AWS Config
What this tool proves, in the authored overlay. Every recipe below names AWS Config; the controls are what their output is evidence for. The mapping is this project’s opinion (overlay v3.0.0) — the upstream FedRAMP rules name no vendor and no product.
Recipes calling AWS Config (29)
- partialconfig-mfa-enabled-console-accesscontinuous
AWS Config compliance result for the managed rule proving every IAM user with a console password has MFA enabled
- partialconfig-access-keys-rotatedcontinuous
AWS Config compliance result proving long-lived IAM access keys (including those used by service/non-user identities) are rotated within the maximum age
- partialconfig-iam-policy-no-admin-accesscontinuous
AWS Config compliance result proving no customer-managed IAM policy grants full administrative access (Allow Action:* on Resource:*)
- partialconfig-encryption-at-restcontinuous
AWS Config compliance results across the storage services proving customer data is encrypted at rest — S3 buckets with default server-side encryption, EBS volumes encrypted, and RDS storage encrypted, all backed by KMS
- partialconfig-encryption-in-transitcontinuous
AWS Config compliance results proving data in transit is protected by TLS — S3 bucket policies denying non-TLS requests, load-balancer listeners restricted to SSL/HTTPS, and Redshift clusters requiring SSL
- partialconfig-kms-key-managementcontinuous
AWS Config compliance results proving KMS customer-managed keys are lifecycle-managed — automatic annual rotation enabled and no active key scheduled for deletion — the key-hygiene half of the cryptographic-protection control
- partialconfig-network-boundary-protectioncontinuous
AWS Config compliance results proving the network boundary is controlled — no security group exposes SSH to the internet, groups open to 0.0.0.0/0 only allow authorized ports, and every VPC's default security group denies all traffic
- partialconfig-cloudtrail-audit-loggingcontinuous
AWS Config compliance results proving the audit trail exists and is protected — CloudTrail enabled and multi-region so management events are captured account-wide, log-file validation on so records are tamper-evident, and SSE-KMS encryption on so the logs themselves are protected at rest
- partialconfig-threat-monitoring-enabledcontinuous
AWS Config compliance results proving continuous security monitoring is switched on account-wide — GuardDuty threat detection enabled (optionally centralized to a delegated admin) and Security Hub aggregating control findings
- partialconfig-data-backup-enabledcontinuous
AWS Config compliance results proving system data is backed up on a defined schedule — RDS automated backups enabled with a minimum retention, and AWS Backup plans meeting a minimum frequency and retention
- partialssm-configuration-baseline-enforcedcontinuous
AWS Config compliance results plus the State Manager association list proving a defined configuration is actually applied and re-applied to every managed node — instances are under SSM management, and the associations that carry your baseline report COMPLIANT on a schedule rather than drifting
- partialpatch-and-vulnerability-remediationdaily
Patch Manager compliance state plus Amazon Inspector scan status and coverage — proving flaws are being found continuously (Inspector enabled and actually covering your resources) and that the fixes landed (per-node missing/failed patch counts and the time of the last scan or install)
- partialcloudwatch-log-review-alertingweekly
The metric filters that turn audit log events into metrics, the alarms built on them, and Config's confirmation that those alarms actually notify someone — the automated-mechanism half of audit review
- partialconfig-asset-inventorydaily
The machine-maintained component inventory — Config's recorder status and discovered-resource counts proving supported resources are tracked continuously and the list stays current without anyone editing a spreadsheet, plus Systems Manager Inventory's node and installed-application metadata for what runs inside them
- partialcloudtrail-config-change-historyweekly
Who changed what, when, and from which state to which — CloudTrail's record of every mutating API call and Config's per-resource configuration history, plus, where Change Manager is in use, the change-request executions that carry the approval
- partialconfig-least-functionalitymonthly
Config compliance results proving the ports you declared unnecessary are not reachable from the internet and the software you declared prohibited is not installed, plus the actual installed-application set a periodic review has to read
- partialbackup-restore-testingmonthly
Restore jobs that actually ran — the schedule they ran on, whether each one completed, how long it took, and what it produced — plus the point-in-time recovery window that makes transaction-level recovery possible
- partialaudit-log-retention-and-delivery-failuredaily
How long audit records are kept, how much space they occupy, and whether the pipeline that delivers them is currently failing — retention settings on every log group and log bucket, the storage they consume, and the trail's own delivery-error fields
- partialboundary-access-points-and-default-denyweekly
Every route in or out of the boundary, named and counted — internet gateways, NAT gateways, VPC endpoints and Site-to-Site VPN tunnels — alongside what each boundary device does with traffic that matched no rule: the network ACL entries, the closed default security group, subnets that hand out public IPs, and the firewall policy's stateless and stateful default actions
- partialddos-protection-and-rate-limitingdaily
The denial-of-service defences that are actually attached to the internet-facing resources — the Shield Advanced subscription and the list of resources it protects, the web ACL's rate-based rules and their limits, whether web ACL logging is on — plus what those defences observed: the attacks Shield recorded over the period and the CloudWatch detection and block counts underneath them
- partialintegrity-verification-and-immutabilityweekly
Cryptographic proof that the audit trail CloudTrail delivered has not been altered or deleted, plus the compliance state of the write-once controls that make stored records and container images tamper-evident
- partialunauthorized-component-detection-and-responsecontinuous
Every running instance built from an image you never approved and every node carrying denylisted software, together with proof that an automated action was configured for those findings and a record of what it did when one fired
- partialinformation-location-and-classificationmonthly
A Region-by-Region inventory of the resources that can hold information, the classification tags you asserted on them, and — where Macie exists — a sampled machine judgement about which S3 buckets actually contain sensitive data
- partialremote-access-authorization-and-monitoringweekly
How operators actually reach the environment from outside it: the managed access paths that exist, the logging and encryption configured on them, the session-by-session record of who used them, and the negative check that no instance is directly reachable instead
- partialmalicious-code-protectionweekly
Whether malware scanning is switched on for compute and for the buckets that accept uploads, plus the scan-by-scan record of what was actually examined and what came back INFECTED
- partialidentity-sources-and-root-credential-lockdownmonthly
Every way a workforce user can authenticate into the account, counted and named in one pass — how many IAM users and federated trusts exist, which SAML and OIDC providers are registered, whether an IAM Identity Center instance is the workforce entry path — together with the state of the two credentials that belong to no person: the root user's access key and the account's X.509 signing certificate
- partialtemporary-account-automatic-revocationcontinuous
The mechanism that ends a temporary or emergency account without anyone deciding to: the AWS Config rule that measures how long an IAM credential has gone unused, the period it is configured with, the remediation configuration proving the revocation fires automatically, and an empty non-compliant set showing nothing has outlived the period
- partialexternal-access-inventory-and-trust-boundaryquarterly
The machine-generated inventory of every resource an external entity can reach — IAM Access Analyzer's active ExternalAccess findings — read against the declared zone of trust, so the terms-and-conditions review has a list to work from rather than a memory
- partialsession-authenticity-tls-terminationquarterly
Every place a client session terminates, with the protocol and negotiated policy it terminates under: listener protocol and SslPolicy on each load balancer, HTTP listeners that redirect rather than serve, an ACM certificate behind each one, and CloudFront viewer policies that refuse plain HTTP
Controls it carries evidence for (46)
The reverse of the join above. A mark here is the control’s own grade across the whole corpus, not its grade from this tool alone — a control this tool partly proves may be fully proved with another.
- recipeAC-17
- recipeAC-17 (01)
- recipeAC-17 (02)
- recipeAC-17 (03)
- recipeAC-02 (02)
- recipeAC-20
- recipeAC-06
- recipeAU-11
- recipeAU-12
- recipeAU-02
- recipeAU-04
- recipeAU-05
- recipeAU-06
- recipeAU-06 (01)
- recipeAU-09
- recipeCM-12
- recipeCM-12 (01)
- recipeCM-02
- recipeCM-02 (02)
- recipeCM-03
- recipeCM-06
- recipeCM-07
- recipeCM-07 (01)
- recipeCM-08
- recipeCM-08 (01)
- recipeCM-08 (03)
- recipeCP-10
- recipeCP-10 (02)
- recipeCP-09
- recipeIA-02
- recipeIA-05
- recipeRA-05
- recipeSC-13
- recipeSC-23
- recipeSC-28
- recipeSC-05
- recipeSC-07
- recipeSC-07 (03)
- recipeSC-07 (04)
- recipeSC-07 (05)
- recipeSC-08
- recipeSI-02
- recipeSI-03
- recipeSI-04
- recipeSI-07
- recipeSI-07 (01)
Tool names are canonical, from data/overlays/aws-services.json and data/overlays/pipeline-tools.json. The two overlays that name services spelled five of them two ways; a page keyed on the raw string would have split those in half.