Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add recording setup of Config to every base account provision #528

Open
andrewpatto opened this issue Jan 12, 2025 · 0 comments
Open

Add recording setup of Config to every base account provision #528

andrewpatto opened this issue Jan 12, 2025 · 0 comments

Comments

@andrewpatto
Copy link
Member

We have a base Config setup (daily.. etc..) that we have click-ops applied in each account. We sometimes forget to do it in new accounts.

Config configured correctly is vital for the proper functioning of Security Hub. I suggest we make part of our terraform bootstrap of accounts include an AWS config setup.

Things to note:

  • not sure whether terraform will "update" over the top of recorders that we have already set up by click-ops. Need to check.

Items to set:

  • frequency to daily rather than continuous (too expensive at continuous)
  • send to common config bucket (needs special policy on the bucket to allow writes)
  • reduce days of retention (? we have no legislative need for keeping config records?)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant