Have security group related config rule at organisation level

0

The issue is our accounts are in control tower environment and in control tower there are no options to add config rules other than Predefined ones, in those predefined ones there is non for security groups. How can we enable more config rules at organization level e.g. security group verification rule.

I have the option to enable this at per account level but not at aggregator level, but there are hundreds of account and it is not feasible to have this one by one for each account.

2 Answers
0

Hello,

AWS Config is something that you are looking for & you might want to consider. Read through the link below for all the details & necessary information.

Link- https://docs.aws.amazon.com/config/latest/developerguide/evaluate-config_manage-rules.html -- [1]

profile pictureAWS
SUPPORT ENGINEER
answered 2 years ago
  • Hi Chirag, the issue is our accounts are in control tower environment and in control tower there are no options to add config rules other than Predefined ones, in those predefined ones there is non for security groups. How can we enable more config rules at organisation level e.g. security group verification rules.

    I have the option to enable this ar per account level but not at aggregator level, but there are hundreds of account and it is not feasible to have this one by one for each account.

0

You can implement custom AWS Config rules to cover use cases that are specific to your organization. However, these controls are not implemented as AWS Control Tower controls. Instead, these controls are implemented as custom AWS Config rules outside of AWS Control Tower. And since you are managing hundreds of account, AWS Config Conformance Pack may work for your case. https://docs.aws.amazon.com/config/latest/developerguide/conformance-packs.html https://aws.amazon.com/blogs/mt/extend-aws-control-tower-governance-using-aws-config-conformance-packs/

JED007
answered a year ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.

Guidelines for Answering Questions