AWS Security Hub CSPM Posture Report
Delivers a weekly report on Security Hub CSPM coverage across your accounts and regions, what changed in the findings, and anything in the configuration that needs an admin, from disabled controls to broken product integrations.
What this agent does
This read-only agent checks the health of AWS Security Hub CSPM across an organization every week. It finds accounts and enabled regions where Security Hub CSPM is off, the account is not a member of the administrator account, or findings are not aggregated. It compares the enabled standards and controls with a baseline the team approved. It summarizes the Critical and High findings that appeared, were resolved, and were suppressed since last week. It flags anything that needs an admin, such as a product integration that stopped sending findings or a control the team disabled without a reason.
The challenge
Security Hub CSPM only reports on the accounts and regions where it is on. Nothing warns the team when a gap opens. A new account joins the organization while auto-enable is off, so Security Hub CSPM never turns on there. A region is enabled with no Security Hub CSPM. A control is disabled to quiet a noisy finding and never turned back on. Nobody audits who suppressed which finding. A product integration stops delivering, and the dashboard looks cleaner, not broken.
The solution
The agent checks coverage, configuration, integrations, and finding movement in one pass each week and compares them with the previous week and with the approved baseline. It lists what changed and what someone needs to act on, with the fix for each item. Provides a weekly briefing an admin can read in a few minutes.
Workflow
- 01
Check coverage
Compare the organization's accounts and enabled regions with where Security Hub CSPM is on, a member, and aggregated.
- 02
Check configuration
Compare enabled standards, controls, and configuration policies with the approved baseline, and check each product integration's status.
- 03
Check activity
Summarize Critical and High findings that appeared, were resolved, and were suppressed since last week.
- 04
Report
Publish what changed and what needs action, with the fix for each item.
Agent template
# AWS Security Hub CSPM Posture Report
## Measurable outcomes
Every week, the admin knows which accounts and regions Security Hub CSPM is not covering, how the configuration differs from the baseline, how the Critical and High findings moved, and what needs action. Track covered and uncovered account-region pairs, baseline differences, and open action items on every run.
## Procedure
Once a week, from the delegated administrator account, list the organization's accounts and each account's enabled regions. Flag each account-region pair where Security Hub CSPM is off, where the account is not a member of the administrator, or where findings are not aggregated to the aggregation region. Flag accounts that joined the organization and were not enrolled. Compare the enabled standards and controls in each account-region pair with a baseline I approve. Flag each control that is disabled or enabled outside the baseline, with the disabled reason if one was given. When central configuration is on, compare each configuration policy and its account associations with the baseline. Treat a configuration with no approved baseline as a candidate, never as drift. Check each product integration, and flag any integration that is disabled, or that stopped sending after a week with findings. Summarize the new Critical and High findings, the findings resolved, and the findings suppressed since the last report, with who suppressed each one and the note they left. Flag automation rules that suppress findings, with the rule's criteria. Compare everything with last week's report, and lead with what changed. Give every action item the specific fix. Report a check it cannot run as not checked, never as fine.
## Requirements
It needs read-only AWS Security Hub CSPM access in the delegated administrator account, read-only AWS Organizations access to list accounts, and nothing more. It never changes Security Hub CSPM settings, configuration policies, standards, controls, automation rules, or findings, and never approves a baseline. Related templates
-
Aikido Issue Triage
Checks open Aikido findings against the affected repository and writes an evidence-backed decision back to each one.
Vulnerability Management / Application Security 4 tools -
Aikido Posture Report
Delivers a weekly report on Aikido coverage, what changed, and anything in the workspace that needs attention, from failing scans to plan limits.
Reporting and Compliance / Vulnerability Management 4 tools -
AWS Resource Logging and Delivery
Identifies the AWS log sources in an account that are not enabled or not delivering logs.
Reporting and Compliance / Infrastructure Operations 1 tools -
AWS Security Hub CSPM Finding Triage
Writes an evidence-based judgment for each open Critical and High Security Hub CSPM finding, verifies it against the live resource, and suppresses the ones the checks prove are false positives.
Featured Vulnerability Management 2 tools