Glossary

    AWS Config Rules

    Monitoring & Detection

    AWS Config Rules continuously evaluate your AWS resource configurations. When a resource violates a rule, Config flags it as non-compliant and can trigger automatic remediation.

    Rule Types

    • AWS Managed Rules:350+ pre-built rules (e.g., s3-bucket-public-read-prohibited, iam-root-access-key-check, encrypted-volumes)
    • Custom Rules: Lambda-backed rules for organization-specific policies
    • CloudFormation Guard Rules: declarative policy-as-code rules

    Evaluation Triggers

    • Configuration Change: evaluate when a resource is created, modified, or deleted
    • Periodic: evaluate on a schedule (1h, 3h, 6h, 12h, 24h)

    Remediation

    • Auto Remediation: SSM Automation documents execute corrective actions
    • Manual Remediation: one-click fix from the Config console
    • Conformance Packs: collections of Config rules mapped to compliance frameworks (PCI DSS, HIPAA, NIST)

    Related AWS Services

    Related Content

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.