Configuration Auditing Feature Overview

For instructions on setting up for Configuration Audit in F5 Distributed Cloud App Infrastructure Protection (AIP), see AWS Integrations Overview.

Introduction

The Distributed Cloud AIP Configuration Auditing (Config Audit) feature allows Amazon Web Services (AWS) users to check their infrastructure (AWS) configuration against industry best practices curated by Distributed Cloud AIP security engineers.

Distributed Cloud AIP comes pre-configured with a set of best practices for AWS Cloud Security. After you integrate Distributed Cloud AIP with your AWS account, you can initiate an audit of the configurations in your account on demand and then schedule regular daily audits.

The following are the major functions of the feature:

  1. Configuration Auditing for users with multiple AWS Profiles
  2. Audit the AWS configuration for violations
  3. View summary of violations
  4. View details of each violation
  5. Suppress specific resources for further configuration checks
  6. Enable/disable/edit configuration audit rules

Access the Config Audit Page

  1. Log into Distributed Cloud AIP.
  2. In the left navigation pane, click Config Audit. The Config Audit page opens.

configauditpage.png

View AWS Profiles on the Config Audit Page

If you have multiple AWS profiles, you can view your AWS integrations by number of violations.

  1. Hover your cursor over any segment under AWS Integrations by Number of Violations. The AWS Integration summary displays.

    integrationbyvio.png
  2. Click the Show Results for Only This Profile button to filter results by profile. The relevant filter displays in the Filter menu.

    awsintegrationfilter.png

Audit the AWS Configuration for Violations

  1. Click the Run button in the upper right corner to begin scanning for violations.

    scanviolations.png

View Summary Results of Violations

  1. Click any listed AWS Service. A summary of the violation scan results displays.

    summaryviolation.png

View Violation Details

  1. Click the Information icon beside any Resource Type. A description of the violation displays.

    infoicon.png
  2. Click the violation you want to view details for. The details pane displays.
  3. Click the Go to Resource Details button. The Resource Details page displays. Here, you can view detailed information about resources and suppressions.

    viodetails.png

Suppress Violation Results on the Resource Details Details Page

  1. On the Resource Details page, click the fire extinguisher icon beside the violation you want to suppress. The Add New Configuration Auditing Policy Suppression menu displays.

    fireextinguishericon.png
  2. Select a reason for suppressing.
  3. Click the Add New Suppression button.

    suppression.png

Configuration Audit Rules

You can view and edit Configuration Auditing Rules from the Rules page.

  1. In the left navigation pane, click Rules. The Rules page displays.

    rulestab.png
  2. To the right of the Configuration Auditing Rule you want to view or edit, click the Details button. The Rule Details pane displays.
  3. Click the Edit button in the upper right corner if you want to make changes to rule severity, enable or disable rules, or modify any rule details. For more information, see Edit Rule Drawer.
Was this article helpful?
0 out of 0 found this helpful