AWS Config 推出 75 条新托管规则
发布于:
2026年3月18日
AWS Config 宣布新增 75 条托管 Config 规则,涵盖安全性、持久性和运营等多个使用案例。您现在可直接通过 AWS Config 搜索、发现、启用和管理这些新增规则,进一步实现对 AWS 环境中更多使用案例的治理。
通过此次发布,您现在可以在单个账户或整个组织范围内启用这些控制措施。例如,您可以评测自己在 AWS Amplify、Amazon SageMaker、Amazon Route 53 等服务上的安全态势。此外,您还可以利用规则及补救措施套件包将这些新控制措施进行分组,并在单个账户或整个组织范围内部署,从而简化多账户治理。
有关最近发布的规则的完整列表,请访问 AWS Config 开发人员指南。有关每条规则的具体说明及其支持的 AWS 区域,请参阅我们的 Config 托管规则文档。要开始使用 Config 规则,请参阅我们的文档。
新规则已发布:
- ACM_CERTIFICATE_TRANSPARENT_LOGGING_ENABLED
- AMPLIFY_APP_BUILD_SPEC_CONFIGURED
- AMPLIFY_APP_PLATFORM_CHECK
- AMPLIFY_BRANCH_AUTO_BUILD_ENABLED
- AMPLIFY_BRANCH_BUILD_SPEC_CONFIGURED
- AMPLIFY_BRANCH_FRAMEWORK_CONFIGURED
- AMPLIFY_BRANCH_PULL_REQUEST_PREVIEW_ENABLED
- APIGATEWAY_DOMAIN_NAME_TLS_CHECK
- APIGATEWAYV2_INTEGRATION_PRIVATE_HTTPS_ENABLED
- APPINTEGRATIONS_APPLICATION_APPROVED_ORIGINS_CHECK
- APPINTEGRATIONS_APPLICATION_TAGGED
- APPMESH_MESH_IP_PREF_CHECK
- APPMESH_VIRTUAL_GATEWAY_LISTENERS_HEALTH_CHECK_ENABLED
- APPMESH_VIRTUAL_NODE_LISTENERS_HEALTH_CHECK_ENABLED
- APPMESH_VIRTUAL_NODE_LISTENERS_OUTLIER_DETECT_ENABLED
- APPMESH_VIRTUAL_NODE_SERVICE_BACKENDS_TLS_ENFORCED
- CLOUDTRAIL_EVENT_DATA_STORE_MULTI_REGION
- CLOUDWATCH_ALARM_DESCRIPTION
- CODEARTIFACT_REPOSITORY_TAGGED
- CODEBUILD_PROJECT_TAGGED
- EC2_IPAMSCOPE_TAGGED
- EC2_LAUNCHTEMPLATE_EBS_ENCRYPTED
- ECS_SERVICE_PROPAGATE_TAGS_ENABLED
- ELBV2_TARGETGROUP_HEALTHCHECK_PROTOCOL_ENCRYPTED
- ELBV2_TARGETGROUP_PROTOCOL_ENCRYPTED
- EVENTSCHEMAS_DISCOVERER_TAGGED
- EVENTSCHEMAS_REGISTRY_TAGGED
- GROUNDSTATION_CONFIG_TAGGED
- GROUNDSTATION_DATAFLOWENDPOINTGROUP_TAGGED
- GROUNDSTATION_MISSIONPROFILE_TAGGED
- HEALTHLAKE_FHIRDATASTORE_TAGGED
- IAM_OIDC_PROVIDER_CLIENT_ID_LIST_CHECK
- IAM_POLICY_DESCRIPTION
- IMAGEBUILDER_DISTRIBUTIONCONFIGURATION_TAGGED
- IMAGEBUILDER_IMAGEPIPELINE_TAGGED
- IMAGEBUILDER_IMAGERECIPE_EBS_VOLUMES_ENCRYPTED
- IMAGEBUILDER_IMAGERECIPE_TAGGED
- IMAGEBUILDER_INFRASTRUCTURECONFIGURATION_TAGGED
- KINESISVIDEO_SIGNALINGCHANNEL_TAGGED
- KINESISVIDEO_STREAM_TAGGED
- LAMBDA_FUNCTION_APPLICATION_LOG_LEVEL_CHECK
- LAMBDA_FUNCTION_LOG_FORMAT_JSON
- LAMBDA_FUNCTION_SYSTEM_LOG_LEVEL_CHECK
- LIGHTSAIL_BUCKET_OBJECT_VERSIONING_ENABLED
- MEDIAPACKAGE_PACKAGINGCONFIGURATION_TAGGED
- MEDIATAILOR_PLAYBACKCONFIGURATION_TAGGED
- MEMORYDB_SUBNETGROUP_TAGGED
- NEPTUNE_CLUSTER_SNAPSHOT_IAM_DATABASE_AUTH_ENABLED
- OPENSEARCHSERVERLESS_COLLECTION_DESCRIPTION
- OPENSEARCHSERVERLESS_COLLECTION_STANDBYREPLICAS_ENABLED
- PANORAMA_PACKAGE_TAGGED
- RDS_CLUSTER_BACKUP_RETENTION_CHECK
- RDS_GLOBAL_CLUSTER_AURORA_MYSQL_SUPPORTED_VERSION
- RESILIENCEHUB_APP_TAGGED
- RESILIENCEHUB_RESILIENCYPOLICY_TAGGED
- ROUTE53_RECOVERY_CONTROL_CLUSTER_TAGGED
- ROUTE53_RECOVERY_READINESS_CELL_TAGGED
- ROUTE53_RECOVERY_READINESS_READINESS_CHECK_TAGGED
- ROUTE53_RECOVERY_READINESS_RECOVERY_GROUP_TAGGED
- ROUTE53_RECOVERY_READINESS_RESOURCE_SET_TAGGED
- ROUTE53_RESOLVER_RESOLVER_ENDPOINT_TAGGED
- S3_DIRECTORY_BUCKET_LIFECYCLE_POLICY_RULE_CHECK
- SAGEMAKER_DATA_QUALITY_JOB_ENCRYPT_IN_TRANSIT
- SAGEMAKER_DATA_QUALITY_JOB_ISOLATION
- SAGEMAKER_FEATUREGROUP_DESCRIPTION
- SAGEMAKER_INFERENCEEXPERIMENT_TAGGED
- SAGEMAKER_MODEL_BIAS_JOB_ENCRYPT_IN_TRANSIT
- SAGEMAKER_MODEL_BIAS_JOB_ISOLATION
- SAGEMAKER_MODEL_EXPLAINABILITY_JOB_ENCRYPT_IN_TRANSIT
- SAGEMAKER_MODEL_QUALITY_JOB_ENCRYPT_TRANSIT
- SAGEMAKER_MONITORING_SCHEDULE_ISOLATION
- SIGNER_SIGNINGPROFILE_TAGGED
- TRANSFER_CONNECTOR_AS2_ENCRYPTION_ALGORITHM_CHECK
- TRANSFER_CONNECTOR_AS2_MDN_SIGNING_ALGORITHM_CHECK
- TRANSFER_CONNECTOR_AS2_SIGNING_ALGORITHM_CHECK