1 Answer
- Newest
- Most votes
- Most comments
1
Hi There
- You aren't charged for config aggregators. There are 2 setup by Control Tower, one in the management account and one in the audit account. Each one gives that account a view of compliance with detective controls across your multi-account environment. Remember, aggregators simply give you a read-only view of the resources, they aren't recording any resource changes. Refer to How AWS Control Tower Works
- Preventive controls are implemented by Service Control Policies (SCPs), not Config. Detective controls are implemented with AWS Config rules. You will see the compliance status of a detective control both in AWS config and Control Tower. Config rules implemented by Control Tower will be prefixed with
AWSControlTower_
in the Config console. - You use an AWS Config conformance pack to evaluate how your accounts may be affected by some AWS Control Tower controls BEFORE you enable the control. To determine how enrollment into AWS Control Tower may affect your accounts, see Extend AWS Control Tower governance using AWS Config conformance packs. The Frameworks you see in Control Tower are groups of control aligned to that particular framework.
Relevant content
- asked 2 years ago
- asked 3 years ago
- asked a year ago
- asked a year ago
- AWS OFFICIALUpdated 3 years ago
- AWS OFFICIALUpdated 4 years ago
- AWS OFFICIALUpdated 2 years ago
- AWS OFFICIALUpdated 9 months ago
matt, I am afraid to say that my first question on why or difference between 2 aggregators still remain unanswered.
On the second one, yes I was supposed to write detective over preventive. My question is if aws config service exists why there is detective control concept exclusively for CT.
Control Tower uses the config aggregator in the management account to get a compliance view of your entire organization for the Control Tower dashboard.
Compliance with detective controls is determined according to data retrieved from the AWS Config aggregator in the Audit account. Its used for alerts, etc.
All of the detective controls you see in Control Tower are AWS Config rules under the hood.