Set up AWS Security Hub and AWS Config
Turn on AWS Config and enable Security Hub CSPM step by step, so your Emnode dashboard can read your compliance findings. Includes setting up AWS Config if you have not already.
Last updated
The Compliance area of your Emnode dashboard reads security findings from AWS Security Hub. Security Hub runs automated checks against your account and grades them against recognised standards, such as the AWS Foundational Security Best Practices. Emnode pulls those findings and maps each one to a fix you can copy and paste.
Security Hub does not work on its own: its checks evaluate the resource configurations that AWS Config records. So this guide does two things, in order. First it sets up AWS Config (skip that part if Config is already recording), then it enables Security Hub and chooses the standards your findings are graded against.
You need access to the AWS account you want assessed, with permission to set up AWS Config and enable Security Hub. Work in the Region you want Emnode to read findings from, and use that same Region throughout. The whole process takes about fifteen minutes and changes none of your workloads. Security Hub offers a 30-day free trial; after that it is billed per check, with current prices on the pricing panel in the console.
Turn on Config, then enable Security Hub
Work through the two parts below. As you scroll each console screen into view it comes into focus; the cyan highlights mark the control to use, and the amber highlights mark a value to write down. If AWS Config is already recording in this Region, skip Part 1 and start at Part 2.
Set up AWS Config
Security Hub runs its checks against the resource configurations AWS Config records. If Config is already recording in this Region, skip to Part 2. Otherwise, work through these five screens first.
Step 1 of 5
Open AWS Config
In the AWS console search bar, type Config and open AWS Config. If Config has never run in this Region you will see the setup splash. Choose Get started.
The 1-click setup button applies these same recommended defaults in one step; we walk through Get started so you can see each choice.
Management Tools
AWS Config
Record and evaluate configurations of your AWS resources
How it works
AWS Config keeps a detailed view of your resources and how their configuration changes over time. Security Hub reads it to evaluate your resources against each standard's controls.
Set up AWS Config
A summarised view of AWS and non-AWS resources, and their compliance with the rules and the resources in each AWS Region.
Choose Get started
Step 2 of 5
Choose what Config records
On the Settings step, keep Record all resource types with customizable overrides and Continuous recording. Recording all resource types gives Security Hub the full picture it checks against.
Under Data governance, keep Use an existing AWS Config service-linked role. Under Delivery channel, leave Create a bucket selected: AWS names this bucket for you. It is internal to Config, so there is nothing to record here. Choose Next.
- Step 1 Settings
- Step 2 Rules
- Step 3 Review
Settings
Recording method
Recording strategy
Recording frequency
Record all resource types, continuously
Data governance
IAM role for AWS Config.
Delivery channel
Amazon S3 bucket where AWS Config delivers configuration snapshots and history.
Step 3 of 5
Skip the managed rules
The Rules step lets you add AWS Config managed rules, but you do not need any here. Security Hub turns on the exact control checks it needs once you enable it.
Leave the selection empty and choose Next.
- ✓ Step 1 Settings
- Step 2 Rules
- Step 3 Review
AWS Managed Rules (694)
Find ruleAdd nothing here, choose Next
Step 4 of 5
Review and confirm
The Review step summarises your choices: recording all resource types, continuously, delivering to the bucket AWS created, with no Config rules of your own.
Choose Confirm to finish. AWS Config starts recording straight away.
- ✓ Step 1 Settings
- ✓ Step 2 Rules
- Step 3 Review
Review
Review your AWS Config setup details. Choose Confirm to finish setting up AWS Config.
Step 1: Settings
Recording method
Recording strategy
Record all resource types with customizable overrides
Recording frequency
Continuous
Delivery method
S3 bucket name
config-bucket-123456789012
Step 2: Rules
AWS Config rules (0)
Choose Confirm
Step 5 of 5
Config is recording
You land on the AWS Config dashboard. Within a few minutes it begins listing your resources and their compliance. Config is now feeding Security Hub the configuration data its checks rely on.
That is the prerequisite done. On to enabling Security Hub itself.
Dashboard
Resource inventory
124
Resources now recorded across this Region.
Compliance status
Evaluations begin once rules report. Security Hub will add its control checks shortly.
Enable Security Hub CSPM
With Config recording, enable Security Hub and choose the standards Emnode maps your findings to. Three screens.
Step 1 of 3
Open Security Hub CSPM
In the search bar, type Security Hub and open AWS Security Hub CSPM. CSPM (cloud security posture management) is the automated control checking Emnode reads.
Choose Go to Security Hub CSPM to start enabling it. A 30-day free trial covers the first month.
Security, Identity & Compliance
AWS Security Hub CSPM
Manage and improve your security posture
How it works
- Runs automated security checks across your AWS environment.
- Prioritises and remediates security issues.
- Consolidates findings from AWS and partner products in one place.
Get started with Security Hub CSPM
Try Security Hub CSPM free for up to 30 days, then run automated checks against your account.
Choose Go to Security Hub CSPM
Step 2 of 3
Choose standards and enable
The Enable AWS Config panel reminds you Security Hub needs Config recording, which you set up in Part 1.
Under Security standards, keep AWS Foundational Security Best Practices v1.0.0 selected: this is the standard the dashboard maps your findings to. You can also enable a CIS AWS Foundations Benchmark. Note which standards you switch on, then choose Enable Security Hub CSPM.
Enable AWS Security Hub CSPM
Enable AWS Config
Before you can enable Security Hub standards and controls, you must first enable resource recording in AWS Config. You did this in Part 1, so Config is recording in this Region.
Security standards
Enabling AWS Security Hub CSPM grants it permissions to conduct security checks.
Keep AWS Foundational Security Best Practices selected
Delegated administrator
Optional. Delegate an account to manage Security Hub CSPM for your AWS Organization.
Choose Enable Security Hub CSPM
Step 3 of 3
Let the first checks run
Security Hub is enabled. It now runs the control checks against the resources AWS Config records. Allow up to two hours for the first results: until then, controls show a status of No data.
Record the Region shown at the top right of the console (Europe (Ireland) in this example). This is the Security Hub Region you give the dashboard.
Summary
Security standards
Standards enabled for this account.
Assets with the most findings
No data available. Checks are still running.
✎ Record this Security Hub Region
What to record
You will hand these to the dashboard when you grant it access to your findings. Note the values you actually used, not the examples.
| Detail | Example | Why it matters |
|---|---|---|
| AWS account ID | 123456789012 | Identifies the account Emnode reads findings from. |
| Security Hub Region | Europe (Ireland) | The Region Emnode reads Security Hub findings from. Record it exactly. |
| Standards enabled | AWS Foundational Security Best Practices v1.0.0 | Emnode groups your compliance findings by the standards you switch on. |
What happens next
Security Hub takes up to a couple of hours to complete its first checks; until then its controls read No data. Once findings appear, you are ready to give the dashboard read-only access so it can pull them. That access is a cross-account role, covered in Grant the dashboard access to your data. Keep the details you recorded to hand: you will confirm the account, Region and standards when you connect the account.
Store the AWS account ID, the Security Hub Region and the standards you enabled somewhere you can find them again. If you ever enable Security Hub in a different Region, tell us, or the dashboard will be reading findings from the wrong place.