Skip to main content

More Info:

Ensure that AWS Config service is configured to include Global resources in order to have complete visibility over the configuration changes made within your AWS account. Global resources are not tied to a specific AWS region and can be used in all regions. Supported Global resource types are IAM users, groups, roles and customer managed policies.

Risk Level

Medium

Address

Security

Compliance Standards

  • APRA CPS 234 (Australia)
  • BSI C5 (Germany)
  • Brazil LGPD
  • CCPA / CPRA (California)
  • CIS Critical Security Controls v8
  • CMMC 2.0
  • CSA Cloud Controls Matrix v4
  • DPDPA
  • Digital Operational Resilience Act (EU)
  • Essential 8
  • ISO/IEC 27017
  • ISO/IEC 27018
  • ISO/IEC 27701
  • KSA PDPL
  • MAS Technology Risk Management (Singapore)
  • MITRE ATT&CK (Cloud)
  • NIS2 Directive
  • NIST SP 800-171
  • NYDFS 23 NYCRR 500
  • SWIFT Customer Security Controls Framework
  • Sarbanes-Oxley IT General Controls
  • UK NCSC Cyber Assessment Framework

Triage and Remediation

Remediation

Using Console

Here’s how to enable AWS Config to record global resources (including Route 53) using the AWS Management Console:
  1. Sign in and open AWS Config
    • Go to the AWS Management Console.
    • In the search bar, type “Config” and open AWS Config.
    • Make sure you are in the desired Region (e.g., us-east-1). Global resources are still controlled per-region in Config.
  2. Open Settings (or Set up recorder)
    • If AWS Config is not yet set up:
      • Choose “Get started”.
    • If AWS Config is already set up:
      • In the left navigation pane, choose “Settings”.
  3. Enable recording of global resources
    • In the Resource recording (or Recorder / Resource types to record) section:
      • Find the option “Record global resources (e.g., IAM resources)”.
      • Check or turn ON this option.
        • This is what ensures global services such as Route 53 are included.
  4. Select resource types (if applicable)
    • If you are using Record specific resource types:
      • Ensure Route 53 resource types are selected, for example:
        • AWS::Route53::HostedZone
        • AWS::Route53::HealthCheck
        • Any other Route 53 types relevant to your environment.
    • If you use Record all current and future resource types:
      • Route 53 will automatically be included once global resources are enabled.
  5. Confirm delivery channel
    • In the same Settings page, confirm:
      • S3 bucket for configuration history and snapshots is set.
      • Optionally, SNS topic for notifications is set.
    • These may already be configured; if not, follow the prompts to create/select them.
  6. Save changes
    • Scroll down and choose “Save” / “Save settings”.
    • AWS Config will now begin recording global Route 53 resources.
  7. Verify
    • After a few minutes:
      • In AWS Config, go to “Resources”.
      • In the Resource type filter, search for Route 53 types (e.g., AWS::Route53::HostedZone).
      • Confirm your Route 53 resources are now visible and tracked.
To have AWS Config record global resources like Route 53, you must enable includeGlobalResourceTypes on your configuration recorder.Below are the minimal CLI steps.

1. Find your existing configuration recorder (if any)

Look for the name and current recordingGroup settings, e.g.:
Note the name (e.g., default) and roleARN.

2. Update the recorder to include global resources

Replace the recorder name and role ARN as appropriate:
Key part is includeGlobalResourceTypes=true.If you prefer to record only specific resource types and include Route 53 explicitly:
(Any value of includeGlobalResourceTypes=true will allow global resources like Route 53 to be recorded.)

3. Ensure the recorder is started


4. Verify the configuration

Confirm:
AWS Config will now include global resources (including Route 53) in its recording.
To record Route 53 (a global service) in AWS Config, you must enable recording of global resources in the us-east-1 region, because AWS Config treats global resources there.Below are step‑by‑step instructions plus a Python (boto3) example.

1. Prerequisites

  • boto3 installed:
  • IAM permissions for:
    • config:DescribeConfigurationRecorders
    • config:PutConfigurationRecorder
    • config:StartConfigurationRecorder
  • Run everything in us-east-1:

2. Logic You Need

  1. Connect to AWS Config in us-east-1.
  2. Get existing configuration recorder.
  3. If none exists, create one that:
    • Records all supported resource types.
    • Includes global resource types.
  4. If one exists, update it to include global resources.
  5. Start/restart the configuration recorder.

3. Python Script (boto3)

This script:
  • Ensures there is a recorder called default.
  • Sets includeGlobalResourceTypes=True (legacy style) or adjusts the recording strategy as needed.
  • Starts the recorder.

4. What This Fixes For Route 53

  • Route 53 is a global service.
  • By setting includeGlobalResourceTypes=True in us-east-1, AWS Config starts recording Route 53 resources (and other global resources like IAM), satisfying the requirement: “AWS Config Should Include Global Resources” for Route 53.
Replace AWS_CONFIG_BUCKET_NAME with your S3 bucket name for Config logs. Changing include_global_resource_types from false to true is an in-place update and does not force replacement of the recorder.To verify, terraform plan should show an in-place update to aws_config_configuration_recorder.this.recording_group.include_global_resource_types from false (or null) to true, with no resource recreation.

Additional Reading: