15.2 AWS Config, Conformance Packs & Automated Remediation
Key Takeaways
AWS Config continuously records resource configurations, relationships, and state modifications into Configuration Items (CIs), publishing history and snapshots to Amazon S3 and notifications to Amazon SNS.
Config Rules evaluate resource compliance using either configuration change triggers (event-driven evaluation upon CI creation/modification) or periodic triggers (scheduled intervals from 1 to 24 hours).
Multi-Account Multi-Region Configuration Aggregators centralize compliance data across an entire AWS Organization into a dedicated security account, eliminating the need to log into individual member accounts.
Conformance Packs package collections of Config rules and remediation documents into single, version-controlled YAML templates; organization conformance packs deployed centrally are immutable in member accounts.
Automated remediation links non-compliant Config rule evaluations directly to AWS Systems Manager Automation documents, executing corrective actions automatically or manually with configurable retry logic and dynamic resource ID parameter mapping.
15.2 AWS Config, Conformance Packs & Automated Remediation
Maintaining continuous security compliance across distributed multi-account cloud environments requires continuous monitoring, auditing, and recording of resource configurations. Traditional periodic audits rely on point-in-time manual assessments that fail to detect transient misconfigurations, ephemeral resource exposures, or unauthorized infrastructure alterations. AWS Config addresses this challenge by providing a continuous, fully managed configuration recording and compliance auditing service.
AWS Config tracks the detailed inventory of supported AWS resources, logs configuration history, models inter-resource relationships, and evaluates whether resource configurations conform to internal security baselines and regulatory frameworks. When combined with Conformance Packs and AWS Systems Manager Automated Remediation, AWS Config transitions security governance from passive alerting to active, autonomous self-healing.
AWS Config Core Architecture
The AWS Config operational workflow comprises three fundamental components: the Configuration Recorder, Configuration Items (CIs), and the Delivery Channel.
[Resource State Change] ──> [Configuration Recorder] ──> [Configuration Item (CI)]
│
┌────────────────────────────────────────────┴─────────────────────────────┐
▼ ▼
[Delivery Channel] [Config Rules Engine]
├── S3: Configuration History & Snapshots ├── Evaluate Compliance
└── SNS: Real-time Configuration Streams └── Trigger SSM Remediation
1. Configuration Recorder
The Configuration Recorder detects changes in resource states and creates corresponding configuration records. Security engineers configure the recorder to capture:
- All Supported Resources: Records every supported AWS resource in the target Region.
- Specific Resource Types: Selectively records high-risk services (e.g.,
AWS::IAM::*,AWS::S3::Bucket,AWS::EC2::SecurityGroup). - Global Resources: IAM users, groups, roles, and customer-managed policies are global resources. To avoid duplicate Configuration Items and billing charges across multiple Regions, global resources should be recorded in only one Region per account (typically
us-east-1). - Recording Frequency: Organizations can select Continuous Recording (real-time recording of changes as they occur, essential for incident detection) or Daily Recording (aggregates changes every 24 hours, suitable for cost-sensitive, low-churn environments).
2. Configuration Items (CIs)
A Configuration Item (CI) is a point-in-time JSON document representing the state of an AWS resource. Each CI contains:
- Metadata: CI capture time, CI version, AWS account ID, Region, and resource type.
- Attributes: Resource ID, resource ARN, resource tags, and creation time.
- Configuration: The full serialized configuration payload of the resource (e.g., S3 bucket encryption algorithms, security group inbound/outbound rules).
- Relationships: Graph linkages to associated resources (e.g., an EC2 instance CI references its attached EBS volumes, ENIs, and security groups).
3. Delivery Channel
The Delivery Channel exports CIs for long-term retention and real-time processing:
- Amazon S3 Bucket: Stores configuration history files (delivered periodically throughout the day) and periodic Configuration Snapshots (complete point-in-time inventories of all recorded resources).
- Amazon SNS Topic: Streams configuration change notifications and compliance evaluation status transitions in real time, enabling downstream integration with SIEMs, ticketing systems, or event routers.
AWS Config Rules: Managed vs. Custom
AWS Config Rules represent desired configuration states for specific resource types or entire accounts. Config evaluates resources against these rules to determine whether resources are COMPLIANT, NON_COMPLIANT, or NOT_APPLICABLE.
Evaluation Triggers
Config rules are executed based on one of two trigger mechanisms:
- Configuration Changes (Event-Driven): Evaluated immediately when AWS Config detects a change in the resource's configuration, tags, or deletion. Used for critical security controls requiring immediate detection (e.g., S3 public access, security group rule expansion).
- Periodic (Schedule-Driven): Evaluated at a fixed time frequency (1 hour, 3 hours, 6 hours, 12 hours, or 24 hours). Required for rules that evaluate time-dependent criteria (e.g., checking whether IAM user access keys have remained unrotated for more than 90 days).
Rule Types: Managed vs. Custom Lambda vs. Custom Guard
| Rule Classification | Architectural Mechanics | Maintenance Overhead | Operational Flexibility |
|---|---|---|---|
| AWS Managed Rules | Pre-built rules authored and maintained by AWS (e.g., s3-bucket-public-read-prohibited, encrypted-volumes, iam-root-access-key-check). | Zero maintenance: Automatically updated by AWS as service APIs evolve. | High for standard checks; limited to parameters exposed by AWS. |
| Custom Rules (Lambda) | Evaluates resources by invoking a user-managed AWS Lambda function that queries resource state and returns results via the PutEvaluations API. | High maintenance: Requires maintaining Lambda runtime, execution roles, VPC access, and error-handling code. | Unlimited flexibility: Can perform complex cross-service lookups, API queries, and external threat intelligence checks. |
| Custom Rules (Guard) | Evaluates resources using CloudFormation Guard DSL rules defined directly within the Config rule without provisioning Lambda functions. | Low maintenance: No Lambda function to patch, manage, or monitor; eliminates cold starts. | Fast, declarative policy-as-code evaluations for properties present within the Configuration Item. |
Lambda Custom Rule Lifecycle & PutEvaluations API
When a configuration change occurs on a resource monitored by a Lambda-based custom rule:
- AWS Config invokes the Lambda function asynchronously, passing an event payload containing
invokingEvent(containing the Configuration Item) andruleParameters. - The Lambda function inspects the CI's configuration properties.
- The function determines compliance and constructs an evaluation result containing
ComplianceResourceType,ComplianceResourceId,ComplianceType(COMPLIANTorNON_COMPLIANT), andOrderingTimestamp. - The Lambda function calls the AWS Config API
config:PutEvaluationsto record the finding in AWS Config. If the function fails to callPutEvaluations, the rule status transitions toEVALUATION_FAILURE.
Multi-Account Multi-Region Configuration Aggregators
In an enterprise environment spanning dozens or hundreds of AWS accounts and multiple active Regions, reviewing compliance on an account-by-account basis is unworkable. AWS Config provides Configuration Aggregators to centralize inventory tracking and compliance posture.
Aggregator Types
- Organization Aggregators: When configured from the AWS Organizations management account or an AWS Config Delegated Administrator account, the aggregator automatically discovers and aggregates configuration and compliance data from all member accounts in the organization across all active Regions. As new accounts join the organization, they are automatically enrolled into the aggregator without configuration changes.
- Individual Account Aggregators: Manually configured to aggregate specific account IDs. Requires target accounts to grant authorization via
PutConfigurationAggregatorAuthorization.
Organization-Wide Config Rules
Security teams can deploy rules enterprise-wide using Organization Config Rules (PutOrganizationConfigRule).
- Managed or custom rules are defined once in the management or delegated administrator account.
- AWS Config deploys the rule to all current and future member accounts in the Region where you create it (repeat per Region), except accounts you exclude.
- Immutability in Member Accounts: Member accounts cannot modify, disable, or delete Organization Config rules. Local administrators attempting to delete the rule receive an
AccessDeniedException.
AWS Config Conformance Packs
A Conformance Pack is a packaged collection of AWS Config rules and automated remediation actions authored as a single YAML template. Conformance packs simplify compliance management by providing version-controlled governance blueprints mapped to specific industry standards and regulatory frameworks.
Supported Regulatory Frameworks
AWS provides pre-architected, managed conformance pack templates for major regulatory standards:
- NIST SP 800-53 (Rev 4 and Rev 5): Comprehensive security and privacy controls for federal and enterprise systems.
- PCI DSS v4.0: Controls covering network segmentation, encryption of cardholder data, vulnerability management, and access control.
- HIPAA Security Rule: Standards for safeguarding electronic protected health information (ePHI).
- CIS AWS Foundations Benchmark: Industry-consensus best practices for identity, logging, monitoring, and networking.
- FedRAMP Moderate & High: Federal Risk and Authorization Management Program security baselines.
Organization Conformance Packs
Similar to organization rules, Organization Conformance Packs (PutOrganizationConformancePack) deploy entire suites of rules and remediation documents across an AWS Organization:
- Deployed centrally from the management account or a delegated administrator account.
- Automatically provisioned into new member accounts when they are added to the organization.
- Cannot be deleted, modified, or bypassed by IAM principals in member accounts, ensuring an immutable compliance baseline.
- Support parameterized templates, allowing organizations to override specific rule parameters (e.g., passing custom KMS key ARNs or retention day thresholds) across different OUs.
Automated Remediation with Systems Manager Automation
Detecting a non-compliant resource satisfies audit visibility, but security defense requires minimizing the window of vulnerability. AWS Config integrates natively with AWS Systems Manager (SSM) Automation Documents to execute automated remedial actions.
Remediation Architecture & Configuration
Security engineers attach a Remediation Configuration to an AWS Config rule using the PutRemediationConfigurations API. The configuration specifies:
- Target Document: The SSM Automation document to execute (AWS-managed or custom).
- Execution Mode: Automatic Execution (triggers immediately upon non-compliant evaluation) or Manual Execution (operator must review finding and click "Remediate" in the console or CLI).
- Parameters: Input parameters passed to the SSM document. Config supports Dynamic Parameters (binding the non-compliant resource's identifier using the
RESOURCE_IDtoken) and Static Parameters (fixed values such as notification ARNs or IAM roles). - Retry Controls: Governs remediation resilience via
MaximumAutomaticAttempts(1 to 25 attempts, default 5) andRetryAttemptSeconds(1 to 2,678,000 seconds, default 60 seconds).
Common AWS-Managed Remediation Documents
| SSM Automation Document | Remedial Action Performed | dynamic Parameter Binding |
|---|---|---|
AWSConfigRemediation-ConfigureS3BucketPublicAccessBlock | Enables S3 Block Public Access (all four settings) on the non-compliant bucket. | BucketName: RESOURCE_ID |
AWS-EnableCloudTrail | Creates a trail that delivers to a specified S3 bucket and starts logging. | TrailName, S3BucketName (static) |
AWSConfigRemediation-RemoveUnrestrictedSourceIngressRules | Removes ingress rules that allow 0.0.0.0/0 or ::/0. (AWS-DisablePublicAccessForSecurityGroup removes open SSH and RDP rules only.) | SecurityGroupId: RESOURCE_ID |
AWSConfigRemediation-EnableKeyRotation | Enables automatic rotation on a customer managed KMS key. | KeyId: RESOURCE_ID |
AWS-ConfigureS3BucketLogging | Configures server access logging delivery to a designated central logging bucket. | BucketName: RESOURCE_ID |
Remediation Execution Role Permissions
For automated remediation to succeed, the remediation configuration must specify an IAM service role (AutomationAssumeRole) that Systems Manager assumes to perform the action:
- The role must trust the Systems Manager service principal (
ssm.amazonaws.com). - The role's policy must grant the exact least-privilege actions executed by the SSM document (e.g.,
s3:PutBucketPublicAccessBlockfor S3 remediation, orec2:RevokeSecurityGroupIngressfor security group remediation). - If remediating across accounts in an Organization Conformance Pack, the execution role must be pre-provisioned in member accounts with identical names and trust relationships.
Specialty Exam Pitfalls & Architectural Traps
- Detective Nature of Config vs. Preventive Controls: Believing that AWS Config rules can block a developer from deploying an unencrypted resource. Config is strictly detective; the resource is created first, a CI is recorded, and Config marks it
NON_COMPLIANT. To block creation proactively, use Service Control Policies (SCPs), CloudFormation Hooks, orcfn-guardin CI/CD. - Global Resource Duplication Across Regions: Enabling global resource recording (IAM) in all active Regions. This creates duplicate Configuration Items for the exact same IAM changes, clutters S3 delivery buckets, and inflates AWS Config recording costs. Always record global resources in only one Region per account.
- SSM Remediation Role Missing in Spoke Accounts: Deploying an Organization Conformance Pack with automated remediation, but failing to deploy the corresponding SSM Automation execution IAM role into all member accounts. The Config rule will evaluate resources as
NON_COMPLIANT, but remediation will fail withActionExecutionFailedbecause Systems Manager cannot assume the specified role ARN. - Event-Driven vs. Scheduled Rule Mismatches: Configuring an event-driven trigger for a rule that requires periodic time calculations (e.g., checking for unrotated IAM credentials older than 90 days). Because an inactive IAM user's configuration never changes, no CI is emitted, and the rule will never trigger unless configured with a Periodic schedule.
A global financial enterprise wants to enforce a standardized set of 45 security compliance rules and automated remediation workflows across 150 AWS accounts in an AWS Organization. The compliance rules must conform to PCI DSS v4.0. Furthermore, security engineers must ensure that member account administrators cannot disable, alter, or delete these compliance rules. Which architecture achieves this with the lowest administrative overhead?
Write a Python script that assumes a cross-account role in every member account and invokes the PutConfigRule API for all 45 rules individually.
Author a CloudFormation template in every member account that creates the Config rules, and use IAM permission boundaries to prevent developers from deleting CloudFormation stacks.
Deploy an Organization Conformance Pack using the pre-architected PCI DSS v4.0 template from the AWS Organizations delegated administrator account.
Configure AWS Security Hub with the PCI DSS standard enabled in each account and configure Amazon EventBridge rules to alert on failed security checks.
A security engineer must configure automated remediation for an AWS Config managed rule named s3-bucket-public-read-prohibited. When a non-compliant bucket is detected, the solution must immediately enable S3 Block Public Access on that specific bucket without human intervention. How should the remediation configuration be structured?
Set the remediation target to the SSM Automation document AWSConfigRemediation-ConfigureS3BucketPublicAccessBlock, configure Automatic execution, and map the BucketName parameter to RESOURCE_ID.
Configure an Amazon EventBridge rule matching AWS Config Non-Compliant findings that triggers an SNS topic with email alerts to the S3 bucket owner.
Attach an S3 bucket policy with an explicit Deny statement matching all Principals where s3:PublicAccessBlock is disabled.
Set the remediation target to a Lambda function, configure Manual execution, and hardcode the primary S3 bucket ARN in the Lambda environment variables.
A company is authoring a custom AWS Config rule using an AWS Lambda function to verify that all Amazon DynamoDB tables have point-in-time recovery (PITR) enabled. The rule is configured with a Configuration Changes trigger. What sequence of operations must the Lambda function perform to successfully report compliance back to AWS Config?
The Lambda function queries CloudWatch Logs for DynamoDB API calls and publishes an Amazon SNS message to the security operations center.
The Lambda function receives the invoking event, calls DynamoDB DescribeContinuousBackups, and writes an evaluation JSON file to the AWS Config S3 delivery bucket.
The Lambda function executes on an EventBridge schedule, parses CloudTrail Lake, and modifies the DynamoDB table tags to mark PITR status.
The Lambda function parses the Configuration Item from the invoking event, evaluates PITR status, and calls the config:PutEvaluations API with COMPLIANT or NON_COMPLIANT.
A central security operations team oversees 80 AWS accounts across three geographical Regions. Currently, security analysts must log into individual member account consoles to check AWS Config compliance scores and resource inventories. The Chief Information Security Officer (CISO) requires a centralized single-pane-of-glass dashboard displaying real-time compliance status for the entire enterprise without managing individual cross-account IAM credentials. Which solution directly satisfies this requirement?
Deploy an Amazon CloudWatch cross-account cross-region dashboard in the security account and write custom metric math queries.
Create an AWS Config Configuration Aggregator in the delegated administrator account targeting the entire AWS Organization and all active Regions.
Configure Amazon S3 Cross-Region Replication to copy AWS Config delivery bucket contents from all member accounts into a central security data lake.
Create an Amazon Athena query that runs every hour against AWS CloudTrail logs across all accounts and outputs results to Amazon QuickSight.
Sections you finish are checked off in the contents.