<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Coffee & Cloud ☁️ ☕️: AWS Security]]></title><description><![CDATA[AWS Cloud Security]]></description><link>https://jakubfras.substack.com/s/aws-cloud</link><image><url>https://substackcdn.com/image/fetch/$s_!PC0T!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d7ca925-dcb5-4d87-8222-8ca545cdbc9b_1280x1280.png</url><title>Coffee &amp; Cloud ☁️ ☕️: AWS Security</title><link>https://jakubfras.substack.com/s/aws-cloud</link></image><generator>Substack</generator><lastBuildDate>Mon, 04 May 2026 23:02:39 GMT</lastBuildDate><atom:link href="https://jakubfras.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Jakub Fras]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[jakubfras@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[jakubfras@substack.com]]></itunes:email><itunes:name><![CDATA[Jakub Fras]]></itunes:name></itunes:owner><itunes:author><![CDATA[Jakub Fras]]></itunes:author><googleplay:owner><![CDATA[jakubfras@substack.com]]></googleplay:owner><googleplay:email><![CDATA[jakubfras@substack.com]]></googleplay:email><googleplay:author><![CDATA[Jakub Fras]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[AWS Security Hub CSPM Feature Breakdown]]></title><description><![CDATA[A hands-on walkthrough of Security Hub CSPM features and behaviour]]></description><link>https://jakubfras.substack.com/p/aws-security-hub-cspm-feature-breakdown</link><guid isPermaLink="false">https://jakubfras.substack.com/p/aws-security-hub-cspm-feature-breakdown</guid><dc:creator><![CDATA[Jakub Fras]]></dc:creator><pubDate>Thu, 01 Jan 2026 13:40:50 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9EOJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F403087cd-852a-4779-9190-3225b6704c37_1600x900.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9EOJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F403087cd-852a-4779-9190-3225b6704c37_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9EOJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F403087cd-852a-4779-9190-3225b6704c37_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!9EOJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F403087cd-852a-4779-9190-3225b6704c37_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!9EOJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F403087cd-852a-4779-9190-3225b6704c37_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!9EOJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F403087cd-852a-4779-9190-3225b6704c37_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9EOJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F403087cd-852a-4779-9190-3225b6704c37_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/403087cd-852a-4779-9190-3225b6704c37_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:41504,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://jakubfras.substack.com/i/182524351?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F403087cd-852a-4779-9190-3225b6704c37_1600x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9EOJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F403087cd-852a-4779-9190-3225b6704c37_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!9EOJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F403087cd-852a-4779-9190-3225b6704c37_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!9EOJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F403087cd-852a-4779-9190-3225b6704c37_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!9EOJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F403087cd-852a-4779-9190-3225b6704c37_1600x900.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In this blog, we&#8217;ll take a detailed look at the <strong>Security Hub CSPM features</strong>. For this purpose, I spun up a set of AWS resources and activated the free trial so you don&#8217;t have to. This post assumes you&#8217;ve already read my earlier blogs covering the new CSPM capability and its solution architecture. If you haven&#8217;t, I&#8217;d highly recommend starting there, as they help build a clear mental model of how everything fits together.</p><h2><strong>Summary page</strong></h2><p>This page is your <strong>at-a-glance view</strong> of what&#8217;s going on in <strong>Security Hub CSPM</strong>. Instead of digging through raw findings, the dashboard uses widgets to summarise your security posture and highlight the issues that matter most.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gsUr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd1b3087-4e1e-4c3c-9b18-d9dfe1d6071f_1600x721.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gsUr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd1b3087-4e1e-4c3c-9b18-d9dfe1d6071f_1600x721.png 424w, https://substackcdn.com/image/fetch/$s_!gsUr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd1b3087-4e1e-4c3c-9b18-d9dfe1d6071f_1600x721.png 848w, https://substackcdn.com/image/fetch/$s_!gsUr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd1b3087-4e1e-4c3c-9b18-d9dfe1d6071f_1600x721.png 1272w, https://substackcdn.com/image/fetch/$s_!gsUr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd1b3087-4e1e-4c3c-9b18-d9dfe1d6071f_1600x721.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gsUr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd1b3087-4e1e-4c3c-9b18-d9dfe1d6071f_1600x721.png" width="585" height="263.57142857142856" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cd1b3087-4e1e-4c3c-9b18-d9dfe1d6071f_1600x721.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:656,&quot;width&quot;:1456,&quot;resizeWidth&quot;:585,&quot;bytes&quot;:207093,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://jakubfras.substack.com/i/182524351?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd1b3087-4e1e-4c3c-9b18-d9dfe1d6071f_1600x721.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gsUr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd1b3087-4e1e-4c3c-9b18-d9dfe1d6071f_1600x721.png 424w, https://substackcdn.com/image/fetch/$s_!gsUr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd1b3087-4e1e-4c3c-9b18-d9dfe1d6071f_1600x721.png 848w, https://substackcdn.com/image/fetch/$s_!gsUr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd1b3087-4e1e-4c3c-9b18-d9dfe1d6071f_1600x721.png 1272w, https://substackcdn.com/image/fetch/$s_!gsUr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd1b3087-4e1e-4c3c-9b18-d9dfe1d6071f_1600x721.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Widgets</strong>: Widgets are based on how security teams actually work and on real feedback from AWS customers. The idea is to help you spot risk quickly, not overwhelm you with noise. You can of course customise the page to suit your needs adding or removing more of the pre defined widgets that AWS makes available. At this time there is no option to make your own widgets from scratch. To customise the dashboard you can:</p><ul><li><p>Add widgets that are useful to you</p></li><li><p>Remove ones that don&#8217;t add value</p></li><li><p>Rearrange the layout to match how you work</p></li></ul><p>Ask yourself:<br>What do I need to see first when I open this page?<br>What helps me make a decision faster?</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sUoo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bc62768-52b9-41ec-b6d6-c6436ffd2b72_826x563.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sUoo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bc62768-52b9-41ec-b6d6-c6436ffd2b72_826x563.png 424w, https://substackcdn.com/image/fetch/$s_!sUoo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bc62768-52b9-41ec-b6d6-c6436ffd2b72_826x563.png 848w, https://substackcdn.com/image/fetch/$s_!sUoo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bc62768-52b9-41ec-b6d6-c6436ffd2b72_826x563.png 1272w, https://substackcdn.com/image/fetch/$s_!sUoo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bc62768-52b9-41ec-b6d6-c6436ffd2b72_826x563.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sUoo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bc62768-52b9-41ec-b6d6-c6436ffd2b72_826x563.png" width="498" height="339.43583535108957" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7bc62768-52b9-41ec-b6d6-c6436ffd2b72_826x563.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:563,&quot;width&quot;:826,&quot;resizeWidth&quot;:498,&quot;bytes&quot;:66379,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://jakubfras.substack.com/i/182524351?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bc62768-52b9-41ec-b6d6-c6436ffd2b72_826x563.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sUoo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bc62768-52b9-41ec-b6d6-c6436ffd2b72_826x563.png 424w, https://substackcdn.com/image/fetch/$s_!sUoo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bc62768-52b9-41ec-b6d6-c6436ffd2b72_826x563.png 848w, https://substackcdn.com/image/fetch/$s_!sUoo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bc62768-52b9-41ec-b6d6-c6436ffd2b72_826x563.png 1272w, https://substackcdn.com/image/fetch/$s_!sUoo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bc62768-52b9-41ec-b6d6-c6436ffd2b72_826x563.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h4><strong>Using filters to stay focused</strong></h4><p>At the top of the page, you can apply filters to narrow what the dashboard shows. You can save these filters as a <strong>filter set</strong>, so you don&#8217;t have to rebuild the same view every time. Just load it and carry on where you left off.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FWHc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a549e69-18f4-420f-ad67-827d83784346_1074x131.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FWHc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a549e69-18f4-420f-ad67-827d83784346_1074x131.png 424w, https://substackcdn.com/image/fetch/$s_!FWHc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a549e69-18f4-420f-ad67-827d83784346_1074x131.png 848w, https://substackcdn.com/image/fetch/$s_!FWHc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a549e69-18f4-420f-ad67-827d83784346_1074x131.png 1272w, https://substackcdn.com/image/fetch/$s_!FWHc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a549e69-18f4-420f-ad67-827d83784346_1074x131.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FWHc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a549e69-18f4-420f-ad67-827d83784346_1074x131.png" width="1074" height="131" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2a549e69-18f4-420f-ad67-827d83784346_1074x131.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:131,&quot;width&quot;:1074,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:28084,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://jakubfras.substack.com/i/182524351?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a549e69-18f4-420f-ad67-827d83784346_1074x131.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FWHc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a549e69-18f4-420f-ad67-827d83784346_1074x131.png 424w, https://substackcdn.com/image/fetch/$s_!FWHc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a549e69-18f4-420f-ad67-827d83784346_1074x131.png 848w, https://substackcdn.com/image/fetch/$s_!FWHc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a549e69-18f4-420f-ad67-827d83784346_1074x131.png 1272w, https://substackcdn.com/image/fetch/$s_!FWHc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a549e69-18f4-420f-ad67-827d83784346_1074x131.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h4>What data is actually included?</h4><p>If you&#8217;ve set an <strong>aggregation Region</strong>, the dashboard shows findings from that Region <strong>and</strong> all linked Regions. If your account is a <strong>Security Hub CSPM administrator</strong>, the view goes even wider. You&#8217;ll see findings from:</p><ul><li><p>The administrator account</p></li><li><p>All member accounts in scope</p></li></ul><p>Understanding that context is critical, especially when you&#8217;re making decisions based on what the dashboard is telling you.</p><div><hr></div><h1>Controls</h1><p>In AWS Security Hub CSPM, a security control, also referred to as a control, is a safeguard within a security standard such as CIS. A control relates to a specific resource or account level checks part of the standard.</p><p>When you enable a control in one or more standards, Security Hub CSPM begins running security checks on it for the in scope resources or accounts. The security checks result in Security Hub CSPM findings.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AEhl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F346ede25-6856-4f14-a367-211a79716062_1594x696.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AEhl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F346ede25-6856-4f14-a367-211a79716062_1594x696.png 424w, https://substackcdn.com/image/fetch/$s_!AEhl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F346ede25-6856-4f14-a367-211a79716062_1594x696.png 848w, https://substackcdn.com/image/fetch/$s_!AEhl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F346ede25-6856-4f14-a367-211a79716062_1594x696.png 1272w, https://substackcdn.com/image/fetch/$s_!AEhl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F346ede25-6856-4f14-a367-211a79716062_1594x696.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AEhl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F346ede25-6856-4f14-a367-211a79716062_1594x696.png" width="1456" height="636" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/346ede25-6856-4f14-a367-211a79716062_1594x696.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:636,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:175519,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://jakubfras.substack.com/i/182524351?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F346ede25-6856-4f14-a367-211a79716062_1594x696.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!AEhl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F346ede25-6856-4f14-a367-211a79716062_1594x696.png 424w, https://substackcdn.com/image/fetch/$s_!AEhl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F346ede25-6856-4f14-a367-211a79716062_1594x696.png 848w, https://substackcdn.com/image/fetch/$s_!AEhl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F346ede25-6856-4f14-a367-211a79716062_1594x696.png 1272w, https://substackcdn.com/image/fetch/$s_!AEhl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F346ede25-6856-4f14-a367-211a79716062_1594x696.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Can I disable a control?</strong></p><p>You can enable or disable controls individually for a single account and AWS Region. To save time and reduce configuration drift in multi-account environments, AWS recommend using <a href="https://docs.aws.amazon.com/securityhub/latest/userguide/central-configuration-intro.html">central configuration</a> to enable or disable controls. With central configuration, the delegated Security Hub CSPM administrator can create policies that specify how a control should be configured across multiple accounts and Regions.</p><p><strong>What if a control is part of multiple standards?</strong></p><p>If you&#8217;ve turned on consolidated control findings, Security Hub CSPM generates a single finding even when a control is associated with more than one standard. For more information, see <a href="https://docs.aws.amazon.com/securityhub/latest/userguide/controls-findings-create-update.html#consolidated-control-findings">Consolidated control findings</a>.</p><p><strong>Severity levels</strong></p><p>Severity levels for controls are rated from:  CRITICAL, HIGH, MEDIUM, LOW</p><p><strong>Status of controls </strong></p><p>For administrator accounts, the <strong>Controls</strong> page reflects the status of controls across the member accounts. If a control check fails in at least one member account, the control status is <strong>Failed</strong>. If you have set an <a href="https://docs.aws.amazon.com/securityhub/latest/userguide/finding-aggregation.html">aggregation Region</a>, the <strong>Controls</strong> page reflects the status of controls across all linked Regions. If a control check fails in at least one linked Region, the control status is <strong>Failed</strong>. Controls are evaluated periodically but the emulation can also be triggered manually.</p><p><strong>Security score (new): </strong></p><p>Security Hub CSPM uses the compliance status of control findings to determine an overall control status. Based on the control status, Security Hub CSPM also calculates a security score across all enabled controls and for specific standards.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Fxvw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7433dbe1-394e-49e7-93d5-97e199de8ff2_691x246.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Fxvw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7433dbe1-394e-49e7-93d5-97e199de8ff2_691x246.png 424w, https://substackcdn.com/image/fetch/$s_!Fxvw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7433dbe1-394e-49e7-93d5-97e199de8ff2_691x246.png 848w, https://substackcdn.com/image/fetch/$s_!Fxvw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7433dbe1-394e-49e7-93d5-97e199de8ff2_691x246.png 1272w, https://substackcdn.com/image/fetch/$s_!Fxvw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7433dbe1-394e-49e7-93d5-97e199de8ff2_691x246.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Fxvw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7433dbe1-394e-49e7-93d5-97e199de8ff2_691x246.png" width="691" height="246" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7433dbe1-394e-49e7-93d5-97e199de8ff2_691x246.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:246,&quot;width&quot;:691,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:24330,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://jakubfras.substack.com/i/182524351?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7433dbe1-394e-49e7-93d5-97e199de8ff2_691x246.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Fxvw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7433dbe1-394e-49e7-93d5-97e199de8ff2_691x246.png 424w, https://substackcdn.com/image/fetch/$s_!Fxvw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7433dbe1-394e-49e7-93d5-97e199de8ff2_691x246.png 848w, https://substackcdn.com/image/fetch/$s_!Fxvw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7433dbe1-394e-49e7-93d5-97e199de8ff2_691x246.png 1272w, https://substackcdn.com/image/fetch/$s_!Fxvw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7433dbe1-394e-49e7-93d5-97e199de8ff2_691x246.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The <strong>Controls</strong> page of the Security Hub CSPM console displays all of the controls available in the current AWS Region (you can view controls in the context of a standard by visiting the <strong>Security standards</strong> page and choosing an enabled standard). Security Hub CSPM assigns controls a consistent security control ID, title, and description across standards. Controls IDs include the relevant AWS service and a unique number (for example, CodeBuild.3).</p><p>AWS Config must be enabled with resource recording for scores to appear. ( See my blog on CSPM Architecture breakdown).</p><p><strong>How its calculated?</strong></p><p>Security scores represent the proportion of <strong>Passed</strong> controls to enabled controls. The score is displayed as a percentage rounded up or down to the nearest whole number.</p><p>Security Hub CSPM calculates a summary security score across all of your enabled standards. Security Hub CSPM also calculates a security score for each enabled standard. For purposes of score calculation, enabled controls include controls with a status of <strong>Passed</strong>, <strong>Failed</strong>, and <strong>Unknown</strong>. Controls with a status of <strong>No data</strong> are excluded from the score calculation. Security Hub CSPM ignores archived and suppressed findings when calculating control status. This can impact security scores. For example, if you suppress all failed findings for a control, its status becomes <strong>Passed</strong>, which can in turn improve your security scores.</p><p><strong>When is the score updated &amp; what if I have multiple regions?</strong></p><p>After first-time score generation, Security Hub CSPM updates security scores every 24 hours. Security Hub CSPM displays a timestamp to indicate when a security score was last updated.</p><p>If you have set an aggregation Region, the overall security score reflects control findings across linked Regions.</p><div><hr></div><h1>Security standards</h1><p>When you enable a standard, Security Hub CSPM automatically enables all the controls that apply to the standard. Security Hub CSPM then runs security checks on the controls, which generates Security Hub CSPM findings ( as seen in the finding tab covered below). </p><p>You can disable and later re-enable individual controls as necessary. You can also disable a standard completely. If you disable a standard, Security Hub CSPM stops running security checks on controls that apply to the standard. Findings are no longer generated for the controls.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jDld!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd88264a4-4f86-426c-bb65-2624fa319f34_1420x645.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jDld!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd88264a4-4f86-426c-bb65-2624fa319f34_1420x645.png 424w, https://substackcdn.com/image/fetch/$s_!jDld!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd88264a4-4f86-426c-bb65-2624fa319f34_1420x645.png 848w, https://substackcdn.com/image/fetch/$s_!jDld!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd88264a4-4f86-426c-bb65-2624fa319f34_1420x645.png 1272w, https://substackcdn.com/image/fetch/$s_!jDld!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd88264a4-4f86-426c-bb65-2624fa319f34_1420x645.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jDld!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd88264a4-4f86-426c-bb65-2624fa319f34_1420x645.png" width="1420" height="645" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d88264a4-4f86-426c-bb65-2624fa319f34_1420x645.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:645,&quot;width&quot;:1420,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:125628,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://jakubfras.substack.com/i/182524351?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd88264a4-4f86-426c-bb65-2624fa319f34_1420x645.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jDld!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd88264a4-4f86-426c-bb65-2624fa319f34_1420x645.png 424w, https://substackcdn.com/image/fetch/$s_!jDld!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd88264a4-4f86-426c-bb65-2624fa319f34_1420x645.png 848w, https://substackcdn.com/image/fetch/$s_!jDld!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd88264a4-4f86-426c-bb65-2624fa319f34_1420x645.png 1272w, https://substackcdn.com/image/fetch/$s_!jDld!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd88264a4-4f86-426c-bb65-2624fa319f34_1420x645.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In addition to findings, Security Hub CSPM generates a security score for each standard that you enable. The score is based on the status of the controls that apply to the standard. If you set an aggregation Region, the security score for a standard reflects the status of the controls across all linked Regions.</p><p> <a href="https://docs.aws.amazon.com/securityhub/latest/userguide/standards-reference.html">Supported Standards reference for Security Hub CSPM</a></p><p>Standards can be automatically enabled on new accounts and regions with <a href="https://docs.aws.amazon.com/securityhub/latest/userguide/central-configuration-intro.html">central configuration</a>.</p><p>Some standards such as the CIS V5 are not deployed via a conformance pack, instead they are AWS managed and deployed automatically when you enable teh standard. <a href="https://docs.aws.amazon.com/config/latest/developerguide/service-linked-awsconfig-rules.html">These are known as service linked rules</a>.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Paue!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9ea7433-224f-471f-905b-305ae1082299_1564x253.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Paue!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9ea7433-224f-471f-905b-305ae1082299_1564x253.png 424w, https://substackcdn.com/image/fetch/$s_!Paue!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9ea7433-224f-471f-905b-305ae1082299_1564x253.png 848w, https://substackcdn.com/image/fetch/$s_!Paue!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9ea7433-224f-471f-905b-305ae1082299_1564x253.png 1272w, https://substackcdn.com/image/fetch/$s_!Paue!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9ea7433-224f-471f-905b-305ae1082299_1564x253.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Paue!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9ea7433-224f-471f-905b-305ae1082299_1564x253.png" width="1456" height="236" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c9ea7433-224f-471f-905b-305ae1082299_1564x253.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:236,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:46692,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://jakubfras.substack.com/i/182524351?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9ea7433-224f-471f-905b-305ae1082299_1564x253.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Paue!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9ea7433-224f-471f-905b-305ae1082299_1564x253.png 424w, https://substackcdn.com/image/fetch/$s_!Paue!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9ea7433-224f-471f-905b-305ae1082299_1564x253.png 848w, https://substackcdn.com/image/fetch/$s_!Paue!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9ea7433-224f-471f-905b-305ae1082299_1564x253.png 1272w, https://substackcdn.com/image/fetch/$s_!Paue!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9ea7433-224f-471f-905b-305ae1082299_1564x253.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div><hr></div><h1>Insights</h1><p>In AWS Security Hub CSPM, an <em>insight</em> is a way of grouping related findings so you can spot patterns instead of looking at issues one by one. Rather than asking &#8220;what&#8217;s wrong?&#8221;, insights help you ask &#8220;where is the problem concentrated?&#8221;. For example, an insight might highlight EC2 instances that repeatedly fail security checks, pulling together findings from multiple providers into one view. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IFGJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34cfa87b-61d9-4179-9e10-417fc676bcbc_1350x505.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IFGJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34cfa87b-61d9-4179-9e10-417fc676bcbc_1350x505.png 424w, https://substackcdn.com/image/fetch/$s_!IFGJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34cfa87b-61d9-4179-9e10-417fc676bcbc_1350x505.png 848w, https://substackcdn.com/image/fetch/$s_!IFGJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34cfa87b-61d9-4179-9e10-417fc676bcbc_1350x505.png 1272w, https://substackcdn.com/image/fetch/$s_!IFGJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34cfa87b-61d9-4179-9e10-417fc676bcbc_1350x505.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IFGJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34cfa87b-61d9-4179-9e10-417fc676bcbc_1350x505.png" width="1350" height="505" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/34cfa87b-61d9-4179-9e10-417fc676bcbc_1350x505.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:505,&quot;width&quot;:1350,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:103432,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://jakubfras.substack.com/i/182524351?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34cfa87b-61d9-4179-9e10-417fc676bcbc_1350x505.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IFGJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34cfa87b-61d9-4179-9e10-417fc676bcbc_1350x505.png 424w, https://substackcdn.com/image/fetch/$s_!IFGJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34cfa87b-61d9-4179-9e10-417fc676bcbc_1350x505.png 848w, https://substackcdn.com/image/fetch/$s_!IFGJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34cfa87b-61d9-4179-9e10-417fc676bcbc_1350x505.png 1272w, https://substackcdn.com/image/fetch/$s_!IFGJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34cfa87b-61d9-4179-9e10-417fc676bcbc_1350x505.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Each insight is built using two simple ideas: <strong>grouping</strong> and <strong>filters</strong>. Grouping defines <em>what</em> you want to list (such as resources, accounts, or Regions), while filters define <em>which findings</em> should be included. Security Hub CSPM gives you managed insights out of the box, which you can&#8217;t change, but you can also create custom insights tailored to your environment. On the Insights page in the console, you can filter between managed and custom insights, search by name, and focus only on what&#8217;s relevant. One important question to keep in mind: if an insight shows no results, is it because everything is secure or because the related standard or integration hasn&#8217;t been enabled yet?</p><p>Creating custom insights: When creating <strong>custom insights</strong>, you&#8217;re in control of what Security Hub CSPM shows you. By choosing the right combination of <strong>grouping</strong> and <strong>filters</strong>. To create one you can use the Security Hub CSPM console, Security Hub CSPM API or PowerShell.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!iq1J!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9abae6e1-8a83-4cdd-830f-e7172176cfed_1483x390.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iq1J!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9abae6e1-8a83-4cdd-830f-e7172176cfed_1483x390.png 424w, https://substackcdn.com/image/fetch/$s_!iq1J!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9abae6e1-8a83-4cdd-830f-e7172176cfed_1483x390.png 848w, https://substackcdn.com/image/fetch/$s_!iq1J!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9abae6e1-8a83-4cdd-830f-e7172176cfed_1483x390.png 1272w, https://substackcdn.com/image/fetch/$s_!iq1J!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9abae6e1-8a83-4cdd-830f-e7172176cfed_1483x390.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iq1J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9abae6e1-8a83-4cdd-830f-e7172176cfed_1483x390.png" width="1456" height="383" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9abae6e1-8a83-4cdd-830f-e7172176cfed_1483x390.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:383,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:69420,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://jakubfras.substack.com/i/182524351?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9abae6e1-8a83-4cdd-830f-e7172176cfed_1483x390.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!iq1J!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9abae6e1-8a83-4cdd-830f-e7172176cfed_1483x390.png 424w, https://substackcdn.com/image/fetch/$s_!iq1J!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9abae6e1-8a83-4cdd-830f-e7172176cfed_1483x390.png 848w, https://substackcdn.com/image/fetch/$s_!iq1J!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9abae6e1-8a83-4cdd-830f-e7172176cfed_1483x390.png 1272w, https://substackcdn.com/image/fetch/$s_!iq1J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9abae6e1-8a83-4cdd-830f-e7172176cfed_1483x390.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h1>Findings</h1><p>In <strong>AWS Security Hub CSPM</strong>, a <em>finding</em> is a single recorded result of a security check or detection. It answers a basic question: <em>did something pass, fail, or need attention?</em> </p><p>Findings can come from CSPM controls, other AWS security services, third-party tools, or even your own custom integrations. No matter where they come from, Security Hub CSPM converts them into a common format called <strong>ASFF</strong>, so everything looks and behaves consistently. If you use cross-Region aggregation, those findings are automatically rolled up into your chosen aggregation Region.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PoFF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F547a33c4-b8b0-43b1-8eb4-d0ad885cb98f_1424x731.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PoFF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F547a33c4-b8b0-43b1-8eb4-d0ad885cb98f_1424x731.png 424w, https://substackcdn.com/image/fetch/$s_!PoFF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F547a33c4-b8b0-43b1-8eb4-d0ad885cb98f_1424x731.png 848w, https://substackcdn.com/image/fetch/$s_!PoFF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F547a33c4-b8b0-43b1-8eb4-d0ad885cb98f_1424x731.png 1272w, https://substackcdn.com/image/fetch/$s_!PoFF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F547a33c4-b8b0-43b1-8eb4-d0ad885cb98f_1424x731.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PoFF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F547a33c4-b8b0-43b1-8eb4-d0ad885cb98f_1424x731.png" width="1424" height="731" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/547a33c4-b8b0-43b1-8eb4-d0ad885cb98f_1424x731.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:731,&quot;width&quot;:1424,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:251178,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://jakubfras.substack.com/i/182524351?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F547a33c4-b8b0-43b1-8eb4-d0ad885cb98f_1424x731.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PoFF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F547a33c4-b8b0-43b1-8eb4-d0ad885cb98f_1424x731.png 424w, https://substackcdn.com/image/fetch/$s_!PoFF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F547a33c4-b8b0-43b1-8eb4-d0ad885cb98f_1424x731.png 848w, https://substackcdn.com/image/fetch/$s_!PoFF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F547a33c4-b8b0-43b1-8eb4-d0ad885cb98f_1424x731.png 1272w, https://substackcdn.com/image/fetch/$s_!PoFF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F547a33c4-b8b0-43b1-8eb4-d0ad885cb98f_1424x731.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Once a finding exists, it doesn&#8217;t stay static. Providers can update the findings they created, and you (or tools like SIEMs and SOAR platforms) can update investigation status through the console or API. To avoid long-term noise, Security Hub CSPM automatically deletes old findings: active findings expire after 90 days without updates, and archived ones after 30 days. Control findings rely mainly on the <em>last update time</em>, while other findings use whichever is most recent between processing and update time. If you need longer history, you&#8217;ll need to export findings to S3 using EventBridge because if a finding disappears, will you still have the evidence you need later?</p><blockquote><p><strong>IMPORTANT</strong>: Although AWS Security Hub and Security Hub CSPM use the same underlying findings platform, they do not share findings in the way many people expect. <strong>Security Hub CSPM acts as a separate finding producer, </strong>which means it creates its own findings even when an equivalent Security Hub control already exists for the same resource. As a result, closing a finding in Security Hub only updates the workflow status of that specific finding and does not automatically close or suppress a related CSPM finding. Each finding has its own ID, generator, and lifecycle, and it will only resolve automatically when the underlying configuration is fixed and the control is re-evaluated.</p></blockquote><ul><li><p><strong>Security Hub CSPM:</strong> Uses the <strong><a href="https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-findings-format.html">AWS Security Finding Format (ASFF)</a></strong>.</p></li><li><p><strong>Security Hub:</strong> Uses the <strong><a href="https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-ocsf.html">OCSF</a></strong> format. While they track the same resource issues, they are technically separate &#8220;records&#8221; because the data structure is different.</p></li></ul><p>Where is my single place of truth?</p><blockquote><p><em>Security Hub is the central place where findings live, but Security Hub CSPM should be treated as the authoritative source for security posture. To avoid duplicate findings and inconsistent reporting, posture reporting should be based only on CSPM findings, with Security Hub used for triage, automation, and response.</em></p></blockquote><p>Is the API shared between Security hub CSPM and Security Hub?</p><blockquote><p>AWS Security Hub and Security Hub CSPM do not have separate <a href="https://docs.aws.amazon.com/securityhub/1.0/APIReference/Welcome.html">APIs</a>. CSPM findings are accessed through the same Security Hub API as all other findings, because Security Hub acts as the central findings platform. However, CSPM is a separate finding producer within that platform, so its findings are distinct objects that must be filtered explicitly (for example by ProductName or ProductArn). Using the same API does not mean the findings are shared or automatically linked it simply means they are managed through a single interface.</p></blockquote><p>What is the posture management tab in security hub?</p><blockquote><p>The posture management tab in security hub: The Posture management tab in Security Hub is the front-end for Security Hub CSPM. It visualises CSPM posture results and findings, but the findings themselves are still separate CSPM-generated findings stored and accessed through the Security Hub API.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HIu9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F156c3d4e-4b7f-4223-8018-075bd0e748fb_1564x622.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HIu9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F156c3d4e-4b7f-4223-8018-075bd0e748fb_1564x622.png 424w, https://substackcdn.com/image/fetch/$s_!HIu9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F156c3d4e-4b7f-4223-8018-075bd0e748fb_1564x622.png 848w, https://substackcdn.com/image/fetch/$s_!HIu9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F156c3d4e-4b7f-4223-8018-075bd0e748fb_1564x622.png 1272w, https://substackcdn.com/image/fetch/$s_!HIu9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F156c3d4e-4b7f-4223-8018-075bd0e748fb_1564x622.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HIu9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F156c3d4e-4b7f-4223-8018-075bd0e748fb_1564x622.png" width="1456" height="579" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/156c3d4e-4b7f-4223-8018-075bd0e748fb_1564x622.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:579,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:144116,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://jakubfras.substack.com/i/182524351?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F156c3d4e-4b7f-4223-8018-075bd0e748fb_1564x622.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HIu9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F156c3d4e-4b7f-4223-8018-075bd0e748fb_1564x622.png 424w, https://substackcdn.com/image/fetch/$s_!HIu9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F156c3d4e-4b7f-4223-8018-075bd0e748fb_1564x622.png 848w, https://substackcdn.com/image/fetch/$s_!HIu9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F156c3d4e-4b7f-4223-8018-075bd0e748fb_1564x622.png 1272w, https://substackcdn.com/image/fetch/$s_!HIu9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F156c3d4e-4b7f-4223-8018-075bd0e748fb_1564x622.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I&#8217;ll be breaking down more advanced features in upcoming blogs, stay tuned!</p><ul><li><p>Automations - in depth blog coming soon</p></li><li><p>Custom actions - in depth blog coming soon</p></li></ul><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://jakubfras.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://jakubfras.substack.com/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://jakubfras.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share Coffee &amp; Cloud &#9729;&#65039; &#9749;&#65039;&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://jakubfras.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share Coffee &amp; Cloud &#9729;&#65039; &#9749;&#65039;</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://jakubfras.substack.com/p/part-three-integrating-devsecops/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://jakubfras.substack.com/p/part-three-integrating-devsecops/comments"><span>Leave a comment</span></a></p><p>Have blog ideas, want to engage on a topic, or explore collaboration? Let&#8217;s take it offline reach out on <strong><a href="https://www.linkedin.com/in/jakub-fras/">LinkedIn</a></strong>. I&#8217;d love to connect and continue the conversation!</p>]]></content:encoded></item><item><title><![CDATA[AWS Security Hub CSPM architecture ]]></title><description><![CDATA[In this blog we'll break down and simplify the architecture of the new Security Hub CSPM]]></description><link>https://jakubfras.substack.com/p/aws-security-hub-cspm-architecture</link><guid isPermaLink="false">https://jakubfras.substack.com/p/aws-security-hub-cspm-architecture</guid><pubDate>Thu, 01 Jan 2026 13:40:01 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!_WHQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e3536c-7fd9-443b-9965-dccef54d47b0_1600x900.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_WHQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e3536c-7fd9-443b-9965-dccef54d47b0_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_WHQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e3536c-7fd9-443b-9965-dccef54d47b0_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!_WHQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e3536c-7fd9-443b-9965-dccef54d47b0_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!_WHQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e3536c-7fd9-443b-9965-dccef54d47b0_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!_WHQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e3536c-7fd9-443b-9965-dccef54d47b0_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_WHQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e3536c-7fd9-443b-9965-dccef54d47b0_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/39e3536c-7fd9-443b-9965-dccef54d47b0_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:36298,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://jakubfras.substack.com/i/182630597?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e3536c-7fd9-443b-9965-dccef54d47b0_1600x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_WHQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e3536c-7fd9-443b-9965-dccef54d47b0_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!_WHQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e3536c-7fd9-443b-9965-dccef54d47b0_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!_WHQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e3536c-7fd9-443b-9965-dccef54d47b0_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!_WHQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e3536c-7fd9-443b-9965-dccef54d47b0_1600x900.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In my previous blog, I covered what the new AWS Security Hub CSPM capability provides and why it exists. In this post, we&#8217;re going a level deeper.</p><p>This blog focuses on the <strong>solution architecture behind Security Hub CSPM</strong> how data flows through AWS services, where findings come from, how they&#8217;re analysed, and how they ultimately surface as exposures in Security Hub.</p><p>The goal here isn&#8217;t to repeat documentation.<strong> It&#8217;s to give you a clear mental model of how the service works </strong>so you can make informed decisions about enablement and operational impact.</p><h2>Where does security CSPM data come from?</h2><p>The data you see in AWS Security Hub and Security Hub CSPM comes from two sources: AWS-native security services and third-party security tools that you choose to integrate.</p><p>Security Hub CSPM focuses on <strong>security posture</strong>. It evaluates how your AWS environment is configured and whether it aligns with security standards and best practices.</p><h3>AWS native services used by Security Hub CSPM</h3><p>Security Hub CSPM evaluates security posture using data from multiple AWS native services with <strong>AWS Config being the core and required data source</strong>, providing resource configuration state and change history used by most CSPM controls. </p><p>In addition, CSPM uses data from <strong>IAM, IAM Access Analyzer, AWS Organizations, and read-only AWS service APIs</strong> to evaluate account- and organisation-level controls that are not purely resource based. Together, these services allow Security Hub CSPM to assess standards. For example CIS AWS Foundations Benchmark v5.0.0 is evaluated by Security Hub CSPM using a combination of AWS Config data and other AWS service APIs, depending on whether a control is resource, account, or organisation-level.</p><p>AWS Config is therefore a <strong>prerequisite</strong> for Security Hub CSPM. Without it, a large portion of CSPM controls cannot be evaluated and will report no data or incomplete results.</p><h3>AWS native detection services in Security Hub (not CSPM)</h3><p>Services such as <strong>Amazon GuardDuty</strong>, <strong>Amazon Inspector</strong>, and <strong>Amazon Macie</strong> provide <strong>detections</strong>, not posture assessments.</p><p>These services identify threats, vulnerabilities, and data exposure risks. Their findings are sent to Security Hub and shown alongside CSPM results, but they are <strong>not the source of CSPM posture data</strong>.</p><h3>How Security Hub brings this together</h3><p>Security Hub acts as the central place where posture findings from CSPM and detections from other AWS services are normalised and correlated. Each service provides a different type of signal, and viewing them together gives security teams better context and prioritisation.</p><h3>Getting data from AWS native services into Security Hub CSPM</h3><p>Security Hub CSPM <strong>evaluates your security posture</strong> using data from AWS-native services (for example, configuration state, identity settings, and resource metadata).<br><strong>It turns that data into controls and posture results</strong>, which are the surface in Security Hub as findings.</p><ul><li><p><strong>If you are not using AWS Organisations</strong>, you enable Security Hub CSPM in one AWS account. That account can then invite other AWS accounts to join as member accounts. Once an invitation is accepted, the account that sent the invite becomes the administrator account, and the invited accounts become member accounts. The administrator account can manage Security Hub CSPM settings and view CSPM findings for its member accounts. An account cannot be both an administrator and a member at the same time, and each member account can only be associated with a single administrator account. This approach works for smaller setups but becomes harder to manage as the number of accounts grows.</p></li><li><p><strong>When using AWS Organisations</strong>, you select one account to act as the Security Hub CSPM administrator for the organisation. This administrator account manages CSPM centrally and can enable it across other organisation accounts, which automatically become member accounts. No manual invitations are required, and onboarding new accounts is much simpler. This model provides better scale, consistency, and central visibility, making it the recommended approach for most environments.</p></li></ul><h3>Regional setup</h3><p>Security Hub CSPM operates on a regional basis, but findings can be centrally viewed using region aggregation. This allows security teams to manage posture results without switching between regions.</p><h3>Region aggregation</h3><p>When region aggregation is enabled, one region is designated as the <strong>home region</strong>. CSPM findings from other enabled regions are automatically sent to this home region, where they are normalised and displayed in Security Hub.</p><p>This provides a single view of security posture across regions while still allowing CSPM controls to run locally where resources exist. Even when findings are aggregated into a single home region, <strong>each finding still belongs to the original account and region</strong> where it was generated. This also means remediation workflows must run in the <strong>source account</strong>, not the administrator account.</p><h3>Linked regions</h3><p>Linked regions are the AWS regions that send their CSPM findings to the home region. Controls continue to be evaluated in each linked region, but the results are aggregated centrally.</p><p>This setup simplifies reporting and investigation while preserving regional evaluation and scope.</p><blockquote><p>For multi-region environments, findings are evaluated in the region where the resource or setting exists and then forwarded to the designated home region using region aggregation. This provides a single, central view of posture without duplicating data collection.</p></blockquote><h3>How is data stored?</h3><p>Security Hub findings are stored <strong>natively inside the Security Hub service</strong>.<br>You do not get direct access to an underlying database or log store.</p><p>You interact with the data through:</p><ul><li><p>The AWS console</p></li><li><p>The Security Hub APIs</p></li><li><p>The AWS CLI</p></li><li><p>SDKs</p></li></ul><p>There is no native query engine like KQL or log analytics work space where the data ends up if you are familiar with how Azure works with its security services. Security Hub CSPM data can be sent out using EventBridge and exported to services like S3, Lambda, or third-party tools. </p><h3>Control lifecycle</h3><p><strong>how a control is evaluated end-to-end: </strong>Security Hub CSPM works by continuously evaluating controls rather than running one-off scans. Each control represents a specific security expectation, such as whether logging is enabled or whether a setting is configured correctly. For resource-level controls, CSPM evaluates the <strong>latest configuration state</strong> recorded by <strong>AWS Config</strong>. When a resource changes, AWS Config records the change, and CSPM re-evaluates the relevant controls.</p><p>For account- and organisation-level controls, CSPM evaluates settings using AWS service APIs, such as <strong>AWS IAM</strong> or <strong>AWS Organizations</strong>. These controls are checked periodically or when AWS detects relevant changes. Each evaluation results in a control state such as PASSED, FAILED, or NO DATA, which is then surfaced in Security Hub.</p><blockquote><p><a href="https://docs.aws.amazon.com/config/latest/developerguide/managed-rules-by-trigger-type.html">Learn about AWS config trigger types</a> while some triggers run periodically you can also manually trigger a config rule to be re evaluated. </p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8HRT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef0c0fc1-b94e-4024-9f3a-9f49abb0b12b_1317x687.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8HRT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef0c0fc1-b94e-4024-9f3a-9f49abb0b12b_1317x687.png 424w, https://substackcdn.com/image/fetch/$s_!8HRT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef0c0fc1-b94e-4024-9f3a-9f49abb0b12b_1317x687.png 848w, https://substackcdn.com/image/fetch/$s_!8HRT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef0c0fc1-b94e-4024-9f3a-9f49abb0b12b_1317x687.png 1272w, https://substackcdn.com/image/fetch/$s_!8HRT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef0c0fc1-b94e-4024-9f3a-9f49abb0b12b_1317x687.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8HRT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef0c0fc1-b94e-4024-9f3a-9f49abb0b12b_1317x687.png" width="546" height="284.8154897494305" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ef0c0fc1-b94e-4024-9f3a-9f49abb0b12b_1317x687.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:687,&quot;width&quot;:1317,&quot;resizeWidth&quot;:546,&quot;bytes&quot;:127011,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://jakubfras.substack.com/i/182630597?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef0c0fc1-b94e-4024-9f3a-9f49abb0b12b_1317x687.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8HRT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef0c0fc1-b94e-4024-9f3a-9f49abb0b12b_1317x687.png 424w, https://substackcdn.com/image/fetch/$s_!8HRT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef0c0fc1-b94e-4024-9f3a-9f49abb0b12b_1317x687.png 848w, https://substackcdn.com/image/fetch/$s_!8HRT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef0c0fc1-b94e-4024-9f3a-9f49abb0b12b_1317x687.png 1272w, https://substackcdn.com/image/fetch/$s_!8HRT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef0c0fc1-b94e-4024-9f3a-9f49abb0b12b_1317x687.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>If you enable a standard in Security Hub CSPM but haven&#8217;t enabled AWS Config, Security Hub CSPM tries to create service-linked AWS Config rules <a href="https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-setup-prereqs.html#:~:text=If%20you%20enable,or%20the%20root.">according to the following schedule:</a></p><ul><li><p>On the day that you enable the standard.</p></li><li><p>The day after you enable the standard.</p></li><li><p>3 days after you enable the standard.</p></li><li><p>7 days after you enable the standard, and continuously every 7 days thereafter.</p></li></ul><p>If you use central configuration, Security Hub CSPM also tries to create service-linked AWS Config rules each time you associate a configuration policy that enables one or more standards with accounts, organisational units (OUs), or the root.</p><p>In AWS Config, you can choose between <em>continuous recording</em> and <em>daily recording</em> of changes in resource state. If you choose daily recording, AWS Config delivers resource configuration data at the end of each 24&#8211;hour period if there are changes in resource state. If there are no changes, no data is delivered. This can delay the generation of Security Hub CSPM findings for change-triggered controls until a 24&#8211;hour period is complete.</p><h3>Control states</h3><p>CSPM Security Hub control results are not just pass or fail. Each state tells you something important about your environment.</p><p><strong>PASSED</strong> means the required configuration or setting is present and correctly configured.</p><p><strong>FAILED</strong> means CSPM detected a misconfiguration or missing requirement.</p><p><strong>NO DATA</strong> usually means CSPM could not evaluate the control. This often happens when AWS Config is not recording a required resource type, global resources are disabled, or a dependency is missing.</p><p><strong>DISABLED</strong> means the control exists but has been intentionally turned off by an administrator.</p><p><strong>UNKNOWN</strong> typically indicates a temporary evaluation issue or an upstream service dependency problem.</p><p><strong>Warning:</strong> If a required resource was never recorded by AWS config, or recording was turned off before that resource existed, the control will show a <strong>WARNING</strong>. This warning doesn&#8217;t reflect the real configuration it&#8217;s just a default result because Security Hub has no data to evaluate.</p><h3>Data freshness and latency</h3><p>Security Hub CSPM is <strong>not real-time</strong>. There is always a delay between a configuration change and the corresponding CSPM result. For resource-based controls, the delay depends on how quickly AWS Config records the change and processes it. This can range from minutes to longer in large or busy environments.</p><p>For account-level controls evaluated via APIs, updates occur on a periodic basis rather than instantly. According to AWS Security Hub offers <strong><a href="https://aws.amazon.com/blogs/aws/aws-security-hub-now-generally-available-with-near-real-time-analytics-and-risk-prioritization/">Near real-time risk analytics </a>&#8220;Security Hub now calculates exposures in near real-time and includes threat correlation from GuardDuty alongside existing vulnerability and misconfiguration analysis.&#8220;</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uDX4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9312ed27-9875-42c6-bdb8-b5e72930e74e_1929x1162.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uDX4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9312ed27-9875-42c6-bdb8-b5e72930e74e_1929x1162.png 424w, https://substackcdn.com/image/fetch/$s_!uDX4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9312ed27-9875-42c6-bdb8-b5e72930e74e_1929x1162.png 848w, https://substackcdn.com/image/fetch/$s_!uDX4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9312ed27-9875-42c6-bdb8-b5e72930e74e_1929x1162.png 1272w, https://substackcdn.com/image/fetch/$s_!uDX4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9312ed27-9875-42c6-bdb8-b5e72930e74e_1929x1162.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uDX4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9312ed27-9875-42c6-bdb8-b5e72930e74e_1929x1162.png" width="585" height="352.36607142857144" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9312ed27-9875-42c6-bdb8-b5e72930e74e_1929x1162.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:877,&quot;width&quot;:1456,&quot;resizeWidth&quot;:585,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!uDX4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9312ed27-9875-42c6-bdb8-b5e72930e74e_1929x1162.png 424w, https://substackcdn.com/image/fetch/$s_!uDX4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9312ed27-9875-42c6-bdb8-b5e72930e74e_1929x1162.png 848w, https://substackcdn.com/image/fetch/$s_!uDX4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9312ed27-9875-42c6-bdb8-b5e72930e74e_1929x1162.png 1272w, https://substackcdn.com/image/fetch/$s_!uDX4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9312ed27-9875-42c6-bdb8-b5e72930e74e_1929x1162.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">The <strong>Exposure</strong> page surfaces critical findings helping you focus on most severe issues first.</figcaption></figure></div><p></p><h3>AWS Config </h3><p>AWS Config rules that Security Hub CSPM uses for controls are referred to as <em>service-linked rules</em>. For every control that uses a service-linked AWS Config rule, Security Hub CSPM creates instances of the required rule in your AWS environment. </p><p>These service-linked rules are specific to Security Hub CSPM. Security Hub CSPM creates these service-linked rules even if other instances of the same rules already exist. The service-linked rule adds <code>securityhub</code> before the original rule name and a unique identifier after the rule name. For example, for the AWS Config managed rule<code>vpc-flow-logs-enabled</code>, the service-linked rule name might be <code>securityhub-vpc-flow-logs-enabled-12345</code>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sF5v!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa041328c-e9e3-4775-91ed-4c6f8531d1e7_1288x707.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sF5v!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa041328c-e9e3-4775-91ed-4c6f8531d1e7_1288x707.png 424w, https://substackcdn.com/image/fetch/$s_!sF5v!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa041328c-e9e3-4775-91ed-4c6f8531d1e7_1288x707.png 848w, https://substackcdn.com/image/fetch/$s_!sF5v!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa041328c-e9e3-4775-91ed-4c6f8531d1e7_1288x707.png 1272w, https://substackcdn.com/image/fetch/$s_!sF5v!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa041328c-e9e3-4775-91ed-4c6f8531d1e7_1288x707.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sF5v!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa041328c-e9e3-4775-91ed-4c6f8531d1e7_1288x707.png" width="569" height="312.33152173913044" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a041328c-e9e3-4775-91ed-4c6f8531d1e7_1288x707.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:707,&quot;width&quot;:1288,&quot;resizeWidth&quot;:569,&quot;bytes&quot;:125126,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://jakubfras.substack.com/i/182630597?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa041328c-e9e3-4775-91ed-4c6f8531d1e7_1288x707.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sF5v!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa041328c-e9e3-4775-91ed-4c6f8531d1e7_1288x707.png 424w, https://substackcdn.com/image/fetch/$s_!sF5v!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa041328c-e9e3-4775-91ed-4c6f8531d1e7_1288x707.png 848w, https://substackcdn.com/image/fetch/$s_!sF5v!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa041328c-e9e3-4775-91ed-4c6f8531d1e7_1288x707.png 1272w, https://substackcdn.com/image/fetch/$s_!sF5v!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa041328c-e9e3-4775-91ed-4c6f8531d1e7_1288x707.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>To conserve costs, AWS recommend recording global resources in only one Region.<br>If you use central configuration or cross-Region aggregation, this should be your home Region. By default, AWS Config records all supported <em>Regional resources</em> that it discovers in the AWS Region in which it is running.</p><p>By default, AWS Config records supported resources only in the Region where it&#8217;s enabled. To get all Security Hub CSPM control findings, you also need to enable recording for global resources. AWS recommends turning on AWS Config recording <strong>before</strong> enabling any Security Hub CSPM standards and controls, so all resources are fully covered from the start.</p><h3>Automation</h3><p>Security Hub CSPM <strong>does support automated response</strong>, but it does not perform remediation by itself.</p><p>When a CSPM control changes state (for example, from PASSED to FAILED), the resulting finding is published as an event. These events are emitted through <strong>Amazon EventBridge</strong>, where customers can define rules to trigger automation.</p><p>That automation is entirely <strong>customer-controlled</strong>. For example, a CSPM finding can trigger:</p><ul><li><p>A <strong>AWS Lambda</strong> function to remediate a setting</p></li><li><p>A ticket in an ITSM tool</p></li><li><p>A notification or approval workflow</p></li><li><p>A SOAR or third-party response platform</p></li></ul><p>Security Hub CSPM itself does <strong>not decide</strong> when to remediate, <strong>how</strong> to remediate, or <strong>whether remediation is safe</strong>. It only evaluates posture and emits findings.</p><p><strong>Next see: AWS Security Hub Architecture</strong></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://jakubfras.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://jakubfras.substack.com/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://jakubfras.substack.com/p/part-one-the-value-of-a-cloud-native/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://jakubfras.substack.com/p/part-one-the-value-of-a-cloud-native/comments"><span>Leave a comment</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://jakubfras.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share Coffee &amp; Cloud &#9729;&#65039; &#9749;&#65039;&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://jakubfras.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share Coffee &amp; Cloud &#9729;&#65039; &#9749;&#65039;</span></a></p><p>Have blog ideas, want to engage on a topic, or explore collaboration? Let&#8217;s take it offline reach out on <strong><a href="https://www.linkedin.com/in/jakub-fras/">LinkedIn</a></strong>. I&#8217;d love to connect and continue the conversation!</p>]]></content:encoded></item><item><title><![CDATA[Introducing the new AWS CSPM Security Hub capability]]></title><description><![CDATA[Explore how the new AWS CSPM provides unified visibility surfaces critical security issues and helps you respond at scale to protect your environment.]]></description><link>https://jakubfras.substack.com/p/introducing-the-new-aws-cspm-security</link><guid isPermaLink="false">https://jakubfras.substack.com/p/introducing-the-new-aws-cspm-security</guid><dc:creator><![CDATA[Jakub Fras]]></dc:creator><pubDate>Wed, 31 Dec 2025 18:08:50 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!vpWc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F408bb3f4-5d5d-4ec2-a15b-f101d01df48a_1600x900.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vpWc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F408bb3f4-5d5d-4ec2-a15b-f101d01df48a_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vpWc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F408bb3f4-5d5d-4ec2-a15b-f101d01df48a_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!vpWc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F408bb3f4-5d5d-4ec2-a15b-f101d01df48a_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!vpWc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F408bb3f4-5d5d-4ec2-a15b-f101d01df48a_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!vpWc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F408bb3f4-5d5d-4ec2-a15b-f101d01df48a_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vpWc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F408bb3f4-5d5d-4ec2-a15b-f101d01df48a_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/408bb3f4-5d5d-4ec2-a15b-f101d01df48a_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:39705,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://jakubfras.substack.com/i/182176084?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F408bb3f4-5d5d-4ec2-a15b-f101d01df48a_1600x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vpWc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F408bb3f4-5d5d-4ec2-a15b-f101d01df48a_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!vpWc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F408bb3f4-5d5d-4ec2-a15b-f101d01df48a_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!vpWc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F408bb3f4-5d5d-4ec2-a15b-f101d01df48a_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!vpWc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F408bb3f4-5d5d-4ec2-a15b-f101d01df48a_1600x900.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On <strong>December 2, 2025</strong>, AWS announced the general availability of <strong>Security Hub CSPM</strong>, following its preview at <strong><a href="https://reinforce.awsevents.com/">AWS re:Inforce 2025</a></strong>. In this blog, I&#8217;ll break down what Security Hub CSPM actually is, how it differs from the original Security Hub experience, and what you should realistically expect if you enable it.</p><h2>An important note</h2><p><strong>Security Hub CSPM is not a replacement for Security Hub, it extends it.</strong></p><p><a href="https://docs.aws.amazon.com/securityhub/latest/userguide/what-is-securityhub-v2.html">Security Hub</a> remains the central place where security findings are aggregated, prioritised, and acted upon. Security Hub CSPM focuses on <strong>cloud security posture management</strong> &#8212; evaluating your AWS environment against security standards and best practices and identifying risky misconfigurations.</p><p>When both services are enabled:</p><ul><li><p>Security Hub CSPM generates posture and risk findings</p></li><li><p>Those findings are automatically sent into Security Hub</p></li><li><p>Security Hub correlates them with signals from other services (such as Amazon Inspector) to identify <strong>exposures</strong></p></li></ul><p>You <em>can</em> enable <a href="https://docs.aws.amazon.com/securityhub/latest/userguide/what-is-securityhub.html">Security Hub CSPM </a>on its own if your primary goal is identifying misconfigurations and measuring posture. However, if you enable Security Hub without CSPM, you miss the additional risk context and exposure analysis that CSPM provides.</p><p>For most environments, <strong><a href="https://docs.aws.amazon.com/securityhub/latest/userguide/what-are-securityhub-services.html#:~:text=As%20a%20best%20practice%2C%20we%20recommend%20enabling%20both%20services.">running both together provides the most value and is reccomended by AWS</a></strong><a href="https://docs.aws.amazon.com/securityhub/latest/userguide/what-are-securityhub-services.html#:~:text=As%20a%20best%20practice%2C%20we%20recommend%20enabling%20both%20services.">.</a></p><h3>What was Security Hub before CSPM?</h3><p>To understand what changed with the addition of the new CSPM capability to AWS security hub, it helps to look at what Security Hub traditionally did. Security Hub collected security findings from AWS services such as:</p><ul><li><p>Amazon GuardDuty</p></li><li><p>Amazon Inspector</p></li><li><p>IAM Access Analyzer</p></li><li><p>Supported partner security tools</p></li></ul><p>It brought those findings into a single view across accounts and regions, making it easier to see what was wrong and where. For security standards like <strong>CIS AWS Foundations</strong>, Security Hub relied on <strong>AWS Config</strong> to evaluate resource configurations against predefined rules and determine whether controls were met.</p><p>At its core, the original Security Hub focused on:</p><ul><li><p>Compliance visibility</p></li><li><p>Configuration checks against standards</p></li><li><p>Centralised aggregation of security alerts</p></li></ul><p>While useful, this approach had some clear limitations.</p><h3>The problems teams ran into</h3><h4>Alert fatigue</h4><p>In the traditional Security Hub experience, teams often saw hundreds or thousands of high-severity alerts from services like Amazon GuardDuty.</p><p>Many of these alerts were technically correct but not actually risky for example, findings on resources that were <strong>not publicly reachable</strong> or could not realistically be exploited.</p><p>Security Hub CSPM reduces this noise by focusing on <strong>real risk</strong>, highlighting situations where multiple risky conditions exist together, such as:</p><ul><li><p>A vulnerable resource</p></li><li><p>That is publicly exposed</p></li><li><p>And has overly permissive access</p></li></ul><h4>Lack of context</h4><p>Previously, you might see a failed configuration check for an S3 bucket or EC2 instance, but have no idea:</p><ul><li><p>Whether it was reachable from the internet</p></li><li><p>Whether it could realistically be abused</p></li></ul><p>CSPM adds context by showing <strong>how and why</strong> a misconfiguration matters not just that it exists.</p><h4>Slow and manual investigation</h4><p>Before CSPM, security teams often had to manually piece things together, such as:</p><ul><li><p>Which security group belongs to which EC2 instance</p></li><li><p>How traffic flows through VPCs, gateways, and peering connections</p></li></ul><p>This was time-consuming and error-prone.</p><p>Security Hub CSPM introduces <strong>attack path visualisations</strong> that clearly show where exposure comes from, such as:</p><ul><li><p>An internet gateway</p></li><li><p>A VPC peering connection</p></li><li><p>An overly permissive security group</p></li></ul><p>Instead of guessing, teams can see the actual path an attacker could take.</p><h3>What capabilities does Security Hub CSPM add?</h3><p>Security Hub CSPM builds on existing security data and adds a <strong>risk-analysis layer</strong> that helps prioritise what matters most.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!42PY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67d7d149-e380-4f5e-84df-7b47b1e73e18_1560x818.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!42PY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67d7d149-e380-4f5e-84df-7b47b1e73e18_1560x818.png 424w, https://substackcdn.com/image/fetch/$s_!42PY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67d7d149-e380-4f5e-84df-7b47b1e73e18_1560x818.png 848w, https://substackcdn.com/image/fetch/$s_!42PY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67d7d149-e380-4f5e-84df-7b47b1e73e18_1560x818.png 1272w, https://substackcdn.com/image/fetch/$s_!42PY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67d7d149-e380-4f5e-84df-7b47b1e73e18_1560x818.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!42PY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67d7d149-e380-4f5e-84df-7b47b1e73e18_1560x818.png" width="480" height="251.53846153846155" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/67d7d149-e380-4f5e-84df-7b47b1e73e18_1560x818.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:763,&quot;width&quot;:1456,&quot;resizeWidth&quot;:480,&quot;bytes&quot;:356998,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://jakubfras.substack.com/i/182176084?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67d7d149-e380-4f5e-84df-7b47b1e73e18_1560x818.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!42PY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67d7d149-e380-4f5e-84df-7b47b1e73e18_1560x818.png 424w, https://substackcdn.com/image/fetch/$s_!42PY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67d7d149-e380-4f5e-84df-7b47b1e73e18_1560x818.png 848w, https://substackcdn.com/image/fetch/$s_!42PY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67d7d149-e380-4f5e-84df-7b47b1e73e18_1560x818.png 1272w, https://substackcdn.com/image/fetch/$s_!42PY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67d7d149-e380-4f5e-84df-7b47b1e73e18_1560x818.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4>Attack Path Analysis</h4><p>CSPM creates a visual graph showing how an attacker could realistically move through your environment. For example, it might show that an EC2 instance:</p><ul><li><p>Has a critical vulnerability (from Amazon Inspector)</p></li><li><p>Is publicly reachable (from CSPM analysis)</p></li><li><p>Uses an overly privileged IAM role</p></li></ul><p>Together, these signals form a clear, actionable risk.</p><h4>Near real-time risk analytics</h4><p>Instead of relying on periodic scans, CSPM continuously updates a <strong>security score</strong> based on live signals across your environment. It uses the <strong>Open Cybersecurity Schema Framework (OCSF)</strong> to process and correlate data more consistently and quickly than the older ASFF-only approach.</p><h4>Automated finding correlation</h4><p>Rather than flooding teams with dozens of related alerts, CSPM groups related findings into a single <strong>Exposure</strong>. For example, if one database generates 50 individual findings, CSPM can roll those up into one high-priority issue &#8212; making it far easier to understand and act on.</p><h3>Security hub CSPM third party integrations</h3><p>AWS Security Hub CSPM can ingest security findings from several AWS services and supported third-party AWS Partner Network security solutions.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MDhg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F919fb50e-35d7-4c9d-9f25-5b42d10a57d4_1568x696.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MDhg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F919fb50e-35d7-4c9d-9f25-5b42d10a57d4_1568x696.png 424w, https://substackcdn.com/image/fetch/$s_!MDhg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F919fb50e-35d7-4c9d-9f25-5b42d10a57d4_1568x696.png 848w, https://substackcdn.com/image/fetch/$s_!MDhg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F919fb50e-35d7-4c9d-9f25-5b42d10a57d4_1568x696.png 1272w, https://substackcdn.com/image/fetch/$s_!MDhg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F919fb50e-35d7-4c9d-9f25-5b42d10a57d4_1568x696.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MDhg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F919fb50e-35d7-4c9d-9f25-5b42d10a57d4_1568x696.png" width="639" height="283.5123626373626" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/919fb50e-35d7-4c9d-9f25-5b42d10a57d4_1568x696.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:646,&quot;width&quot;:1456,&quot;resizeWidth&quot;:639,&quot;bytes&quot;:286752,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://jakubfras.substack.com/i/182176084?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F919fb50e-35d7-4c9d-9f25-5b42d10a57d4_1568x696.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!MDhg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F919fb50e-35d7-4c9d-9f25-5b42d10a57d4_1568x696.png 424w, https://substackcdn.com/image/fetch/$s_!MDhg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F919fb50e-35d7-4c9d-9f25-5b42d10a57d4_1568x696.png 848w, https://substackcdn.com/image/fetch/$s_!MDhg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F919fb50e-35d7-4c9d-9f25-5b42d10a57d4_1568x696.png 1272w, https://substackcdn.com/image/fetch/$s_!MDhg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F919fb50e-35d7-4c9d-9f25-5b42d10a57d4_1568x696.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Third party integrations example</figcaption></figure></div><h3>Pricing</h3><p>When you enable Security Hub CSPM for the first time, the account is automatically enrolled in a <strong>30-day free trial</strong>. Security Hub CSPM pricing is based on <strong>resources monitored per month</strong>, with costs pro-rated by usage time.</p><p><strong>Example (simplified):</strong></p><ul><li><p>500 EC2 instances</p></li><li><p>500 resource units &#215; $3.75 per unit</p></li><li><p>Estimated monthly cost: <strong>$1,875</strong></p></li></ul><p>This is a simplified example. Actual costs vary by:</p><ul><li><p>Resource type</p></li><li><p>Region</p></li><li><p>Monitoring duration</p></li><li><p>Discount tiers and ingestion usage</p></li></ul><p>During the free trial, you are still charged for usage of other AWS services CSPM relies on (such as AWS Config items). However, <strong>AWS Config rules enabled solely by CSPM security standards are not charged separately</strong>.</p><blockquote><p>Note: The usage information and estimated cost <strong>are only for the current account and current Region that you are in</strong>. In the case that you are using aggregation into a single hime region, the usage information and estimated cost <a href="https://docs.aws.amazon.com/securityhub/latest/userguide/finding-aggregation.html#finding-aggregation-overview">don't include linked regions.</a> Today you can <strong><a href="https://calculator.aws/#/createCalculator/securityHub">create a cost estimate</a>.</strong></p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!X1fY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cd32c2a-ca96-4d58-b899-3547c677ef30_1064x449.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!X1fY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cd32c2a-ca96-4d58-b899-3547c677ef30_1064x449.png 424w, https://substackcdn.com/image/fetch/$s_!X1fY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cd32c2a-ca96-4d58-b899-3547c677ef30_1064x449.png 848w, https://substackcdn.com/image/fetch/$s_!X1fY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cd32c2a-ca96-4d58-b899-3547c677ef30_1064x449.png 1272w, https://substackcdn.com/image/fetch/$s_!X1fY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cd32c2a-ca96-4d58-b899-3547c677ef30_1064x449.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!X1fY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cd32c2a-ca96-4d58-b899-3547c677ef30_1064x449.png" width="550" height="232.09586466165413" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3cd32c2a-ca96-4d58-b899-3547c677ef30_1064x449.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:449,&quot;width&quot;:1064,&quot;resizeWidth&quot;:550,&quot;bytes&quot;:72461,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://jakubfras.substack.com/i/182176084?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cd32c2a-ca96-4d58-b899-3547c677ef30_1064x449.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!X1fY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cd32c2a-ca96-4d58-b899-3547c677ef30_1064x449.png 424w, https://substackcdn.com/image/fetch/$s_!X1fY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cd32c2a-ca96-4d58-b899-3547c677ef30_1064x449.png 848w, https://substackcdn.com/image/fetch/$s_!X1fY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cd32c2a-ca96-4d58-b899-3547c677ef30_1064x449.png 1272w, https://substackcdn.com/image/fetch/$s_!X1fY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cd32c2a-ca96-4d58-b899-3547c677ef30_1064x449.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">usage tab example</figcaption></figure></div><h3>Security Hub CSPM Feature Breakdown</h3><p>I&#8217;ll be breaking down set up and features in upcoming blogs, stay tuned! </p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://jakubfras.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://jakubfras.substack.com/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://jakubfras.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share Coffee &amp; Cloud &#9729;&#65039; &#9749;&#65039;&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://jakubfras.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share Coffee &amp; Cloud &#9729;&#65039; &#9749;&#65039;</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://jakubfras.substack.com/p/part-three-integrating-devsecops/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://jakubfras.substack.com/p/part-three-integrating-devsecops/comments"><span>Leave a comment</span></a></p><p>Have blog ideas, want to engage on a topic, or explore collaboration? Let&#8217;s take it offline reach out on <strong><a href="https://www.linkedin.com/in/jakub-fras/">LinkedIn</a></strong>. I&#8217;d love to connect and continue the conversation!</p>]]></content:encoded></item></channel></rss>