Skip to content

How to debug Security Hub checks failing in the CIS Reference Architecture? #135

Answered by zackproser
zackproser asked this question in Help
Discussion options

You must be logged in to vote

The Gruntwork CIS Reference Architecture implements a configuration that is compliant with the CIS AWS Foundations Benchmark.

If you need to debug why a particular Security Hub check is failing for your CIS Reference Architecture, start by opening the official AWS whitepaper on the CIS Foundations Benchmark and looking for the section that maps to the failing check.

For example, let's say your Ensure a log metric filter and alarm exist for unauthorized API calls securityhub check is failing with CLOUDTRAIL_METRIC_FILTER_NOT_VALID.

Ensure a log metric filter and alarm exist for unauthorized API calls is the relevant section in the whitepaper to review. Within that section is an Audit subhe…

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by zackproser
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment