Can you add custom Security Stadards or edit existing Standards?

0

I don't see this mentioned in the documentation and I do not see any options in the console, so I thought I would double check here to ensure I am not missing anything:

  1. Can you create your own Security Standard that has a set of rules that you'd like your accounts to comply with?

  2. Can you customize existing Security Standards? For example, before enabling the CIS Benchmark, can I disable all Level 2 controls? Or is the only way to do this to enable the standard and then disable individual controls afterwards?

Perhaps using another tool that can integrate with Security Hub, such as Prowler, is the way to go for a custom Security Standard?

Thank you

Jhoov
질문됨 4년 전405회 조회
2개 답변
0

Fully customizable standards are coming in the future. Today, you can disable individual controls in a standard. This can only be done after you have enabled the standard.

Relevant docs:

https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-standards-enable-disable-controls.html

https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-standards-cis-to-disable.html

Ely_K
답변함 4년 전
  • Hi Ely, so are we now able to add custom Security Standards in the security hub?

  • Hi Ely,

    I don't see that this was ever released and we'd still like to be able to define a custom standard. Selecting rules from the existing standards would be perfectly acceptable for us. We know we can enable the standards via the API and then turn off individual rules, but we then have to monitor for new rules and add them to the script or we will have new AWS accounts with rules that we do not wish to be enabled. It would be so much easier to just select the rules we wish to have enabled and add them to a custom standard. We wouldn't have to constantly maintain the script that way and it would simplify the entire process. Please let us know if this is still planned.

    Thank you, Jeff

0

Thank you, Ely. That is great to hear about fully customizable standards coming in the future. Also, thank you for confirming that we can only enable standards and then disable individual rules. That is what I thought.

Jhoov
답변함 4년 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠