Config compliance results proving the ports you declared unnecessary are not reachable from the internet and the software you declared prohibited is not installed, plus the actual installed-application set a periodic review has to read
The API supplies the facts, but a human judgement against a documented baseline turns them into evidence.
Fetch
$ aws configservice get-compliance-details-by-config-rule --config-rule-name restricted-common-ports --compliance-types NON_COMPLIANT$ aws configservice get-compliance-details-by-config-rule --config-rule-name ec2-managedinstance-applications-blacklisted --compliance-types NON_COMPLIANT$ aws ssm list-inventory-entries --instance-id i-0123456789abcdef0 --type-name AWS:ApplicationExpected output
Two EvaluationResults arrays plus an inventory listing. Empty NON_COMPLIANT sets mean no security group opens a blocked TCP port to 0.0.0.0/0 or ::/0 and none of the denylisted applications is installed on any evaluated managed node; the Entries list, stamped with its CaptureTime, is the installed-software set your periodic review actually reads. Managed rule identifiers: RESTRICTED_INCOMING_TRAFFIC (rule name restricted-common-ports), EC2_MANAGEDINSTANCE_APPLICATIONS_BLACKLISTED
Map — what it proves
- recipe2
- recipe— an authored recipe collects evidence for this control
- KSI only— a Key Security Indicator reaches it, but no recipe is authored yet
- orphan— no Key Security Indicator reaches it — a person writes it up instead
What else these families can fetch:CM 14/34 →
GovCloud
AWS Config, both managed rules, and Systems Manager Inventory are available in AWS GovCloud (US); security-group and node ARNs use partition arn:aws-us-gov
Notes & assertions
These prove the negatives you asserted and hand the reviewer the real installed-application set — they do not prove least functionality. That the functions, ports, protocols and services still enabled are the minimum necessary is a judgement against your documented essential-capability list, and CM-07.01's periodic review is a decision someone makes and records, not an API result; keep the review record next to this output. Both rules are only as strong as their parameters. RESTRICTED_INCOMING_TRAFFIC defaults to blocking TCP 20, 21, 3389, 3306 and 4333 — set blockedPorts to your real denylist or you are testing AWS's defaults, not your policy. EC2_MANAGEDINSTANCE_APPLICATIONS_BLACKLISTED needs exact application names (no wildcards, and the name differs per distro) and evaluates AWS::SSM::ManagedInstanceInventory, so a node with no running agent or inventory association is simply not evaluated rather than flagged — pair it with the inventory recipe's coverage check. Security-group ingress deliberately overlaps the SC-07 boundary recipe: there it proves boundary protection, here it proves unnecessary ports are closed.
References
- AWS Config managed rule: restricted-common-ports (RESTRICTED_INCOMING_TRAFFIC) https://docs.aws.amazon.com/config/latest/developerguide/restricted-common-ports.html
- AWS Config managed rule: ec2-managedinstance-applications-blacklisted https://docs.aws.amazon.com/config/latest/developerguide/ec2-managedinstance-applications-blacklisted.html
- AWS CLI: ssm list-inventory-entries https://docs.aws.amazon.com/cli/latest/reference/ssm/list-inventory-entries.html
This AWS mapping is authored opinion (overlay v3.0.0), versioned separately from the dataset and written against ruleset 2026.07.14.01. The upstream FedRAMP dataset names none of these tools.
The Change Management run (7)
- automatable
- partial — needs judgement
- narrative — no API proves this
Every authored recipe filed under CMT, in the order the plan works them. The mark says how much of the evidence the command produces on its own.
- partialPatch Manager compliance state plus Amazon Inspector scan status and coverage — proving flaws are being found continuously (Inspector enabled and actually covering your resources) and that the fixes landed (per-node missing/failed patch counts and the time of the last scan or install)dailypatch-and-vulnerability-remediationAWS Config · AWS Systems Manager Patch Manager · Amazon Inspector
- partialWho changed what, when, and from which state to which — CloudTrail's record of every mutating API call and Config's per-resource configuration history, plus, where Change Manager is in use, the change-request executions that carry the approvalweeklycloudtrail-config-change-historyAWS CloudTrail · AWS Config · AWS Systems Manager Change Manager
- partialConfig compliance results proving the ports you declared unnecessary are not reachable from the internet and the software you declared prohibited is not installed, plus the actual installed-application set a periodic review has to readyou are heremonthlyconfig-least-functionalityAWS Config · AWS Systems Manager Inventory · Amazon EC2
- partialEvery running instance built from an image you never approved and every node carrying denylisted software, together with proof that an automated action was configured for those findings and a record of what it did when one firedcontinuousunauthorized-component-detection-and-responseAWS Config · AWS Systems Manager Automation · AWS Systems Manager Inventory · Amazon EC2
- partialThe enforced half of who may change what: the service control policy type actually enabled in the organization root, the customer-authored SCPs and the roots, OUs and accounts each one is attached to, and the permissions boundary carried by every principal your own tagging marks as a change authoritycontinuouschange-authority-restrictions-and-enforcementAWS Organizations · AWS IAM
- partialFor every change that reached the assessed branch, the automated verification that ran against it — which workflows ran, on which commit, and what each concluded — together with the two things that decide whether those runs were a condition of the change or merely adjacent to it: the rule that made the checks required, and the platform's own per-push record of whether that rule held, failed, or was bypassed. The runs alone are activity; the rule and the per-push record are what make them a gate.weeklychange-verification-status-checks-and-run-recordsGitHub Actions · GitHub repository rulesets
- partialThe rule requiring the designated owners of the changed code to approve before it merges, the file that names who those owners are, the platform's own report of whether that file actually parses — and, per change, who approved, on which commit, and when.continuoussecurity-representative-change-approvalGitHub code owners · GitHub repository rulesets · GitHub pull requests