waits for someone to click. Automatic remediation runs when the rule reports non-compliance, with a configurable number of retries.
- The runbook needs an automation assume role with permission to make the fix. A missing or under-privileged role is the usual reason remediation "doesn't work".
- For notifications, send Config compliance change events through EventBridge to SNS. Config's own SNS topic on the delivery channel sends every configuration change, which is usually too noisy.
Remediation that fights IaC
If CloudFormation owns the resource, automatic remediation changes it outside the stack and causes drift. The next deployment may put the bad setting back. Fix the template, and use remediation as the safety net.
Conformance packs and aggregators
- A conformance pack is a YAML template of Config rules and optional remediation actions, deployed and reported as one unit. AWS provides sample packs such as Operational Best Practices for PCI DSS 4.0, HIPAA Security, NIST 800-53 and CIS.
- Deploy organization conformance packs from the management account or Config delegated admin to put the same pack in every account. Each pack gets a compliance score.
- An aggregator collects Config data and rule results from many accounts and Regions into one account. Use an organization aggregator so new accounts are included automatically. It's read-only: it doesn't deploy rules or remediate.
- Run advanced queries (SQL) on the aggregator for questions like "every unencrypted EBS volume in the org".
The aggregator enforces nothing
An aggregator only shows results for rules that already exist in each source account. "Evaluate every account" needs organization rules or conformance packs first, then an aggregator to view them.
Security Hub CSPM
Legacy: use AWS Security Hub CSPM instead
The service long known as AWS Security Hub is now Security Hub CSPM (cloud security posture management). The name "AWS Security Hub" now belongs to a newer service that correlates CSPM, GuardDuty, Inspector, Macie and IAM Access Analyzer findings into exposures, in OCSF format. See Security findings hub.
- Runs controls grouped into standards, using service-linked Config rules. AWS Config must be recording in each account and Region for most controls.
- Standards you should know:
- AWS Foundational Security Best Practices (FSBP): AWS's own, broadest set. The default choice.
- CIS AWS Foundations Benchmark: industry baseline, several versions.
- PCI DSS: for cardholder data environments.
- NIST SP 800-53 Rev. 5 and NIST SP 800-171: common in government and regulated work.
- AWS Resource Tagging Standard and the service-managed Control Tower standard.
- Consolidated control findings give one finding per control across standards, instead of one per standard.
- Central configuration from the delegated admin applies configuration policies (which standards and controls are on) to the organization, OUs or accounts. Add a home Region with linked Regions to aggregate findings.
- Act on findings with automation rules (suppress, change severity, add notes) or EventBridge for response.
Exam signal
"Continuously check all accounts against CIS or PCI DSS and show a compliance score" is Security Hub CSPM with that standard enabled through central configuration. "Check our own internal rule" is a Config rule.
Audit evidence
AWS Audit Manager
- Maps AWS evidence to the controls of a framework (prebuilt ones for SOC 2, PCI DSS, HIPAA, GDPR, CIS and AWS best practices, or custom). An assessment runs a framework over chosen accounts and collects evidence continuously.
- Evidence sources: Config rule results, Security Hub CSPM control checks, CloudTrail user activity, direct API call snapshots, and manual uploads for procedural controls.
- Delegate control sets to reviewers, then generate an assessment report for the auditor.
- Availability change: Audit Manager is in maintenance mode. From 30 April 2026 it can't be set up in new accounts, organizations or Regions. Existing users continue as before. AWS points new users to Config conformance packs (plus partner tools for procedural controls). Expect exam questions written before this change still to name Audit Manager for "collect and organize audit evidence".
AWS Artifact
- Reports: AWS's own third-party audit reports and certifications (SOC 1, 2 and 3, ISO 27001, PCI DSS Attestation of Compliance and more), downloaded on demand. Many are under confidentiality terms you accept before downloading.
- Agreements: review and accept agreements such as the Business Associate Addendum (BAA) for HIPAA. An account agreement covers one account. An organization agreement, accepted from the management account, covers every current and future member.
- Artifact proves what AWS does (security of the cloud). It says nothing about how you configured your resources. Artifact also hosts some independent software vendors' reports for Marketplace products.
Artifact versus Audit Manager
"The auditor wants evidence that AWS's data centers meet SOC 2" is Artifact. "The auditor wants evidence that our accounts meet SOC 2 controls" is Audit Manager (or conformance packs). Mixing them up is the common mistake.
Evaluating the architecture
Well-Architected Framework and Tool
- The security pillar covers security foundations, identity and access management, detection, infrastructure protection, data protection, incident response and application security.
- Design principles: strong identity foundation, traceability, security at every layer, automated best practices, protecting data in transit and at rest, keeping people away from data, and preparing for security events.
- The Well-Architected Tool records a workload, walks you through the questions of each lens, and flags
high and medium risk issues with an improvement plan.
- Lenses: the Framework lens, the lens catalog (serverless, SaaS, financial services and others) and custom lenses for your own internal standards.
- Milestones snapshot a review so you can show improvement over time. Review templates and profiles pre-fill answers and prioritize questions.
- Share workloads and custom lenses with other accounts or the organization. Trusted Advisor data can be shown alongside the review.
Trusted Advisor
- Every account gets the core security checks: S3 bucket permissions, security groups with unrestricted access to specific ports, IAM use, MFA on the root user, and public EBS and RDS snapshots.
- Business, Enterprise On-Ramp and Enterprise Support plans unlock the full check set, the API, and organizational views across accounts.
- Good for a quick baseline. For continuous, customizable, org-wide compliance, the answer is Config or Security Hub CSPM.
Shared responsibility
- The line moves with the service. On EC2 you patch the guest OS and configure security groups. On RDS AWS patches the engine and you control access and encryption. On Lambda or S3 you own code, data, permissions and configuration only.
- Inherited controls (physical and environmental) come fully from AWS, and Artifact is how you prove them. Customer-specific controls (data classification, application security) are always yours.
Scenarios
An organization conformance pack puts the managed rule in every current and future account, the organization aggregator gives the single view, and EventBridge handles notification. A per-account Lambda is the high-effort option and misses new accounts until someone deploys it. Trusted Advisor's fixed checks can't be customized to this rule or wired to org-wide notifications. An aggregator only displays results; it doesn't deploy or evaluate rules.
The Attestation of Compliance in Artifact covers AWS's side of the shared responsibility model, and the Security Hub CSPM PCI DSS standard continuously scores the startup's own configuration. The BAA is a HIPAA agreement. A Well-Architected review assesses design against AWS best practice, not PCI DSS. GuardDuty detects threats, not configuration compliance.
Remediation runs the runbook with the automation assume role you supply, and if that role can't call the S3 actions the runbook needs, every attempt fails. The trigger type changes when evaluation happens, not whether remediation succeeds. Remediation works with managed rules, and bucket encryption has nothing to do with public access settings.