More Info:

Ensure that AWS Config service is configured to include Global resources in order to have complete visibility over the configuration changes made within your AWS account. Global resources are not tied to a specific AWS region and can be used in all regions. Supported Global resource types are IAM users, groups, roles and customer managed policies.

Risk Level

Medium

Address

Security

Compliance Standards

GDPR, APRA, MAS, NIST4

Triage and Remediation

Remediation

To remediate the misconfiguration “AWS Config Should Include Global Resources” for AWS using the AWS console, follow these steps:

  1. Sign in to the AWS Management Console.

  2. Navigate to the AWS Config console at AWS Config Console.

  3. In the main navigation panel, under AWS Config, choose Settings.

  4. Choose Edit to access the configuration settings available for AWS Config in the selected AWS region.

  5. In the General settings section, ensure that Record all resources supported in this region option is selected, select the Include global resources (e.g., AWS IAM resources) checkbox, and choose Save to apply the changes. This will enable you to keep track of configuration changes made to global AWS resources such as IAM resources.

  6. Change the AWS cloud region from the navigation bar and repeat the remediation process for other regions.

Additional Reading: