More Info:

Ensure that all active sessions in the AWS Session Manager do not exceed the period of time set in the rule settings. Sessions that are active for longer than expected could be the result of suspicious activity. Session manager gives users the ability to open a shell into EC2 instances or execute commands on containers running in ECS.

Risk Level

High

Address

Security

Compliance Standards

CBP

Triage and Remediation

Remediation

To remediate the misconfiguration of SSM Session Length Should Be Minimum in AWS using AWS console, you can follow the below steps:

  1. Login to your AWS console.
  2. Go to the AWS Systems Manager console.
  3. Click on the ‘Managed Instances’ option from the left navigation pane.
  4. Select the instance for which you want to remediate the misconfiguration.
  5. Click on the ‘Actions’ button and select ‘Edit Managed Instance Settings’.
  6. In the ‘Edit Managed Instance Settings’ page, scroll down to the ‘SSM Agent Settings’ section.
  7. In the ‘SSM Session Length’ field, enter the minimum session length you want to set.
  8. Click on the ‘Save Changes’ button.

Once you have followed the above steps, the SSM Session Length will be set to the minimum value you have specified. This will help you remediate the misconfiguration of SSM Session Length Should Be Minimum in AWS.

Additional Reading: