Start with the denominator
A dashboard with no critical findings looks encouraging, but only describes the population actually assessed. On a fictional platform spanning accounts and Regions, start with inventory of relevant resources and operations. Compare that set with enabled services, supported types, exclusions, cadence, and latest assessment. Record gaps as gaps, with owners and next actions. Do not silently remove resources from the denominator to improve an indicator. Sign-off should separate observed exposure from uncertainty caused by missing assessment. An exception can be a legitimate business decision when authority, expiry, and conditions are defined; it does not turn an unobserved resource into a technically compliant one. Reporting should make that distinction reproducible.
Understand what AWS Config observed
An aggregator provides read access to data from several sources but does not install rules in those accounts. Confirm the recorder and actual resource-type scope before interpreting aggregate results. Cadence also limits conclusions: daily recording retains the latest state in the period when changed and may omit intermediate transitions. A NOT_APPLICABLE rule did not establish the requirement for that resource. In a pipeline, proactive evaluation provides a result for proposed properties but does not itself block deployment. The gate must interpret results under explicit policy, including errors or absent responses. These contracts distinguish recording configuration, evaluating a rule, and preventing change; each responsibility needs its own mechanism and evidence.
Separate aggregation and central configuration
In Security Hub CSPM, linking a Region for aggregation does not automatically enable the service at the source. Confirm enablement before inferring security from an empty dashboard. Central configuration uses policies created in the home Region and associated with accounts or organizational structures. Those policies apply to the home Region and linked Regions within the defined scope. Centrally managed accounts cannot freely override covered settings; route changes to the responsible authority. A policy listing enabled controls leaves the remainder out, including new controls. That behavior differs from listing disabled controls. When reviewing policy, explain to the service owner how new controls will be adopted and who will handle their results.
Interpret finding lifecycle
RESOLVED and SUPPRESSED describe handling of Security Hub CSPM findings. A manual change to RESOLVED does not fix the resource property. Suppression also does not prevent new findings about the same issue. Retain closure reason, technical evidence, and exception decision where applicable. In GuardDuty, auto-enablement preferences have a different contract: NEW covers new accounts; NONE does not disable already enabled members. Configuration is regional and the organization uses the same delegated administrator across Regions. Suspending and disabling are not equivalent either: suspension retains existing findings, whereas disabling deletes findings and configuration in that Region. Malware Protection for S3 has separate specifics and is excluded from this lesson’s suspension exercise.
Confirm vulnerability coverage
In ECR enhanced scanning, distinguish scan on push from continuous scanning. A result collected at push time does not guarantee reassessment after a CVE appears. Even in continuous mode, confirm applicable eligibility and duration. When an image loses coverage through expiry, closing findings does not demonstrate that packages were patched. Increasing duration also does not automatically reactivate already inactive images. For agent-based EC2 assessment, investigate Systems Manager integration, permissions, and inventory when an instance lacks coverage. Avoid transferring conclusions between image and host or between environments with different versions. A remediation report should identify the assessed artifact, coverage state, relevant result, and evidence that the fixed version is the one actually in use.
Exercise: classify the available result
The local model receives a fictional observation with confirmed scope, active coverage, result age, and finding count. It uses an internal window defined by the exercise, not an AWS SLA. Missing evidence leaves the conclusion pending; stale observation requests reassessment. Zero findings only describes the observed result, not universal absence of vulnerabilities. Run the cases and change the window to understand internal policy effects. Then write a short sign-off for the change committee, including resource, account, Region, assessment time, limitations, and next-step owner. The aim is a traceable decision useful to operations and management without hiding uncertainty behind a green indicator or treating a model result as vendor assurance.
# Original local review model, not an AWS scanner or proof of absence of vulnerabilities.
def classify(scope_confirmed, active, age_hours, findings, max_age_hours):
if scope_confirmed is not True or active is not True:
return "coverage gap"
if age_hours is None or findings is None:
return "evidence missing"
if age_hours < 0 or findings < 0 or max_age_hours <= 0:
raise ValueError("invalid observation or policy")
if age_hours > max_age_hours:
return "reassessment required"
if findings > 0:
return "findings require disposition"
return "no findings in the stated assessed scope"
# Fictional internal policy; not a vendor SLA.
assert classify(True, True, 2, 0, 24) == "no findings in the stated assessed scope"
assert classify(False, True, 2, 0, 24) == "coverage gap"
assert classify(True, False, 2, 0, 24) == "coverage gap"
assert classify(True, True, None, 0, 24) == "evidence missing"
assert classify(True, True, 25, 0, 24) == "reassessment required"
assert classify(True, True, 2, 4, 24) == "findings require disposition"
try:
classify(True, True, -1, 0, 24)
except ValueError:
pass
else:
raise AssertionError("invalid age accepted")
Fictional example: image findings leave the active set because scanning expired. The remediation task stays open until relevant assessment and a documented decision exist.
Common pitfalls
Pitfalls: using an aggregator as a deployment mechanism, treating NOT_APPLICABLE as approval, assuming regional enablement, and interpreting expiry as package remediation.
Related topics: Data recovery and service cutover
Credible sign-off connects resource and scope with current assessment, interpretation of the result, and decisions made about gaps.
Reference: DOP-C02 security and compliance objectives · DOP-C02