1.3 AWS Security Hub & Automated Conformance Assessment

Key Takeaways

  • AWS Security Hub CSPM (the original Security Hub, renamed in 2025) provides posture management and finding aggregation, normalizing findings from AWS and third-party tools into the AWS Security Finding Format (ASFF).

  • Security Hub CSPM continuously evaluates resources against standards including AWS Foundational Security Best Practices (FSBP), CIS AWS Foundations Benchmark, PCI DSS, and NIST SP 800-53.

  • Security scores represent the percentage of passed controls relative to total enabled controls, weighted by control requirements.

  • Cross-Region finding aggregation designates an aggregation Region that centralizes findings, compliance statuses, and workflow updates from all linked spoke Regions into a single pane of glass.

  • Automated remediation leverages EventBridge rules matching ASFF finding schemas to trigger AWS Systems Manager Automation runbooks or Lambda functions.

Last updated: September 2026

1.3 AWS Security Hub & Automated Conformance Assessment

Enterprise cloud environments generate security telemetry across dozens of specialized tools, including Amazon GuardDuty, Amazon Inspector, Amazon Macie, AWS IAM Access Analyzer, and third-party vulnerability scanners. Without a centralized aggregation layer, security teams face fragmented dashboards, inconsistent alert formats, and manual compliance audits. AWS Security Hub resolves this operational challenge as a comprehensive Cloud Security Posture Management (CSPM) service that normalizes, correlates, and prioritizes findings while continuously assessing adherence to industry compliance standards.


Note

2025 naming change. AWS renamed the original service AWS Security Hub CSPM and launched a new, unified AWS Security Hub that correlates signals from GuardDuty, Inspector, Macie, and Security Hub CSPM into exposures and threats. Security Hub CSPM still runs the standards, controls, and security scores described here, and it still uses ASFF. The SCS-C03 outline removed ASFF as a named topic, so expect questions about what the service does (aggregation, standards, automation) rather than ASFF field trivia. This section uses "Security Hub" for the CSPM capabilities.

Centralized Posture Management & The ASFF Schema

Security Hub acts as a single pane of glass for security posture. It ingests findings from native AWS services, third-party security products, and custom internal scanners. The foundational mechanism enabling this integration is the AWS Security Finding Format (ASFF).

Loading diagram...

The AWS Security Finding Format (ASFF)

Before ASFF, each security tool emitted telemetry with unique JSON keys (e.g., one tool used severity_level, another used priority, a third used an integer scale). ASFF enforces a strict, consistent JSON syntax across all finding providers:

{
  "SchemaVersion": "2018-10-08",
  "Id": "arn:aws:securityhub:us-east-1:123456789012:subscription/aws-foundational-security-best-practices/v/1.0.0/S3.1/finding/a1b2c3d4",
  "ProductArn": "arn:aws:securityhub:us-east-1::product/aws/securityhub",
  "GeneratorId": "aws-foundational-security-best-practices/v/1.0.0/S3.1",
  "AwsAccountId": "123456789012",
  "Types": [
    "Software and Configuration Checks/Industry and Regulatory Standards/AWS-Foundational-Security-Best-Practices"
  ],
  "CreatedAt": "2026-09-29T04:15:30Z",
  "UpdatedAt": "2026-09-29T04:15:30Z",
  "Severity": {
    "Label": "CRITICAL",
    "Normalized": 90
  },
  "Title": "S3.1 S3 Block Public Access setting should be enabled",
  "Description": "This AWS control checks whether S3 buckets have bucket-level Block Public Access settings enabled.",
  "Resources": [
    {
      "Type": "AwsS3Bucket",
      "Id": "arn:aws:s3:::customer-confidential-financial-records",
      "Partition": "aws",
      "Region": "us-east-1"
    }
  ],
  "Compliance": {
    "Status": "FAILED",
    "SecurityControlId": "S3.1"
  },
  "Workflow": {
    "Status": "NEW"
  },
  "RecordState": "ACTIVE"
}

Core ASFF Attributes Worth Recognizing

  • ProductArn: The ARN of the product that created the finding (e.g., arn:aws:securityhub:... for native controls, or a partner ARN).
  • GeneratorId: The specific security rule, control, or detector that generated the finding.
  • Severity.Label: Standardized string classification: INFORMATIONAL, LOW, MEDIUM, HIGH, or CRITICAL.
  • Severity.Normalized: An integer between 0 and 100 that normalizes disparate third-party scoring systems into a universal baseline.
  • Compliance.Status: The compliance state of the evaluated resource: PASSED, WARNING, FAILED, or NOT_AVAILABLE.
  • Workflow.Status: Tracking the lifecycle of a finding: NEW, NOTIFIED, RESOLVED, or SUPPRESSED.
  • RecordState: Indicates whether the finding is ACTIVE (still present) or ARCHIVED (resolved or outdated).

Supported Compliance Standards & Security Score Mechanics

Security Hub continuously assesses resource configurations against enabled regulatory and industry benchmarks.

Major Compliance Frameworks

  1. AWS Foundational Security Best Practices (FSBP): AWS-curated security controls representing AWS security architects' baseline recommendations. Covers IAM, data protection, network hardening, logging, and encryption across all primary AWS services. Updated continuously by AWS.
  2. CIS AWS Foundations Benchmark: Industry-standard configuration guidelines developed by the Center for Internet Security (CIS). Covers identity, logging, monitoring, and networking across multiple versions (v1.2.0, v1.4.0, v3.0.0, and v5.0.0).
  3. Payment Card Industry Data Security Standard (PCI DSS): Specific controls for workloads handling, storing, or transmitting cardholder data (versions v3.2.1 and v4.0).
  4. NIST SP 800-53 Rev. 5: Comprehensive federal information security controls catalog required for United States government agencies and regulated contractors.

Underlying Evaluation Engine: AWS Config Dependency

Security Hub controls do not perform direct API polling against your infrastructure. Instead, Security Hub relies on AWS Config managed rules as its underlying configuration evaluation engine.

Exam Trap Alert: For Security Hub compliance standards to generate findings and calculate security scores, AWS Config resource recording must be enabled in the target account and Region. If AWS Config recording is disabled or configured to record only a subset of resource types, Security Hub controls will display a compliance status of NOT_AVAILABLE and the security score will be incomplete.

Security Score Calculation

Security Hub calculates a quantitative Security Score (expressed as a percentage from 0% to 100%) for each enabled standard and a consolidated security score across all standards:

Security Score = (Number of Passed Controls / Total Number of Enabled Controls) * 100

Crucial operational nuances govern this calculation:

  • Consolidated Controls View: Many controls are shared across standards (e.g., enforcing S3 bucket encryption is required by FSBP, CIS, and PCI DSS). Under the Consolidated Controls View, Security Hub evaluates the control once; passing or failing it updates all associated standards simultaneously.
  • Disabled Controls vs Suppressed Findings: If an organization intentionally disables a control (e.g., RDS multi-AZ is not required in development sandboxes), the control is removed from the denominator and does not penalize the security score. If a failed control finding is set to Workflow.Status = SUPPRESSED, the control is treated as non-breaching and does not degrade the score, while preserving an audit record of the business exception.

Cross-Region Finding Aggregation Architecture

In an enterprise environment operating across global AWS Regions, managing findings locally in each individual Region is operationally unsustainable. Security Hub provides Cross-Region Finding Aggregation to establish a single pane of glass.

Hub-and-Spoke Aggregation Mechanics

  1. Designate an Aggregation Region: The security engineering team selects one primary Region (the Hub or Aggregation Region, e.g., us-east-1) in the delegated administrator account.
  2. Link Spoke Regions: The administrator links all active Regions (the Spokes) to the aggregation Region. Linking can include all current Regions and automatically opt into any newly enabled future Regions.
  3. Continuous Asynchronous Replication: Findings, compliance statuses, and security scores generated in spoke Regions are automatically replicated asynchronously to the aggregation Region.
  4. Bi-Directional Status Synchronization: If a security analyst in the aggregation Region updates a finding's workflow status (e.g., changing Workflow.Status from NEW to RESOLVED or adding an audit note), the change is automatically synchronized back to the originating spoke Region.
  5. Centralized EventBridge Automation: Because all findings from all linked Regions flow into the aggregation Region, security teams configure their primary Amazon EventBridge routing rules and automated remediation pipelines solely in the aggregation Region, eliminating the need to duplicate Lambda remediation functions and EventBridge rules in every spoke Region.

Automated Remediation with AWS Config & Systems Manager

Security Hub provides two remediation paradigms: automated real-time remediation and user-driven custom actions.

Automated Real-Time Remediation Flow

  1. A resource configuration change breaches a security control (e.g., an S3 bucket is created with public read access).
  2. AWS Config detects the configuration drift and emits a compliance state change to Security Hub.
  3. Security Hub generates an ASFF finding with Compliance.Status = FAILED and Severity.Label = HIGH or CRITICAL.
  4. Security Hub emits the finding to the Amazon EventBridge default event bus as a Security Hub Findings - Imported event.
  5. An EventBridge rule matches the failed control ID and triggers an AWS Systems Manager (SSM) Automation Document (e.g., AWSConfigRemediation-ConfigureS3BucketPublicAccessBlock or a custom runbook).
  6. The SSM Automation runbook assumes an IAM remediation role, applies S3 Block Public Access, and updates the finding's Workflow.Status to RESOLVED.

Custom Actions for Human-in-the-Loop Triage

Not all remediation actions can be fully automated without risking application availability (e.g., isolating a production database instance). For high-impact resources, Security Hub supports Custom Actions:

  • An administrator creates a custom action in Security Hub (e.g., IsolateCompromisedEC2Instance), generating a unique Custom Action ARN.
  • An analyst reviewing findings in the Security Hub console selects one or more findings and clicks the custom action from the Actions dropdown.
  • Security Hub publishes a Security Hub Findings - Custom Action event to EventBridge containing the selected finding payloads.
  • EventBridge routes the event to an automated Step Functions state machine or Lambda function to execute the controlled quarantine workflow.

Scheduled Assessments: Conformance Packs, Security Hub CSPM & State Manager

Skill 1.1.5 asks you to automate regular assessments and investigations rather than one-off checks. Three services cover different layers:

MechanismWhat it assessesHow it runs on a scheduleTypical exam use
AWS Config conformance packResource configuration against a packaged set of Config rules (for example, an operational best-practices template)Change-triggered and periodic Config rules; organization conformance packs deploy to every member account"Continuously evaluate all accounts against a framework and remediate automatically"
Security Hub CSPM standardsControls such as FSBP or CIS, scored per account and RegionChange-triggered or periodic controls that Security Hub CSPM runs through service-linked Config rules"Give me a security score and prioritized failed controls across the organization"
Systems Manager State ManagerThe state inside managed nodes (agents installed, configuration files, inventory collected)Associations that apply a document on a cron or rate schedule and report compliance"Every 12 hours, confirm the EDR agent is installed and running, and reinstall it if missing"

State Manager is the piece candidates forget. An association binds an SSM document (for example, AWS-GatherSoftwareInventory, AWS-RunShellScript, or an Automation runbook) to targets selected by tag, and re-applies it on a schedule. Its compliance results appear in Systems Manager Compliance, so an EventBridge rule or a Security Hub CSPM integration can alert when a node drifts. Use it for host-level assessments that Config rules cannot see, such as a disabled auditd service or a missing CloudWatch agent configuration.

Specialty Exam Pitfalls & Governance Strategies

  1. Security Hub Does Not Auto-Enable AWS Config: A frequent misunderstanding is believing that enabling Security Hub automatically activates AWS Config. Security Hub checks Config, but if Config recording has not been initialized, Security Hub cannot evaluate compliance. You must enable Config in every account and Region.
  2. Custom Actions Require Explicit Invocation: Custom actions are never triggered automatically by incoming findings. They only fire when an operator selects findings in the console and chooses the custom action. For automated remediation without human intervention, use EventBridge rules matching Security Hub Findings - Imported.
  3. Finding Ingestion vs Security Score Impact: Third-party findings and GuardDuty threat findings ingested into Security Hub appear in the findings dashboard, but they do not affect the compliance security score. The security score is derived exclusively from enabled compliance standard controls (FSBP, CIS, PCI DSS, NIST).
  4. AWS Organizations Delegated Admin Boundary: You cannot designate an account as the Security Hub Delegated Administrator unless it is first registered as a member account within AWS Organizations. The Organizations management account should only configure delegation; day-to-day operations must reside in the designated security tooling account.
Loading diagram...
AWS Security Hub Multi-Region Posture Aggregation & Automated Remediation
Test Your Knowledge

A security engineer configures AWS Security Hub with Cross-Region Finding Aggregation. The primary aggregation Region is us-east-1, and us-west-2 is configured as a linked spoke Region. A security analyst in us-east-1 reviews an active finding originating from an EC2 instance in us-west-2 and updates its workflow status to RESOLVED with an explanatory audit note. What happens across the multi-Region architecture?

A

The finding is resolved in us-east-1, but the analyst must manually log into us-west-2 to update the original finding because replication is strictly one-way.

B

Security Hub automatically synchronizes the RESOLVED status and audit note bi-directionally back to us-west-2 without manual intervention.

C

The finding is permanently deleted from both us-east-1 and us-west-2 after 24 hours.

D

The update fails because findings can only be edited in the Region where the target resource resides.

Test Your Knowledge

An organization enables AWS Security Hub in a newly created AWS account and activates the AWS Foundational Security Best Practices standard. After 48 hours, all security controls in the console display a compliance status of 'NOT_AVAILABLE' and the security score is displayed as 0%. What is the root cause of this issue?

A

The account has not yet accumulated at least 100 CloudTrail management events to establish an AI behavioral baseline.

B

The AWS Organizations Service Control Policy (SCP) is blocking Security Hub from assuming the AWSServiceRoleForSecurityHub service-linked role.

C

The security controls require a manual run initiated by clicking 'Evaluate Now' on each individual control.

D

AWS Config resource recording is disabled in the account and Region, preventing Security Hub from executing its underlying configuration checks.

Test Your Knowledge

An enterprise audit team requires that the company's AWS Security Hub security score accurately reflect production compliance without being penalized by non-production development environments where multi-AZ database deployments and automated snapshots are intentionally disabled. How should the security engineer configure Security Hub to meet this audit requirement?

A

Disable the specific non-applicable security controls in the development accounts so they are removed from the security score calculation entirely.

B

Create an EventBridge rule that intercepts failed findings and deletes them from Security Hub before the score recalculates.

C

Set the severity of all failed findings in development accounts to INFORMATIONAL.

D

Configure an IAM permission boundary preventing Security Hub from scanning resources tagged with Environment=Development.

Test Your Knowledge

A security operations team wants an automated remediation pipeline where any S3 bucket whose default encryption is not SSE-KMS is automatically reconfigured to use an approved AWS KMS customer managed key. Which architecture accomplishes this with the lowest operational latency and adherence to AWS best practices?

A

Schedule a cron job in AWS Systems Manager State Manager that queries S3 buckets every 2 hours and applies encryption.

B

Configure an Amazon Macie classification job to discover unencrypted buckets and execute a bash script on an EC2 bastion host.

C

Create an Amazon EventBridge rule that matches Security Hub 'Findings - Imported' events where Compliance.Status is FAILED for control S3.17 (S3 general purpose buckets should be encrypted at rest with AWS KMS keys), and route the event to an AWS Systems Manager Automation document that applies the KMS default-encryption configuration.

D

Configure a Security Hub custom action that analysts must click every morning to invoke an AWS Lambda function across all unencrypted buckets.

Sections you finish are checked off in the contents.