More Info:

Ensure that AWS Config service is configured to include Global resources in order to have complete visibility over the configuration changes made within your AWS account. Global resources are not tied to a specific AWS region and can be used in all regions. Supported Global resource types are IAM users, groups, roles and customer managed policies.

Risk Level

Medium

Address

Security

Compliance Standards

CBP

Triage and Remediation

Remediation

To remediate the misconfiguration “AWS Config Should Include Global Resources” for AWS using the AWS console, follow these steps:

  1. Log in to your AWS account and navigate to the AWS Config console.

  2. Click on the “Rules” tab on the left-hand side of the screen.

  3. Locate the “AWS Config Should Include Global Resources” rule and click on it.

  4. Click on the “Remediation actions” tab.

  5. Click on the “Create remediation action” button.

  6. In the “Create remediation action” window, select the “AWS-EnableConfigGlobalResourceTypes” remediation action.

  7. Click on the “Create” button to create the remediation action.

  8. Once the remediation action is created, select the rule again and click on the “Remediate” button.

  9. In the “Remediate” window, select the “AWS-EnableConfigGlobalResourceTypes” remediation action.

  10. Click on the “Remediate” button to remediate the misconfiguration.

This will enable AWS Config to include global resources and remediate the misconfiguration.

Additional Reading: