#AWSConfig
https://lckhd.eu/2CQeJC

#EKS #Kubernetes #AWSConfig #SNS #EventBridge

Using the Elastic Kubernetes Service (EKS) on AWS makes using Kubernetes easier than setting up from scratch. One complication that many teams don't handle well is regularly updating Kubernetes versions as they get released
September 25, 2026 at 5:30 AM
Amazon CloudWatch now provides centralized visibility into telemetry configurations

Amazon CloudWatch now offers centralized visibility into critical AWS service telemetry configurations, such as Amazon VPC Flow Logs, Amazon EC2 Detailed Met...

#AWS #AwsConfig #AmazonCloudwatch #AwsOrganizations
Amazon CloudWatch now provides centralized visibility into telemetry configurations
Amazon CloudWatch now offers centralized visibility into critical AWS service telemetry configurations, such as Amazon VPC Flow Logs, Amazon EC2 Detailed Metrics, and AWS Lambda Traces. This enhanced visibility enables central DevOps teams, system administrators, and service teams to identify potential gaps in their infrastructure monitoring setup. The telemetry configuration auditing experience seamlessly integrates with AWS Config to discover AWS resources, and can be turned on for the entire organization using the new AWS Organizations integration with Amazon CloudWatch. With visibility into telemetry configurations, you can identify monitoring gaps that might have been missed in your current setup. For example, this helps you identify gaps in your EC2 detailed metrics so that you can address them and easily detect short-lived performance spikes and build responsive auto-scaling policies. You can audit telemetry configuration coverage at both resource type and individual resource levels, refining the view by filtering across specific accounts, resource types, or resource tags to focus on critical resources. The telemetry configurations auditing experience is available in US East (N. Virginia), US West (Oregon), US East (Ohio), Asia Pacific (Tokyo), Asia Pacific (Singapore), Asia Pacific (Sydney), Europe (Frankfurt), Europe (Ireland), and Europe (Stockholm) regions. There is no additional cost to turn on the new experience, including for AWS Config. You can get started with auditing your telemetry configurations using the https://us-east-1.console.aws.amazon.com/cloudwatch/home?region=us-east-1#, by clicking on Telemetry config in the navigation panel, or programmatically using the API/CLI. To learn more, https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/telemetry-config-cloudwatch.html.
aws.amazon.com
December 6, 2024 at 7:05 PM
✨ New article published on @dev.to

I shared how i used AWS Config rules to optimize EKS Cloud costs on @awscloud.bsky.social
Read more 👉 dev.to/aaitaazizi/a...

#AWS #AWSConfig #EKS #Kubernetes #FinOps
Automated EKS Cost Optimization with AWS Config
Through the past years, I helped a number of organizations to optimize cloud costs in AWS, more...
dev.to
January 6, 2026 at 1:13 PM
AWS Control Tower introduces a Controls Dedicated experience

AWS Control Tower now offers Control Only Experience, enabling faster governance setup for established multi-account environments by providing access to AWS managed...

#AWS #AwsConfig #AwsControlTower #AwsOrganizations #ManagementTools
AWS Control Tower introduces a Controls Dedicated experience
AWS Control Tower now offers Control Only Experience, enabling faster governance setup for established multi-account environments by providing access to AWS managed controls without requiring a full landing zone implementation.
aws.amazon.com
November 19, 2025 at 8:05 PM
🆕 Amazon CloudWatch now provides centralized visibility into telemetry configurations

#AWS #AwsConfig #AmazonCloudwatch #AwsOrganizations
Amazon CloudWatch now provides centralized visibility into telemetry configurations
Amazon CloudWatch now offers centralized visibility into critical AWS service telemetry configurations, such as Amazon VPC Flow Logs, Amazon EC2 Detailed Metrics, and AWS Lambda Traces. This enhanced visibility enables central DevOps teams, system administrators, and service teams to identify potential gaps in their infrastructure monitoring setup. The telemetry configuration auditing experience seamlessly integrates with AWS Config to discover AWS resources, and can be turned on for the entire organization using the new AWS Organizations integration with Amazon CloudWatch. With visibility into telemetry configurations, you can identify monitoring gaps that might have been missed in your current setup. For example, this helps you identify gaps in your EC2 detailed metrics so that you can address them and easily detect short-lived performance spikes and build responsive auto-scaling policies. You can audit telemetry configuration coverage at both resource type and individual resource levels, refining the view by filtering across specific accounts, resource types, or resource tags to focus on critical resources. The telemetry configurations auditing experience is available in US East (N. Virginia), US West (Oregon), US East (Ohio), Asia Pacific (Tokyo), Asia Pacific (Singapore), Asia Pacific (Sydney), Europe (Frankfurt), Europe (Ireland), and Europe (Stockholm) regions. There is no additional cost to turn on the new experience, including for AWS Config. You can get started with auditing your telemetry configurations using the Amazon CloudWatch Console, by clicking on Telemetry config in the navigation panel, or programmatically using the API/CLI. To learn more, visit our documentation.
aws.amazon.com
December 6, 2024 at 6:23 PM
🆕 AWS Config now supports resource tags for IAM Policies, enhancing metadata tracking for better configuration assessment and multi-account governance across all regions at no extra cost.

#AWS #AwsConfig
AWS Config now supports resource tags for IAM Policies
AWS Config now tracks resource tags for IAM policy resource types, enhancing the granularity of metadata you can capture to assess, audit, and evaluate configurations of your IAM policies. With this enhancement, you can now track resource tags and their changes for IAM Policies directly in your Config recorder. This capability allows you to scope both Config-managed and custom rule evaluations based on resource tags, ensuring your IAM policies maintain desired configurations. Additionally, you can leverage Config aggregators to selectively aggregate IAM policies across multiple accounts using tags, streamlining your multi-account governance. This feature is now available across all supported AWS Regions at no additional cost. Resource tags are automatically populated in Config when you record IAM policy resource types. For recording IAM policy resource type in your Config recorder, please refer our documentation.
aws.amazon.com
September 8, 2025 at 1:40 PM
AWS Config now supports 191 additional managed rules

AWS Config now supports 191 additional managed rules across key services including Amazon Bedrock, Amazon SageMaker, Amazon ECS, Amazon EKS, Amazon RDS, Amazon Redshift, Amazon S3, and Amazon CloudTrail. This expansion increas...

#AWS #AwsConfig
AWS Config now supports 191 additional managed rules
AWS Config now supports 191 additional managed rules across key services including Amazon Bedrock, Amazon SageMaker, Amazon ECS, Amazon EKS, Amazon RDS, Amazon Redshift, Amazon S3, and Amazon CloudTrail. This expansion increases built-in governance coverage across AI workloads and core cloud infrastructure. Examples of the new managed rules include evaluating resource configurations for encryption, logging, public access, network security, data protection, and other operational best practices across AWS services.  With this launch, you can deploy these new managed rules individually or as part of a conformance pack in the https://docs.aws.amazon.com/config/latest/developerguide/what-is-resource-config-coverage.html where the corresponding AWS services are available.    AWS Certificate Manager  ACM_CERTIFICATE_RSA_CHECK   Amazon API Gateway  API_GWV2_ACCESS_LOGS_ENABLED   AWS AppSync  APPSYNC_AUTHORIZATION_CHECK   APPSYNC_LOGGING_ENABLED   Amazon Athena  ATHENA_WORKGROUP_ENCRYPTED_AT_REST   ATHENA_WORKGROUP_LOGGING_ENABLED   Amazon Aurora  AURORA_MYSQL_CLUSTER_AUDIT_LOGGING   Amazon Bedrock  BEDROCKAGENTCORE_BROWSERCUSTOM_NETWORK_MODE_NOT_PUBLIC   BEDROCKAGENTCORE_BROWSERCUSTOM_RECORDING_ENABLED   BEDROCKAGENTCORE_CODEINTERPRETER_NETWORKMODE_CHECK   BEDROCKAGENTCORE_GATEWAY_AUTHORIZER_ENABLED   BEDROCKAGENTCORE_GATEWAY_ENCRYPTION_ENABLED   BEDROCKAGENTCORE_RUNTIME_PRIVATE_NETWORK_REQUIRED   BEDROCK_AGENTCORE_MEMORY_ENCRYPTION_ENABLED   BEDROCK_AGENTCORE_MEMORY_EVENT_EXPIRY_DURATION   BEDROCK_DATA_SOURCE_ENCRYPTION_ENABLED   AWS CloudFormation  CLOUDFORMATION_STACK_SERVICE_ROLE_CHECK   CLOUDFORMATION_TERMINATION_PROTECTION_CHECK   AWS CloudTrail  CLOUDTRAIL_ALL_READ_S3_DATA_EVENT_CHECK   CLOUDTRAIL_ALL_WRITE_S3_DATA_EVENT_CHECK   CLOUDTRAIL_S3_BUCKET_ACCESS_LOGGING   CLOUDTRAIL_S3_BUCKET_PUBLIC_ACCESS_PROHIBITED   EVENT_DATA_STORE_CMK_ENCRYPTION_ENABLED   Amazon CloudWatch  CLOUDWATCH_ALARM_ACTION_ENABLED_CHECK   Amazon Cognito  COGNITO_IDENTITY_POOL_UNAUTH_ACCESS_CHECK   COGNITO_USERPOOL_CUST_AUTH_THREAT_FULL_CHECK   COGNITO_USER_POOL_ADVANCED_SECURITY_ENABLED   COGNITO_USER_POOL_MFA_ENABLED   COGNITO_USER_POOL_PASSWORD_POLICY_CHECK   AWS CodeBuild  CODEBUILD_PROJECT_ARTIFACT_ENCRYPTION   CODEBUILD_PROJECT_ENVIRONMENT_PRIVILEGED_CHECK   CODEBUILD_PROJECT_LOGGING_ENABLED   CODEBUILD_PROJECT_S3_LOGS_ENCRYPTED   AWS DataSync  DATASYNC_TASK_LOGGING_ENABLED   AWS Database Migration Service (DMS)  DMS_REPLICATION_TASK_SOURCEDB_LOGGING   DMS_REPLICATION_TASK_TARGETDB_LOGGING   Amazon DocumentDB  DOCDB_CLUSTER_AUDIT_LOGGING_ENABLED   DOCDB_CLUSTER_DELETION_PROTECTION_ENABLED   DOCDB_CLUSTER_ENCRYPTED_IN_TRANSIT   DOCDB_CLUSTER_SNAPSHOT_PUBLIC_PROHIBITED   Amazon DynamoDB  DYNAMODB_TABLE_DELETION_PROTECTION_ENABLED   Amazon EC2  EC2_ENIS_SOURCE_DESTINATION_CHECK_ENABLED   EC2_INSTANCE_LAUNCHED_WITH_ALLOWED_AMI   EC2_LAUNCH_TEMPLATES_EBS_VOLUME_ENCRYPTED   EC2_LAUNCH_TEMPLATE_IMDSV2_CHECK   EC2_LAUNCH_TEMPLATE_PUBLIC_IP_DISABLED   EC2_SECURITY_GROUP_ATTACHED_TO_ENI   EC2_SPOT_FLEET_REQUEST_CT_ENCRYPTION_AT_REST   EC2_STOPPED_INSTANCE_DAYS_CHECK_PVT   EC2_TRANSIT_GATEWAY_AUTO_VPC_ATTACH_DISABLED   EC2_VPN_CONNECTION_IKE_VERSION_CHECK   EC2_VPN_CONNECTION_LOGGING_ENABLED   INSTANCES_IN_VPC   Amazon EC2 Auto Scaling  AUTOSCALING_LAUNCH_TEMPLATE   AUTOSCALING_MULTIPLE_AZ   AUTOSCALING_MULTIPLE_INSTANCE_TYPES   Amazon ECR  ECR_PRIVATE_IMAGE_SCANNING_ENABLED   ECR_PRIVATE_LIFECYCLE_POLICY_CONFIGURED   ECR_PRIVATE_TAG_IMMUTABILITY_ENABLED   ECR_REPOSITORY_CMK_ENCRYPTION_ENABLED   Amazon ECS  ECS_CONTAINERS_NONPRIVILEGED   ECS_CONTAINERS_READONLY_ACCESS   ECS_CONTAINER_INSIGHTS_ENABLED   ECS_FARGATE_LATEST_PLATFORM_VERSION   ECS_NO_ENVIRONMENT_SECRETS   ECS_TASK_DEFINITION_EFS_ENCRYPTION_ENABLED   ECS_TASK_DEFINITION_LINUX_USER_NON_ROOT   ECS_TASK_DEFINITION_LOG_CONFIGURATION   ECS_TASK_DEFINITION_NETWORK_MODE_NOT_HOST   ECS_TASK_DEFINITION_PID_MODE_CHECK   ECS_TASK_DEFINITION_USER_FOR_HOST_MODE_CHECK   ECS_TASK_DEFINITION_WINDOWS_USER_NON_ADMIN   Amazon EFS  EFS_ACCESS_POINT_ENFORCE_ROOT_DIRECTORY   EFS_ACCESS_POINT_ENFORCE_USER_IDENTITY   EFS_AUTOMATIC_BACKUPS_ENABLED   EFS_FILESYSTEM_CT_ENCRYPTED   EFS_MOUNT_TARGET_PUBLIC_ACCESSIBLE   Amazon EKS  EKS_NODEGROUP_SUPPORTED_VERSION_CHECK   AWS Elastic Beanstalk   BEANSTALK_ENHANCED_HEALTH_REPORTING_ENABLED  Amazon ElastiCache  ELASTICACHE_AUTOMATIC_BACKUP_CHECK_ENABLED   ELASTICACHE_AUTO_MINOR_VERSION_UPGRADE_CHECK   ELASTICACHE_REPL_GRP_AUTO_FAILOVER_ENABLED   ELASTICACHE_REPL_GRP_ENCRYPTED_AT_REST   ELASTICACHE_SUBNET_GROUP_CHECK   ELASTICACHE_SUPPORTED_ENGINE_VERSION   Elastic Load Balancing  ALB_DESYNC_MODE_CHECK   CLB_DESYNC_MODE_CHECK   CLB_MULTIPLE_AZ   ELBV2_LISTENER_ENCRYPTION_IN_TRANSIT   ELBV2_MULTIPLE_AZ   ELBV2_PREDEFINED_SECURITY_POLICY_SSL_CHECK   NLB_CROSS_ZONE_LOAD_BALANCING_ENABLED   Amazon EMR  EMR_BLOCK_PUBLIC_ACCESS   Amazon EventBridge  CUSTOM_EVENTBUS_POLICY_ATTACHED   Amazon FSx  FSX_LUSTRE_COPY_TAGS_TO_BACKUPS   FSX_OPENZFS_COPY_TAGS_ENABLED   FSX_OPENZFS_DEPLOYMENT_TYPE_CHECK   FSX_WINDOWS_AUDIT_LOG_CONFIGURED   FSX_WINDOWS_DEPLOYMENT_TYPE_CHECK   AWS Glue  GLUE_ML_TRANSFORM_ENCRYPTED_AT_REST   Amazon GuardDuty  GUARDDUTY_ECS_PROTECTION_RUNTIME_ENABLED   GUARDDUTY_EKS_PROTECTION_AUDIT_ENABLED   GUARDDUTY_LAMBDA_PROTECTION_ENABLED   GUARDDUTY_MALWARE_PROTECTION_ENABLED   GUARDDUTY_RUNTIME_MONITORING_ENABLED   GUARDDUTY_S3_PROTECTION_ENABLED   IAM  IAM_EXTERNAL_ACCESS_ANALYZER_ENABLED   IAM_SERVER_CERTIFICATE_EXPIRATION_CHECK   Amazon Kendra  KENDRA_INDEX_TAGGED   Amazon Kinesis  KINESIS_FIREHOSE_DELIVERY_STREAM_ENCRYPTED   KINESIS_STREAM_BACKUP_RETENTION_CHECK   KINESIS_STREAM_ENCRYPTED   AWS KMS  KMS_KEY_POLICY_NO_PUBLIC_ACCESS   AWS Lambda  LAMBDA_FUNCTION_XRAY_ENABLED   LAMBDA_VPC_MULTI_AZ_CHECK   Amazon Neptune  NEPTUNE_CLUSTER_BACKUP_RETENTION_CHECK   NEPTUNE_CLUSTER_COPY_TAGS_TO_SNAPSHOT_ENABLED   NEPTUNE_CLUSTER_DELETION_PROTECTION_ENABLED   NEPTUNE_CLUSTER_ENCRYPTED   NEPTUNE_CLUSTER_IAM_DATABASE_AUTHENTICATION   NEPTUNE_CLUSTER_MULTI_AZ_ENABLED   NEPTUNE_CLUSTER_SNAPSHOT_ENCRYPTED   NEPTUNE_CLUSTER_SNAPSHOT_PUBLIC_PROHIBITED   AWS Network Firewall  NETFW_LOGGING_ENABLED   NETFW_SUBNET_CHANGE_PROTECTION_ENABLED   Amazon OpenSearch Service  OPENSEARCH_ENCRYPTED_AT_REST   OPENSEARCH_HTTPS_REQUIRED   OPENSEARCH_NODE_TO_NODE_ENCRYPTION_CHECK   Amazon RDS  MARIADB_PUBLISH_LOGS_TO_CLOUDWATCH_LOGS   RDS_AURORA_MYSQL_AUDIT_LOGGING_ENABLED   RDS_AURORA_POSTGRESQL_LOGS_TO_CLOUDWATCH   RDS_CLUSTER_DEFAULT_ADMIN_CHECK   RDS_CLUSTER_ENCRYPTED_AT_REST   RDS_GLOBAL_CLUSTER_AURORA_POSTGRESQL_SUPPORTED_VERSION   RDS_INSTANCE_DEFAULT_ADMIN_CHECK   RDS_INSTANCE_SUBNET_IGW_CHECK   RDS_MARIADB_INSTANCE_ENCRYPTED_IN_TRANSIT   RDS_MYSQL_INSTANCE_ENCRYPTED_IN_TRANSIT   RDS_PGSQL_CLUSTER_COPY_TAGS_TO_SNAPSHOT_CHECK   RDS_POSTGRESQL_LOGS_TO_CLOUDWATCH   RDS_POSTGRES_INSTANCE_ENCRYPTED_IN_TRANSIT   RDS_PROXY_TLS_ENCRYPTION   RDS_SNAPSHOT_ENCRYPTED  RDS_SQLSERVER_ENCRYPTED_IN_TRANSIT   RDS_SQL_SERVER_LOGS_TO_CLOUDWATCH   Amazon Redshift  REDSHIFT_CLUSTER_MULTI_AZ_ENABLED   REDSHIFT_CLUSTER_SUBNET_GROUP_MULTI_AZ   REDSHIFT_DEFAULT_ADMIN_CHECK   REDSHIFT_SERVERLESS_DEFAULT_ADMIN_CHECK   REDSHIFT_SERVERLESS_NAMESPACE_CMK_ENCRYPTION   REDSHIFT_SERVERLESS_PUBLISH_LOGS_TO_CLOUDWATCH   REDSHIFT_SERVERLESS_WORKGROUP_ENCRYPTED_IN_TRANSIT   REDSHIFT_SERVERLESS_WORKGROUP_NO_PUBLIC_ACCESS   REDSHIFT_SERVERLESS_WORKGROUP_ROUTES_WITHIN_VPC   REDSHIFT_UNRESTRICTED_PORT_ACCESS   Amazon S3  S3_ACCESS_POINT_IN_VPC_ONLY   S3_ACCESS_POINT_PUBLIC_ACCESS_BLOCKS   S3_BUCKET_ACL_PROHIBITED   S3_BUCKET_CROSS_REGION_REPLICATION_ENABLED   S3_BUCKET_MFA_DELETE_ENABLED   S3_EVENT_NOTIFICATIONS_ENABLED   S3_LIFECYCLE_POLICY_CHECK   S3_VERSION_LIFECYCLE_POLICY_CHECK   Amazon SageMaker  SAGEMAKER_ENDPOINT_CONFIG_KMS_KEY_REQUIRED   SAGEMAKER_FEATUREGROUP_ENCRYPTION_AT_REST   SAGEMAKER_FEATUREGROUP_ONLINE_STORE_ENCRYPTION   SAGEMAKER_INF_EXPERIMENT_DATA_STORAGE_KMS_ENCRYPTED   SAGEMAKER_INF_EXPERIMENT_INSTANCE_STORAGE_KMS_ENCRYPTED   SAGEMAKER_MODEL_EXPLAINABILITY_JOB_NETWORK_ISOLATION   SAGEMAKER_MODEL_MULTICONTAINER_PRIVATE_REGISTRY   SAGEMAKER_MODEL_PRIVATE_REGISTRY_REQUIRED   SAGEMAKER_MODEL_QUALITY_JOB_DEFINITION_ISOLATION   SAGEMAKER_MONITORING_SCHEDULE_TRAFFIC_ENCRYPTION   SAGEMAKER_NOTEBOOK_INSTANCE_INSIDE_VPC   SAGEMAKER_NOTEBOOK_INSTANCE_ROOT_ACCESS_CHECK   SAGEMAKER_NOTEBOOK_INSTANCE_STORAGE_VOL_KMS_ENCRYPTED   AWS Account Management  SECURITY_ACCOUNT_INFORMATION_PROVIDED   Amazon SNS  SNS_TOPIC_MESSAGE_DELIVERY_NOTIFICATION_ENABLED   SNS_TOPIC_NO_PUBLIC_ACCESS   Amazon SQS  SQS_QUEUE_DLQ_CHECK   SQS_QUEUE_NO_PUBLIC_ACCESS   SQS_QUEUE_POLICY_FULL_ACCESS_CHECK   AWS Systems Manager  SSM_AUTOMATION_BLOCK_PUBLIC_SHARING   SSM_AUTOMATION_LOGGING_ENABLED   AWS Transfer Family  TRANSFER_CONNECTOR_LOGGING_ENABLED   Amazon VPC  NACL_NO_UNRESTRICTED_SSH_RDP   VPC_ENDPOINT_ENABLED   VPC_PEERING_DNS_RESOLUTION_CHECK   VPC_SG_PORT_RESTRICTION_CHECK   AWS WAF  WAFV2_RULEGROUP_LOGGING_ENABLED   WAFV2_WEBACL_NOT_EMPTY 
aws.amazon.com
July 10, 2026 at 12:05 AM
🆕 AWS Config now supports 8 new resource types, including Amazon API Gateway, EC2, and S3 vectors, enhancing coverage and enabling better auditing and remediation across your AWS environment.

#AWS #AwsConfig
AWS Config now supports 8 new resource types
AWS Config now supports 8 additional AWS resource types across key services including Amazon API Gateway, Amazon EC2, and Amazon S3 Vectors. This expansion provides greater coverage over your AWS environment, enabling you to more effectively discover, assess, audit, and remediate an even broader range of resources. With this launch, if you have enabled recording for all resource types, then AWS Config will automatically track these new additions. The newly supported resource types are also available in Config rules and Config aggregators. You can now use AWS Config to monitor the following newly supported resource types in all AWS Regions where the resources are available: Resource Types: AWS::ApiGateway::DomainNameV2 AWS::ApiGatewayV2::VpcLink AWS::EC2::VPCEncryptionControl AWS::NetworkFirewall::ContainerAssociation AWS::OpenSearchServerless::SecurityPolicy AWS::OSIS::Pipeline AWS::S3Vectors::VectorBucket AWS::S3Vectors::VectorBucketPolicy
aws.amazon.com
July 2, 2026 at 6:10 PM
🆕 AWS Config now supports 5 new resource types: AWS::CodeArtifact::Domain, AWS::Config::ConformancePack, AWS::Glue::Database, AWS::NetworkManager::TransitGatewayPeering, and AWS::RolesAnywhere::TrustAnchor, enhancing environment coverage and audit capabilities.

#AWS #AwsConfig
AWS Config now supports 5 new resource types
AWS Config now supports 5 additional AWS resource types. This expansion provides greater coverage over your AWS environment, enabling you to more effectively discover, assess, audit, and remediate an even broader range of resources. With this launch, if you have enabled recording for all resource types, then AWS Config will automatically track these new additions. The newly supported resource types are also available in Config rules and Config aggregators. You can now use AWS Config to monitor the following newly supported resource types in all AWS Regions where the supported resources are available. Resource Types: AWS::CodeArtifact::Domain AWS::Config::ConformancePack AWS::Glue::Database AWS::NetworkManager::TransitGatewayPeering AWS::RolesAnywhere::TrustAnchor
aws.amazon.com
September 3, 2025 at 6:40 PM
🆕 AWS Config now supports 3 new resource types: AWS::ApiGatewayV2::Integration, AWS::CloudTrail::EventDataStore, and AWS::Config::StoredQuery, enhancing coverage and enabling better auditing and remediation across your AWS environment.

#AWS #AwsGovcloudUs #AwsConfig
AWS Config now supports 3 new resource types
AWS Config now supports 3 additional AWS resource types. This expansion provides greater coverage over your AWS environment, enabling you to more effectively discover, assess, audit, and remediate an even broader range of resources. With this launch, if you have enabled recording for all resource types, then AWS Config will automatically track these new additions. The newly supported resource types are also available in Config rules and Config aggregators. You can now use AWS Config to monitor the following newly supported resource types in all AWS Regions where the supported resources are available: Resource Types: AWS::ApiGatewayV2::Integration AWS::CloudTrail::EventDataStore AWS::Config::StoredQuery
aws.amazon.com
October 13, 2025 at 10:41 PM
🆕 AWS Config now supports 52 new resource types, including Amazon EC2, Bedrock, and SageMaker, enhancing monitoring and auditing across your AWS environment. If recording is enabled, these new types are automatically tracked.

#AWS #AwsConfig
AWS Config now supports 52 new resource types
AWS Config now supports 52 additional AWS resource types across key services including Amazon EC2, Amazon Bedrock, and Amazon SageMaker. This expansion provides greater coverage over your AWS environment, enabling you to more effectively discover, assess, audit, and remediate an even broader range of resources. With this launch, if you have enabled recording for all resource types, then AWS Config will automatically track these new additions. The newly supported resource types are also available in Config rules and Config aggregators. You can now use AWS Config to monitor the following newly supported resource types in all AWS Regions where the supported resources are available: Resource Types   AWS::ApiGateway::DomainName AWS::IAM::GroupPolicy AWS::ApiGateway::Method AWS::IAM::RolePolicy AWS::ApiGateway::UsagePlan AWS::IAM::UserPolicy AWS::AppConfig::Extension AWS::IoTCoreDeviceAdvisor::SuiteDefinition AWS::Bedrock::ApplicationInferenceProfile AWS::MediaPackageV2::Channel AWS::Bedrock::Prompt AWS::MediaPackageV2::ChannelGroup AWS::BedrockAgentCore::BrowserCustom AWS::MediaTailor::LiveSource AWS::BedrockAgentCore::CodeInterpreterCustom         AWS::MSK::ServerlessCluster AWS::BedrockAgentCore::Runtime AWS::PaymentCryptography::Alias AWS::CloudFormation::LambdaHook AWS::PaymentCryptography::Key AWS::CloudFormation::StackSet AWS::RolesAnywhere::CRL AWS::Comprehend::Flywheel AWS::RolesAnywhere::Profile AWS::Config::AggregationAuthorization AWS::S3::AccessGrant AWS::DataSync::Agent AWS::S3::AccessGrantsInstance AWS::Deadline::Fleet AWS::S3::AccessGrantsLocation AWS::Deadline::QueueFleetAssociation AWS::SageMaker::DataQualityJobDefinition AWS::EC2::IPAMPoolCidr AWS::SageMaker::MlflowTrackingServer AWS::EC2::SubnetNetworkAclAssociation AWS::SageMaker::ModelBiasJobDefinition AWS::EC2::VPCGatewayAttachment AWS::SageMaker::ModelExplainabilityJobDefinition AWS::ECR::RepositoryCreationTemplate AWS::SageMaker::ModelQualityJobDefinition AWS::ElasticLoadBalancingV2::TargetGroup AWS::SageMaker::MonitoringSchedule AWS::EMR::Studio AWS::SageMaker::StudioLifecycleConfig AWS::EMRContainers::VirtualCluster AWS::SecretsManager::RotationSchedule AWS::EMRServerless::Application AWS::SES::DedicatedIpPool AWS::EntityResolution::MatchingWorkflow AWS::SES::MailManagerTrafficPolicy AWS::Glue::Registry AWS::SSM::ResourceDataSync To view the complete list of AWS Config supported resource types, see the supported resource types page.
aws.amazon.com
November 3, 2025 at 9:40 PM
🆕 AWS Config now links rules to CIS, FedRAMP, and NIST frameworks, leveraging AWS Control Tower's Control Catalog for streamlined compliance across AWS Config and Control Tower, available in all commercial regions.

#AWS #AwsControlTower #AwsConfig
AWS Config rules add classifications from AWS Control Tower Control Catalog
Today, AWS Config rules adds classification information from AWS Control Tower Control Catalog to make it easier for you to identify how Config rules map to different compliance frameworks such as CIS-v8.0, FedRAMP-r4, and NIST-CSF-v1.1. AWS Config rules help you automatically evaluate your AWS resource configurations for desired settings, enabling you to assess, audit, and evaluate configurations of your AWS resources. Control Catalog is a feature of AWS Control Tower that enables you to search AWS managed controls and their associated compliance frameworks. Control Catalog has classifications including Domain (such as "Data Protection"), Objective (such as "Data Encryption"), and common control (such as "Encrypt data at rest") to help you better understand the purpose of a control. Today’s launch maps AWS Config rules to the specific compliance frameworks available in AWS Control Tower Control Catalog (CIS-v8.0, FedRAMP-r4, ISO-IEC-27001:2013-Annex-A, NIST-CSF-v1.1, NIST-SP-800-171-r2, PCI-DSS-v4.0, SSAE-18-SOC-2-Oct-2023), adding classification information (Domain, Objective, common control) to each AWS Config rule. If you're using AWS Config, you'll now see the same classification information in the AWS Config Console and in the AWS Control Tower Control Catalog, ensuring a unified experience across your AWS environment. This alignment between AWS Control Tower and AWS Config allows for seamless integration and more efficient management of your compliance and security posture. AWS Config rules with classifications from AWS Control Tower Control Catalog are available in all AWS Commercial regions where AWS Config and AWS Control Tower are available. To learn more about AWS Config rules and compliance frameworks, visit the AWS Config documentation.
aws.amazon.com
June 30, 2025 at 8:11 PM
AWS Config now supports 21 new resource types

AWS Config now supports 21 additional AWS resource types across key services including Amazon EC2, Amazon SageMaker, and Amazon S3 Tables. This expansion provides greater coverage over your AWS environment, enabling ...

#AWS #AwsConfig #AwsGovcloudUs
AWS Config now supports 21 new resource types
AWS Config now supports 21 additional AWS resource types across key services including Amazon EC2, Amazon SageMaker, and Amazon S3 Tables. This expansion provides greater coverage over your AWS environment, enabling you to more effectively discover, assess, audit, and remediate an even broader range of resources. With this launch, if you have enabled recording for all resource types, then AWS Config will automatically track these new additions. The newly supported resource types are also available in Config rules and Config aggregators. You can now use AWS Config to monitor the following newly supported resource types in all https://docs.aws.amazon.com/config/latest/developerguide/what-is-resource-config-coverage.html where the supported resources are available: Resource Types: AWS::AppStream::AppBlockBuilder AWS::IoT::ThingGroup AWS::B2BI::Capability AWS::IoTSiteWise::Asset AWS::CleanRoomsML::TrainingDataset AWS::Location::APIKey AWS::CloudFront::KeyValueStore AWS::MediaPackageV2::OriginEndpoint AWS::Connect::SecurityProfile AWS::PCAConnectorAD::Connector AWS::Deadline::Monitor AWS::Route53::DNSSEC AWS::EC2::SubnetCidrBlock AWS::S3Tables::TableBucketPolicy AWS::ECR::ReplicationConfiguration AWS::SageMaker::UserProfile AWS::GameLift::Build AWS::SecretsManager::ResourcePolicy AWS::GuardDuty::MalwareProtectionPlan       AWS::SSMContacts::Contact AWS::ImageBuilder::LifecyclePolicy  
aws.amazon.com
January 6, 2026 at 4:05 PM
AWS Config now supports 3 new resource types

AWS Config now supports 3 additional AWS resource types. This expansion provides greater coverage over your AWS environment, enabling you to more effectively discover, assess, audit, and remediate an even broader rang...

#AWS #AwsGovcloudUs #AwsConfig
AWS Config now supports 3 new resource types
AWS Config now supports 3 additional AWS resource types. This expansion provides greater coverage over your AWS environment, enabling you to more effectively discover, assess, audit, and remediate an even broader range of resources. With this launch, if you have enabled recording for all resource types, then AWS Config will automatically track these new additions. The newly supported resource types are also available in Config rules and Config aggregators. You can now use AWS Config to monitor the following newly supported resource types in all https://docs.aws.amazon.com/config/latest/developerguide/what-is-resource-config-coverage.html where the supported resources are available: Resource Types: AWS::ApiGatewayV2::Integration AWS::CloudTrail::EventDataStore AWS::Config::StoredQuery
aws.amazon.com
October 13, 2025 at 11:05 PM
🆕 AWS Config's advanced queries and aggregators are now in Asia Pacific (New Zealand), offering centralized visibility and compliance analysis across accounts and regions. Use them via AWS console and CLI. Available globally.

#AWS #AwsConfig
AWS Config advanced query and aggregator now available in Asia Pacific (New Zealand) Region
AWS Config advanced queries and aggregators are now available in Asia Pacific (New Zealand) region. You can use advanced queries to query the current configuration and compliance state of your AWS resources. Aggregators enable centralized visibility and analysis by aggregating configuration and compliance data from multiple accounts and regions, or across an AWS Organization. Advanced queries provide a single query endpoint and a query language to get current resource configuration and compliance state without performing service-specific describe API calls. You can use configuration aggregators to run the same queries from a central account across multiple accounts and AWS Regions. Advanced queries can be used from AWS console and AWS CLI. To learn more about aggregators, please refer to our documentation. With this expansion, AWS Config advanced queries and aggregators are now available in all supported regions.
aws.amazon.com
October 2, 2025 at 8:40 PM
AWS Config advanced query and aggregator now available in Asia Pacific (New Zealand) Region

AWS Config advanced queries and aggregators are now available in Asia Pacific (New Zealand) region. You can use advanced queries to query the current configuration and compliance state ...

#AWS #AwsConfig
AWS Config advanced query and aggregator now available in Asia Pacific (New Zealand) Region
AWS Config advanced queries and aggregators are now available in Asia Pacific (New Zealand) region. You can use advanced queries to query the current configuration and compliance state of your AWS resources. Aggregators enable centralized visibility and analysis by aggregating configuration and compliance data from multiple accounts and regions, or across an AWS Organization. Advanced queries provide a single query endpoint and a query language to get current resource configuration and compliance state without performing service-specific describe API calls. You can use configuration aggregators to run the same queries from a central account across multiple accounts and AWS Regions. Advanced queries can be used from https://docs.aws.amazon.com/config/latest/developerguide/query-using-sql-editor-console.html and https://docs.aws.amazon.com/config/latest/developerguide/query-using-sql-editor-cli.html. To learn more about aggregators, please refer to our https://docs.aws.amazon.com/config/latest/developerguide/aggregate-data.html. With this expansion, AWS Config advanced queries and aggregators are now available in https://docs.aws.amazon.com/config/latest/developerguide/aggregate-data.html#aggregation-regions.
aws.amazon.com
October 2, 2025 at 9:05 PM
AWS Config now supports 52 new resource types

AWS Config now supports 52 additional AWS resource types across key services including Amazon EC2, Amazon Bedrock, and Amazon SageMaker. This expansion provides greater coverage over your AWS environment, enabling you to more effec...

#AWS #AwsConfig
AWS Config now supports 52 new resource types
AWS Config now supports 52 additional AWS resource types across key services including Amazon EC2, Amazon Bedrock, and Amazon SageMaker. This expansion provides greater coverage over your AWS environment, enabling you to more effectively discover, assess, audit, and remediate an even broader range of resources. With this launch, if you have enabled recording for all resource types, then AWS Config will automatically track these new additions. The newly supported resource types are also available in Config rules and Config aggregators. You can now use AWS Config to monitor the following newly supported resource types in all https://docs.aws.amazon.com/config/latest/developerguide/what-is-resource-config-coverage.html where the supported resources are available: Resource Types   AWS::ApiGateway::DomainName AWS::IAM::GroupPolicy AWS::ApiGateway::Method AWS::IAM::RolePolicy AWS::ApiGateway::UsagePlan AWS::IAM::UserPolicy AWS::AppConfig::Extension AWS::IoTCoreDeviceAdvisor::SuiteDefinition AWS::Bedrock::ApplicationInferenceProfile AWS::MediaPackageV2::Channel AWS::Bedrock::Prompt AWS::MediaPackageV2::ChannelGroup AWS::BedrockAgentCore::BrowserCustom AWS::MediaTailor::LiveSource AWS::BedrockAgentCore::CodeInterpreterCustom         AWS::MSK::ServerlessCluster AWS::BedrockAgentCore::Runtime AWS::PaymentCryptography::Alias AWS::CloudFormation::LambdaHook AWS::PaymentCryptography::Key AWS::CloudFormation::StackSet AWS::RolesAnywhere::CRL AWS::Comprehend::Flywheel AWS::RolesAnywhere::Profile AWS::Config::AggregationAuthorization AWS::S3::AccessGrant AWS::DataSync::Agent AWS::S3::AccessGrantsInstance AWS::Deadline::Fleet AWS::S3::AccessGrantsLocation AWS::Deadline::QueueFleetAssociation AWS::SageMaker::DataQualityJobDefinition AWS::EC2::IPAMPoolCidr AWS::SageMaker::MlflowTrackingServer AWS::EC2::SubnetNetworkAclAssociation AWS::SageMaker::ModelBiasJobDefinition AWS::EC2::VPCGatewayAttachment AWS::SageMaker::ModelExplainabilityJobDefinition AWS::ECR::RepositoryCreationTemplate AWS::SageMaker::ModelQualityJobDefinition AWS::ElasticLoadBalancingV2::TargetGroup AWS::SageMaker::MonitoringSchedule AWS::EMR::Studio AWS::SageMaker::StudioLifecycleConfig AWS::EMRContainers::VirtualCluster AWS::SecretsManager::RotationSchedule AWS::EMRServerless::Application AWS::SES::DedicatedIpPool AWS::EntityResolution::MatchingWorkflow AWS::SES::MailManagerTrafficPolicy AWS::Glue::Registry AWS::SSM::ResourceDataSync To view the complete list of AWS Config supported resource types, see the https://docs.aws.amazon.com/config/latest/developerguide/resource-config-reference.html page.
aws.amazon.com
November 3, 2025 at 10:05 PM
🆕 AWS Config adds 42 new managed rules for security, cost, and operations. Enable controls across accounts or organizations, assess tagging strategies, and streamline multi-account governance with Conformance Packs. For details, visit AWS Config documentation.

#AWS #AwsConfig
AWS Config launches 42 new managed rules
AWS Config announces launch of an additional 42 managed Config rules for various use cases such as security, cost, durability, and operations. You can now search, discover, enable and manage these additional rules directly from AWS Config and govern more use cases for your AWS environment. With this launch, you can now enable these controls across your account or across your organization. For example, you can evaluate your tagging strategies across Amazon EKS Fargate profiles, Amazon EC2 Network Insight Analyses, AWS Glue Machine learning transforms. Or you can assess your security posture across Amazon Cognito Identity pools, Amazon Lightsail buckets, AWS Amplify apps and more. Additionally, you can leverage Conformance Packs to group these new controls and deploy across an account or across organization, streamlining your multi-account governance. For the full list of recently released rules, visit the AWS Config developer guide. For description of each rule and the AWS Regions in which it is available, please refer our Config managed rules documentation. To start using Config rules, please refer our documentation. New Rules Launched: AMPLIFY_APP_NO_ENVIRONMENT_VARIABLES AMPLIFY_BRANCH_DESCRIPTION APIGATEWAY_STAGE_DESCRIPTION APIGATEWAYV2_STAGE_DESCRIPTION API_GWV2_STAGE_DEFAULT_ROUTE_DETAILED_METRICS_ENABLED APIGATEWAY_STAGE_ACCESS_LOGS_ENABLED APPCONFIG_DEPLOYMENT_STRATEGY_MINIMUM_FINAL_BAKE_TIME APPCONFIG_DEPLOYMENT_STRATEGY_TAGGED APPFLOW_FLOW_TRIGGER_TYPE_CHECK APPMESH_VIRTUAL_NODE_CLOUD_MAP_IP_PREF_CHECK APPMESH_VIRTUAL_NODE_DNS_IP_PREF_CHECK APPRUNNER_SERVICE_IP_ADDRESS_TYPE_CHECK APPRUNNER_SERVICE_MAX_UNHEALTHY_THRESHOLD APS_RULE_GROUPS_NAMESPACE_TAGGED AUDITMANAGER_ASSESSMENT_TAGGED BATCH_MANAGED_COMPUTE_ENV_ALLOCATION_STRATEGY_CHECK BATCH_MANAGED_SPOT_COMPUTE_ENVIRONMENT_MAX_BID COGNITO_IDENTITY_POOL_UNAUTHENTICATED_LOGINS COGNITO_USER_POOL_PASSWORD_POLICY_CHECK CUSTOMERPROFILES_DOMAIN_TAGGED DEVICEFARM_PROJECT_TAGGED DEVICEFARM_TEST_GRID_PROJECT_TAGGED DMS_REPLICATION_INSTANCE_MULTI_AZ_ENABLED EC2_LAUNCH_TEMPLATES_EBS_VOLUME_ENCRYPTED EC2_NETWORK_INSIGHTS_ANALYSIS_TAGGED EKS_FARGATE_PROFILE_TAGGED GLUE_ML_TRANSFORM_TAGGED IOT_SCHEDULED_AUDIT_TAGGED IOT_PROVISIONING_TEMPLATE_DESCRIPTION IOT_PROVISIONING_TEMPLATE_JITP IOT_PROVISIONING_TEMPLATE_TAGGED KINESIS_VIDEO_STREAM_MINIMUM_DATA_RETENTION LAMBDA_FUNCTION_DESCRIPTION LIGHTSAIL_BUCKET_ALLOW_PUBLIC_OVERRIDES_DISABLED RDS_MYSQL_CLUSTER_COPY_TAGS_TO_SNAPSHOT_CHECK RDS_PGSQL_CLUSTER_COPY_TAGS_TO_SNAPSHOT_CHECK ROUTE53_RESOLVER_FIREWALL_DOMAIN_LIST_TAGGED ROUTE53_RESOLVER_FIREWALL_RULE_GROUP_ASSOCIATION_TAGGED ROUTE53_RESOLVER_FIREWALL_RULE_GROUP_TAGGED ROUTE53_RESOLVER_RESOLVER_RULE_TAGGED RUM_APP_MONITOR_TAGGED RUM_APP_MONITOR_CLOUDWATCH_LOGS_ENABLED
aws.amazon.com
November 4, 2025 at 6:40 PM
AWS Config conformance packs now available in additional AWS Regions

AWS Config conformance packs and organization-level management capabilities for conformance packs are now available in additional AWS Regions. Conformance packs allow you to bundle AWS Config rules into a sin...

#AWS #AwsConfig
AWS Config conformance packs now available in additional AWS Regions
AWS Config conformance packs and organization-level management capabilities for conformance packs are now available in additional AWS Regions. Conformance packs allow you to bundle AWS Config rules into a single package, simplifying deployment at scale. You can deploy and manage these conformance packs throughout your AWS environment. Conformance packs provide a general-purpose compliance framework designed to enable you to create security, operational, or cost-optimization governance checks using managed or custom AWS Config rules. This allows you to monitor compliance scores based on your own groupings. With this launch, you can also manage the AWS Config conformance packs and individual AWS Config rules at the organization level which simplifies the compliance management across your AWS Organization. With this expansion, AWS Config Conformance Packs are now also available in the following AWS Regions: Asia Pacific (Malaysia), Asia Pacific (New Zealand), Asia Pacific (Thailand), Asia Pacific (Taipei) and Mexico (Central). To get started, you can either use the provided https://docs.aws.amazon.com/config/latest/developerguide/conformancepack-sample-templates.html templates or craft a custom YAML file from scratch based on a https://docs.aws.amazon.com/config/latest/developerguide/custom-conformance-pack.html. Conformance pack deployment can be done through the AWS Config console, AWS CLI, or via AWS CloudFormation. You will be charged per conformance pack evaluation in your AWS account per AWS Region. Visit the AWS Config https://aws.amazon.com/config/pricing/ for more details. To learn more about AWS Config conformance packs, see our https://docs.aws.amazon.com/config/latest/developerguide/conformance-packs.html.
aws.amazon.com
November 4, 2025 at 8:05 PM
AWS Config now supports resource tags for IAM Policies

AWS Config now tracks resource tags for IAM policy resource types, enhancing the granularity of metadata you can capture to assess, audit, and evaluate configurations of your IAM policies.

With this enhancement, you c...

#AWS #AwsConfig
AWS Config now supports resource tags for IAM Policies
AWS Config now tracks resource tags for IAM policy resource types, enhancing the granularity of metadata you can capture to assess, audit, and evaluate configurations of your IAM policies. With this enhancement, you can now track resource tags and their changes for IAM Policies directly in your Config recorder. This capability allows you to scope both Config-managed and custom rule evaluations based on resource tags, ensuring your IAM policies maintain desired configurations. Additionally, you can leverage Config aggregators to selectively aggregate IAM policies across multiple accounts using tags, streamlining your multi-account governance. This feature is now available across all supported https://docs.aws.amazon.com/config/latest/developerguide/config-region-support.html#config-region-support-list at no additional cost. Resource tags are automatically populated in Config when you record IAM policy resource types. For recording IAM policy resource type in your Config recorder, please refer our https://docs.aws.amazon.com/config/latest/developerguide/managing-recorder_console-start.html.
aws.amazon.com
September 8, 2025 at 2:05 PM
AWS Config now supports 5 new resource types

AWS Config now supports 5 additional AWS resource types. This expansion provides greater coverage over your AWS environment, enabling you to more effectively discover, assess, audit, and remediate an even broader range of resources....

#AWS #AwsConfig
AWS Config now supports 5 new resource types
AWS Config now supports 5 additional AWS resource types. This expansion provides greater coverage over your AWS environment, enabling you to more effectively discover, assess, audit, and remediate an even broader range of resources. With this launch, if you have enabled recording for all resource types, then AWS Config will automatically track these new additions. The newly supported resource types are also available in Config rules and Config aggregators. You can now use AWS Config to monitor the following newly supported resource types in all https://docs.aws.amazon.com/config/latest/developerguide/what-is-resource-config-coverage.html where the supported resources are available. Resource Types: AWS::CodeArtifact::Domain AWS::Config::ConformancePack AWS::Glue::Database AWS::NetworkManager::TransitGatewayPeering AWS::RolesAnywhere::TrustAnchor
aws.amazon.com
September 3, 2025 at 7:05 PM
AWS Config launches 42 new managed rules

AWS Config announces launch of an additional 42 managed Config rules for various use cases such as security, cost, durability, and operations. You can now search, discover, enable and manage these additional rules directly from AWS Conf...

#AWS #AwsConfig
AWS Config launches 42 new managed rules
AWS Config announces launch of an additional 42 managed Config rules for various use cases such as security, cost, durability, and operations. You can now search, discover, enable and manage these additional rules directly from AWS Config and govern more use cases for your AWS environment. With this launch, you can now enable these controls across your account or across your organization. For example, you can evaluate your tagging strategies across Amazon EKS Fargate profiles, Amazon EC2 Network Insight Analyses, AWS Glue Machine learning transforms. Or you can assess your security posture across Amazon Cognito Identity pools, Amazon Lightsail buckets, AWS Amplify apps and more. Additionally, you can leverage Conformance Packs to group these new controls and deploy across an account or across organization, streamlining your multi-account governance. For the full list of recently released rules, visit the https://docs.aws.amazon.com/config/latest/developerguide/DocumentHistory.html. For description of each rule and the AWS Regions in which it is available, please refer our https://docs.aws.amazon.com/config/latest/developerguide/managed-rules-by-aws-config.html. To start using Config rules, please refer our https://docs.aws.amazon.com/config/latest/developerguide/evaluate-config_add-rules.html. New Rules Launched: AMPLIFY_APP_NO_ENVIRONMENT_VARIABLES AMPLIFY_BRANCH_DESCRIPTION APIGATEWAY_STAGE_DESCRIPTION APIGATEWAYV2_STAGE_DESCRIPTION API_GWV2_STAGE_DEFAULT_ROUTE_DETAILED_METRICS_ENABLED APIGATEWAY_STAGE_ACCESS_LOGS_ENABLED APPCONFIG_DEPLOYMENT_STRATEGY_MINIMUM_FINAL_BAKE_TIME APPCONFIG_DEPLOYMENT_STRATEGY_TAGGED APPFLOW_FLOW_TRIGGER_TYPE_CHECK APPMESH_VIRTUAL_NODE_CLOUD_MAP_IP_PREF_CHECK APPMESH_VIRTUAL_NODE_DNS_IP_PREF_CHECK APPRUNNER_SERVICE_IP_ADDRESS_TYPE_CHECK APPRUNNER_SERVICE_MAX_UNHEALTHY_THRESHOLD APS_RULE_GROUPS_NAMESPACE_TAGGED AUDITMANAGER_ASSESSMENT_TAGGED BATCH_MANAGED_COMPUTE_ENV_ALLOCATION_STRATEGY_CHECK BATCH_MANAGED_SPOT_COMPUTE_ENVIRONMENT_MAX_BID COGNITO_IDENTITY_POOL_UNAUTHENTICATED_LOGINS COGNITO_USER_POOL_PASSWORD_POLICY_CHECK CUSTOMERPROFILES_DOMAIN_TAGGED DEVICEFARM_PROJECT_TAGGED DEVICEFARM_TEST_GRID_PROJECT_TAGGED DMS_REPLICATION_INSTANCE_MULTI_AZ_ENABLED EC2_LAUNCH_TEMPLATES_EBS_VOLUME_ENCRYPTED EC2_NETWORK_INSIGHTS_ANALYSIS_TAGGED EKS_FARGATE_PROFILE_TAGGED GLUE_ML_TRANSFORM_TAGGED IOT_SCHEDULED_AUDIT_TAGGED IOT_PROVISIONING_TEMPLATE_DESCRIPTION IOT_PROVISIONING_TEMPLATE_JITP IOT_PROVISIONING_TEMPLATE_TAGGED KINESIS_VIDEO_STREAM_MINIMUM_DATA_RETENTION LAMBDA_FUNCTION_DESCRIPTION LIGHTSAIL_BUCKET_ALLOW_PUBLIC_OVERRIDES_DISABLED RDS_MYSQL_CLUSTER_COPY_TAGS_TO_SNAPSHOT_CHECK RDS_PGSQL_CLUSTER_COPY_TAGS_TO_SNAPSHOT_CHECK ROUTE53_RESOLVER_FIREWALL_DOMAIN_LIST_TAGGED ROUTE53_RESOLVER_FIREWALL_RULE_GROUP_ASSOCIATION_TAGGED ROUTE53_RESOLVER_FIREWALL_RULE_GROUP_TAGGED ROUTE53_RESOLVER_RESOLVER_RULE_TAGGED RUM_APP_MONITOR_TAGGED RUM_APP_MONITOR_CLOUDWATCH_LOGS_ENABLED
aws.amazon.com
November 4, 2025 at 7:05 PM
AWS Config rules add classifications from AWS Control Tower Control Catalog

Today, AWS Config rules adds classification information from AWS Control Tower Control Catalog to make it easier for you to identify how Config rules map to different compliance framew...

#AWS #AwsControlTower #AwsConfig
AWS Config rules add classifications from AWS Control Tower Control Catalog
Today, AWS Config rules adds classification information from AWS Control Tower Control Catalog to make it easier for you to identify how Config rules map to different compliance frameworks such as CIS-v8.0, FedRAMP-r4, and NIST-CSF-v1.1. AWS Config rules help you automatically evaluate your AWS resource configurations for desired settings, enabling you to assess, audit, and evaluate configurations of your AWS resources. Control Catalog is a feature of AWS Control Tower that enables you to search AWS managed controls and their associated compliance frameworks. Control Catalog has classifications including Domain (such as "Data Protection"), Objective (such as "Data Encryption"), and common control (such as "Encrypt data at rest") to help you better understand the purpose of a control. Today’s launch maps AWS Config rules to the specific compliance frameworks available in AWS Control Tower Control Catalog (CIS-v8.0, FedRAMP-r4, ISO-IEC-27001:2013-Annex-A, NIST-CSF-v1.1, NIST-SP-800-171-r2, PCI-DSS-v4.0, SSAE-18-SOC-2-Oct-2023), adding classification information (Domain, Objective, common control) to each AWS Config rule. If you're using AWS Config, you'll now see the same classification information in the AWS Config Console and in the AWS Control Tower Control Catalog, ensuring a unified experience across your AWS environment. This alignment between AWS Control Tower and AWS Config allows for seamless integration and more efficient management of your compliance and security posture. AWS Config rules with classifications from AWS Control Tower Control Catalog are available in all AWS Commercial regions where AWS Config and AWS Control Tower are available. To learn more about AWS Config rules and compliance frameworks, visit the AWS Config https://docs.aws.amazon.com/config/latest/developerguide/evaluate-config.html.
aws.amazon.com
June 30, 2025 at 8:05 PM
🆕 AWS Control Tower now supports seven new compliance frameworks: CIS-v8.0, FedRAMP-r4, ISO-IEC-27001, NIST-CSF, NIST-SP-800-171, PCI-DSS, and SSAE-18-SOC-2. This enhances Control Catalog for easier compliance management and mapping to domains, objectives, and common controls.

#AWS #AwsConfig
AWS Control Tower now supports seven new compliance frameworks
Today, AWS announces that AWS Control Tower supports seven new compliance frameworks in Control Catalog. Control Catalog is the central place in AWS for searching and enabling managed controls.In addition to existing frameworks, controls are now mapped to CIS-v8.0, FedRAMP-r4, ISO-IEC-27001:2013-Annex-A, NIST-CSF-v1.1, NIST-SP-800-171-r2, PCI-DSS-v4.0, SSAE-18-SOC-2-Oct-2023. To get started, navigate to the Control Catalog in AWS Control Tower and search for a framework like PCI-DSS-v4.0 to view related controls. This feature helps you meet your compliance requirements faster and with higher confidence. For programmatic access, utilize the new ListControlMappings API to search controls by frameworks, and take advantage of the updated ListControls and GetControl APIs, which now support GovernedResources, to understand the resource types governed by each control. We've also introduced a new classification system to help you better comprehend and manage controls. In addition to the new frameworks, controls in Control Catalog are now mapped to a domain (e.g., "Data Protection"), an objective (e.g., "Data Encryption"), and a common control (e.g., "Encrypt data at rest"). This clearer structure simplifies the process of understanding, searching, and deploying the controls you need. If you're using AWS Config, now you'll see the same comprehensive mapping of Config rules to compliance frameworks, domains, objectives, and common controls that you find in AWS Control Tower, ensuring a unified experience across your AWS environment. You can use Control Catalog with new mappings in all AWS Regions where AWS Control Tower is available, including AWS GovCloud (US). To learn more, visit AWS Control Tower User Guide.
aws.amazon.com
June 13, 2025 at 8:40 PM
🆕 AWS Config now supports 60 new resource types, including Amazon Bedrock, EC2, SageMaker, and Organizations, enhancing monitoring and auditing across your AWS environment.

#AWS #AwsConfig
AWS Config now supports 60 new resource types
AWS Config now supports 60 additional AWS resource types across key services including Amazon Bedrock,  Amazon EC2, Amazon SageMaker, and AWS Organizations. This expansion provides greater coverage over your AWS environment, enabling you to more effectively discover, assess, audit, and remediate an even broader range of resources. With this launch, if you have enabled recording for all resource types, then AWS Config will automatically track these new additions. The newly supported resource types are also available in Config rules and Config aggregators. You can now use AWS Config to monitor the following newly supported resource types in all AWS Regions where the resources are available: Resource Types: AWS::AppSync::ChannelNamespace AWS::EC2::RouteServer AWS::Organizations::Policy AWS::AppSync::SourceApiAssociation AWS::EC2::RouteServerEndpoint AWS::Organizations::ResourcePolicy AWS::Bedrock::EnforcedGuardrailConfiguration AWS::EC2::RouteServerPeer AWS::QuickSight::RefreshSchedule AWS::Bedrock::Flow AWS::EKS::PodIdentityAssociation AWS::RDS::DBProxy AWS::Bedrock::FlowVersion AWS::ElasticLoadBalancingV2::ListenerRule AWS::S3Vectors::Index AWS::Bedrock::PromptVersion AWS::GameLiftStreams::Application AWS::SageMaker::Action AWS::BedrockAgentCore::OAuth2CredentialProvider AWS::GameLiftStreams::StreamGroup AWS::SageMaker::Algorithm AWS::BedrockAgentCore::PaymentManager AWS::IdentityStore::Group AWS::SageMaker::App AWS::BedrockAgentCore::Policy AWS::IoT::TopicRuleDestination AWS::SageMaker::Context AWS::BedrockAgentCore::PolicyEngine AWS::Lightsail::Container AWS::SageMaker::Hub AWS::BedrockAgentCore::TokenVault AWS::Lightsail::Database AWS::SageMaker::MlflowApp AWS::Chime::AppInstance AWS::Lightsail::Distribution AWS::SageMaker::ModelCard AWS::CloudTrail::ResourcePolicy AWS::Lightsail::Domain AWS::SageMaker::ModelPackage AWS::CodePipeline::Webhook AWS::Lightsail::Instance AWS::SES::MailManagerArchive AWS::Config::OrganizationConformancePack AWS::Lightsail::LoadBalancer AWS::Transfer::WebApp AWS::Connect::AgentStatus AWS::Logs::ResourcePolicy AWS::WorkSpacesWeb::TrustStore AWS::Connect::EvaluationForm AWS::MediaConnect::Bridge AWS::WorkSpacesWeb::UserAccessLoggingSettings AWS::Connect::View AWS::NetworkManager::CoreNetwork AWS::XRay::Group AWS::Connect::ViewVersion AWS::Organizations::Account AWS::XRay::ResourcePolicy AWS::EC2::NetworkPerformanceMetricSubscription AWS::Organizations::Organization AWS::XRay::SamplingRule
aws.amazon.com
September 2, 2026 at 6:10 PM