AWS Config
- AWS Config is a service that enables you to assess, audit, and evaluate the configurations of your AWS resources.
- Config continuously monitors and records your AWS resource configurations and allows you to automate the evaluation of recorded configurations against desired configurations.
Config with Systems Manager
Remediate noncompliant AWS Config rules with AWS Systems Manager Automation runbooks.
Auto-Remediation
- The AWS Config Auto Remediation feature automatically remediates non-compliant resources evaluated by AWS Config rules.
- You can associate remediation actions with AWS Config rules and choose to execute them automatically to address non-compliant resources without manual intervention.
- An AWS Config rule can be applied to identify and remediate any unauthorized changes to the policy associated with the S3 bucket.
- Amazon SNS can be integrated as a destination for alerts.