Skip to main content
emnode
Browse the docs

Set up AWS Security Hub and AWS Config

Turn on AWS Config and enable Security Hub CSPM step by step, so your Emnode dashboard can read your compliance findings. Includes setting up AWS Config if you have not already.

Last updated

The Compliance area of your Emnode dashboard reads security findings from AWS Security Hub. Security Hub runs automated checks against your account and grades them against recognised standards, such as the AWS Foundational Security Best Practices. Emnode pulls those findings and maps each one to a fix you can copy and paste.

Security Hub does not work on its own: its checks evaluate the resource configurations that AWS Config records. So this guide does two things, in order. First it sets up AWS Config (skip that part if Config is already recording), then it enables Security Hub and chooses the standards your findings are graded against.

Before you begin

You need access to the AWS account you want assessed, with permission to set up AWS Config and enable Security Hub. Work in the Region you want Emnode to read findings from, and use that same Region throughout. The whole process takes about fifteen minutes and changes none of your workloads. Security Hub offers a 30-day free trial; after that it is billed per check, with current prices on the pricing panel in the console.

Turn on Config, then enable Security Hub

Work through the two parts below. As you scroll each console screen into view it comes into focus; the cyan highlights mark the control to use, and the amber highlights mark a value to write down. If AWS Config is already recording in this Region, skip Part 1 and start at Part 2.

Part 1

Set up AWS Config

Security Hub runs its checks against the resource configurations AWS Config records. If Config is already recording in this Region, skip to Part 2. Otherwise, work through these five screens first.

1

Step 1 of 5

Open AWS Config

In the AWS console search bar, type Config and open AWS Config. If Config has never run in this Region you will see the setup splash. Choose Get started.

The 1-click setup button applies these same recommended defaults in one step; we walk through Get started so you can see each choice.

aws

Management Tools

AWS Config

Record and evaluate configurations of your AWS resources

How it works

AWS Config keeps a detailed view of your resources and how their configuration changes over time. Security Hub reads it to evaluate your resources against each standard's controls.

Set up AWS Config

A summarised view of AWS and non-AWS resources, and their compliance with the rules and the resources in each AWS Region.

1
Get started 1-click setup

Choose Get started

2

Step 2 of 5

Choose what Config records

On the Settings step, keep Record all resource types with customizable overrides and Continuous recording. Recording all resource types gives Security Hub the full picture it checks against.

Under Data governance, keep Use an existing AWS Config service-linked role. Under Delivery channel, leave Create a bucket selected: AWS names this bucket for you. It is internal to Config, so there is nothing to record here. Choose Next.

aws

Settings

2

Recording method

Recording strategy

Record all resource types with customizable overrides Record all current and future supported resource types in this account.
Record specific resource types Choose the resource types to record.

Recording frequency

Continuous recording Record configuration changes whenever a change occurs.
Daily recording Record the latest configuration daily, if it has changed.

Record all resource types, continuously

Data governance

IAM role for AWS Config.

Use an existing AWS Config service-linked role The role AWS Config uses to record and evaluate your resources.
Choose a role from your account

Delivery channel

Amazon S3 bucket where AWS Config delivers configuration snapshots and history.

Create a bucket
Choose a bucket from your account
Choose a bucket from another account
CancelNext
3

Step 3 of 5

Skip the managed rules

The Rules step lets you add AWS Config managed rules, but you do not need any here. Security Hub turns on the exact control checks it needs once you enable it.

Leave the selection empty and choose Next.

aws
3

AWS Managed Rules (694)

Find rule
NameResource typesTrigger type
account-part-of-organizations AWS::::Account PERIODIC
acm-certificate-expiration-check AWS::ACM::Certificate CHANGE / PERIODIC
acm-certificate-rsa-check AWS::ACM::Certificate CHANGE-TRIGGERED

Add nothing here, choose Next

CancelPreviousNext
4

Step 4 of 5

Review and confirm

The Review step summarises your choices: recording all resource types, continuously, delivering to the bucket AWS created, with no Config rules of your own.

Choose Confirm to finish. AWS Config starts recording straight away.

aws

Review

Review your AWS Config setup details. Choose Confirm to finish setting up AWS Config.

Step 1: Settings

Recording method

Recording strategy

Record all resource types with customizable overrides

Recording frequency

Continuous

Delivery method

S3 bucket name

config-bucket-123456789012

Step 2: Rules

AWS Config rules (0)

Cancel Previous
4
Confirm

Choose Confirm

5

Step 5 of 5

Config is recording

You land on the AWS Config dashboard. Within a few minutes it begins listing your resources and their compliance. Config is now feeding Security Hub the configuration data its checks rely on.

That is the prerequisite done. On to enabling Security Hub itself.

aws

Dashboard

Resource inventory

124

Resources now recorded across this Region.

Compliance status

Evaluations begin once rules report. Security Hub will add its control checks shortly.

Part 2

Enable Security Hub CSPM

With Config recording, enable Security Hub and choose the standards Emnode maps your findings to. Three screens.

1

Step 1 of 3

Open Security Hub CSPM

In the search bar, type Security Hub and open AWS Security Hub CSPM. CSPM (cloud security posture management) is the automated control checking Emnode reads.

Choose Go to Security Hub CSPM to start enabling it. A 30-day free trial covers the first month.

aws

Security, Identity & Compliance

AWS Security Hub CSPM

Manage and improve your security posture

How it works

  • Runs automated security checks across your AWS environment.
  • Prioritises and remediates security issues.
  • Consolidates findings from AWS and partner products in one place.

Get started with Security Hub CSPM

Try Security Hub CSPM free for up to 30 days, then run automated checks against your account.

1
Go to Security Hub CSPM

Choose Go to Security Hub CSPM

2

Step 2 of 3

Choose standards and enable

The Enable AWS Config panel reminds you Security Hub needs Config recording, which you set up in Part 1.

Under Security standards, keep AWS Foundational Security Best Practices v1.0.0 selected: this is the standard the dashboard maps your findings to. You can also enable a CIS AWS Foundations Benchmark. Note which standards you switch on, then choose Enable Security Hub CSPM.

aws

Enable AWS Security Hub CSPM

Enable AWS Config

Before you can enable Security Hub standards and controls, you must first enable resource recording in AWS Config. You did this in Part 1, so Config is recording in this Region.

Security standards

Enabling AWS Security Hub CSPM grants it permissions to conduct security checks.

2
AWS Foundational Security Best Practices v1.0.0 AWS's own baseline of security controls. The dashboard maps your findings to this standard.
AWS Resource Tagging Standard v1.0.0
CIS AWS Foundations Benchmark v1.2.0
CIS AWS Foundations Benchmark v1.4.0 The Center for Internet Security benchmark. Optional, but a useful second view.
CIS AWS Foundations Benchmark v3.0.0
NIST SP 800-53 Rev 5
PCI DSS v4.0.1

Keep AWS Foundational Security Best Practices selected

Delegated administrator

Optional. Delegate an account to manage Security Hub CSPM for your AWS Organization.

Cancel
Enable Security Hub CSPM

Choose Enable Security Hub CSPM

3

Step 3 of 3

Let the first checks run

Security Hub is enabled. It now runs the control checks against the resources AWS Config records. Allow up to two hours for the first results: until then, controls show a status of No data.

Record the Region shown at the top right of the console (Europe (Ireland) in this example). This is the Security Hub Region you give the dashboard.

aws
After you enable Security Hub CSPM, it can take up to 2 hours to see results from security checks for the newly enabled standards. Until then, the controls have a status of No data.

Summary

Security standards

Standards enabled for this account.

AWS Foundational Security Best Practices v1.0.0No data
CIS AWS Foundations Benchmark v1.4.0No data

Assets with the most findings

No data available. Checks are still running.

Region: Europe (Ireland)

✎ Record this Security Hub Region

Keep these for the next step

What to record

You will hand these to the dashboard when you grant it access to your findings. Note the values you actually used, not the examples.

DetailExample
AWS account ID 123456789012
Security Hub Region Europe (Ireland)
Standards enabled AWS Foundational Security Best Practices v1.0.0

What happens next

Security Hub takes up to a couple of hours to complete its first checks; until then its controls read No data. Once findings appear, you are ready to give the dashboard read-only access so it can pull them. That access is a cross-account role, covered in Grant the dashboard access to your data. Keep the details you recorded to hand: you will confirm the account, Region and standards when you connect the account.

Keep your recorded details safe

Store the AWS account ID, the Security Hub Region and the standards you enabled somewhere you can find them again. If you ever enable Security Hub in a different Region, tell us, or the dashboard will be reading findings from the wrong place.

Spot something wrong on this page?