AWS Systems Manager
What this tool proves, in the authored overlay. Every recipe below names AWS Systems Manager; the controls are what their output is evidence for. The mapping is this project’s opinion (overlay v3.0.0) — the upstream FedRAMP rules name no vendor and no product.
Capabilities
Named separately by the recipes that call them, and counted here too. A recipe naming both this tool and one of its capabilities is one recipe, not two.
Recipes calling AWS Systems Manager (10)
- partialssm-configuration-baseline-enforcedcontinuous
AWS Config compliance results plus the State Manager association list proving a defined configuration is actually applied and re-applied to every managed node — instances are under SSM management, and the associations that carry your baseline report COMPLIANT on a schedule rather than drifting
- partialclock-synchronization-and-timestampsdaily
What each instance's clock is actually locked to and how far off it is right now — the chrony daemon's reference source, offset and leap status collected fleet-wide through Run Command — together with the configured time source in chrony.conf and the UTC time stamps CloudTrail already writes on every audit record
- partialsecurityhub-incident-review-proceduresmonthly
Security Hub finding workflow status plus GuardDuty detection coverage, showing incident response procedures are exercised: enabled insights, automated response actions routed through EventBridge, automated notifications, and Systems Manager Automation documents that encode response steps
- partialconfig-asset-inventorydaily
The machine-maintained component inventory — Config's recorder status and discovered-resource counts proving supported resources are tracked continuously and the list stays current without anyone editing a spreadsheet, plus Systems Manager Inventory's node and installed-application metadata for what runs inside them
- partialconfig-least-functionalitymonthly
Config compliance results proving the ports you declared unnecessary are not reachable from the internet and the software you declared prohibited is not installed, plus the actual installed-application set a periodic review has to read
- partialunauthorized-component-detection-and-responsecontinuous
Every running instance built from an image you never approved and every node carrying denylisted software, together with proof that an automated action was configured for those findings and a record of what it did when one fired
- partialtemporary-account-automatic-revocationcontinuous
The mechanism that ends a temporary or emergency account without anyone deciding to: the AWS Config rule that measures how long an IAM credential has gone unused, the period it is configured with, the remediation configuration proving the revocation fires automatically, and an empty non-compliant set showing nothing has outlived the period
- partialcloudtrail-config-change-historyweekly
Who changed what, when, and from which state to which — CloudTrail's record of every mutating API call and Config's per-resource configuration history, plus, where Change Manager is in use, the change-request executions that carry the approval
- partialpatch-and-vulnerability-remediationdaily
Patch Manager compliance state plus Amazon Inspector scan status and coverage — proving flaws are being found continuously (Inspector enabled and actually covering your resources) and that the fixes landed (per-node missing/failed patch counts and the time of the last scan or install)
- partialremote-access-authorization-and-monitoringweekly
How operators actually reach the environment from outside it: the managed access paths that exist, the logging and encryption configured on them, the session-by-session record of who used them, and the negative check that no instance is directly reachable instead
Controls it carries evidence for (27)
The reverse of the join above. A mark here is the control’s own grade across the whole corpus, not its grade from this tool alone — a control this tool partly proves may be fully proved with another.
- recipeAC-17
- recipeAC-17 (01)
- recipeAC-17 (02)
- recipeAC-17 (03)
- recipeAC-02 (02)
- recipeAU-08
- recipeCM-02
- recipeCM-02 (02)
- recipeCM-03
- recipeCM-06
- recipeCM-07
- recipeCM-07 (01)
- recipeCM-08
- recipeCM-08 (01)
- recipeCM-08 (03)
- recipeIR-04
- recipeIR-04 (01)
- recipeIR-06
- recipeIR-06 (01)
- recipeIR-06 (03)
- recipeIR-07
- recipeIR-07 (01)
- recipeIR-08
- recipeIR-08 (01)
- recipeRA-05
- recipeSI-02
- recipeSI-04 (05)
Tool names are canonical, from data/overlays/aws-services.json and data/overlays/pipeline-tools.json. The two overlays that name services spelled five of them two ways; a page keyed on the raw string would have split those in half.