Required AWS Config resources for control findings
Note
If you are using Security Hub CSPM and Security Hub the configuration of the resource recording is managed for you. Security Hub creates a service-linked configuration recorder with AWS Config and gets direct information on all resources that are related to controls supported in Security Hub CSPM. For more information, see Using the service-linked configuration recorder.
In AWS Security Hub CSPM, some controls use service-linked AWS Config rules that detect configuration changes in your AWS resources. For Security Hub CSPM to generate accurate findings for these controls, you must enable AWS Config and turn on resource recording in AWS Config. For information about how Security Hub CSPM uses AWS Config rules and how to enable and configure AWS Config, see Enabling and configuring AWS Config for Security Hub CSPM. For detailed information about resource recording, see Working with the configuration recorder in the AWS Config Developer Guide.
To receive accurate control findings, you must turn on AWS Config resource recording for enabled controls with a change triggered schedule type. Some controls with a periodic schedule type also require resource recording. This page lists the required resources for these Security Hub CSPM controls.
Security Hub CSPM controls can rely on managed AWS Config rules or custom Security Hub CSPM rules. Make sure there aren't any AWS Identity and Access Management (IAM) policies or AWS Organizations managed policies that prevent AWS Config from having permission to record your resources. Security Hub CSPM controls evaluate resource configurations directly and don’t take AWS Organizations policies into account.
Note
In AWS Regions where a control isn't available, the corresponding resource isn't available in AWS Config. For a list of these limits, see Regional limits on Security Hub CSPM controls.