Integrating with AWS Security Hub CSPM
AWS Security Hub CSPM provides you with a comprehensive view of your security state in AWS and helps you to check your environment against security industry standards and best practices. Security Hub CSPM collects security data from across AWS accounts, services, and supported third-party partner products and helps you to analyze your security trends and identify the highest priority security issues.
The Amazon GuardDuty integration with Security Hub CSPM enables you to send findings from GuardDuty to Security Hub CSPM. Security Hub CSPM can then include those findings in its analysis of your security posture.
How Amazon GuardDuty sends findings to AWS Security Hub CSPM
In AWS Security Hub CSPM, security issues are tracked as findings. Some findings come from issues that are detected by other AWS services or by third-party partners. Security Hub CSPM also has a set of rules that it uses to detect security issues and generate findings.
Security Hub CSPM provides tools to manage findings from across all of these sources. You can view and filter lists of findings and view details for a finding. For more information, see Viewing findings in the AWS Security Hub User Guide. You can also track the status of an investigation into a finding. For more information, see Taking action on findings in the AWS Security Hub User Guide.
All findings in Security Hub CSPM use a standard JSON format called the AWS Security Finding Format (ASFF). The ASFF includes details about the source of the issue, the affected resources, and the current status of the finding. See AWS Security Finding Format (ASFF) in the AWS Security Hub User Guide.
Amazon GuardDuty is one of the AWS services that sends findings to Security Hub CSPM.
Types of findings that GuardDuty sends to Security Hub CSPM
Once you enable GuardDuty and Security Hub CSPM in the same account within the same AWS Region,
GuardDuty starts sending all the generated findings to Security Hub CSPM. These findings are sent to
Security Hub CSPM using the AWS
Security Finding Format (ASFF). In ASFF, the Types field
provides the finding type.
Latency for sending new findings
When GuardDuty creates a new finding, it is usually sent to Security Hub CSPM within five minutes.
Retrying when Security Hub CSPM is not available
If Security Hub CSPM is not available, GuardDuty retries sending the findings until they are received.
Updating existing findings in Security Hub CSPM
After it sends a finding to Security Hub CSPM, GuardDuty sends updates to reflect additional observations of the finding activity to Security Hub CSPM. The new observations of these findings are sent to Security Hub CSPM based on the Step 5 – Frequency for exporting findings settings in your AWS account.
When you archive or unarchive a finding, GuardDuty doesn't send that finding to Security Hub CSPM. Any manually unarchived finding that later become active in GuardDuty is not sent to Security Hub CSPM.
Viewing GuardDuty findings in AWS Security Hub CSPM
Sign in to the AWS Management Console and open the AWS Security Hub CSPM console at https://console.aws.amazon.com/securityhub/
You can now use either of the following ways to view the GuardDuty findings in the Security Hub CSPM console:
- Option 1: Using Integrations in Security Hub CSPM
-
In the left navigation pane, choose Integrations.
-
On the Integrations page, check the Status for Amazon: GuardDuty.
-
If the Status is Accepting findings, then choose See findings next to Accepting findings.
-
If not, then for more information about how Integrations work, see Security Hub CSPM integrations in AWS Security Hub User Guide.
-
- Option 2: Using Findings in Security Hub CSPM
-