Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Solution fails [StepFunctions.1] Security Hub control #185

Open
steve-g-nz opened this issue Feb 8, 2024 · 3 comments
Open

Solution fails [StepFunctions.1] Security Hub control #185

steve-g-nz opened this issue Feb 8, 2024 · 3 comments
Labels
enhancement New feature or request

Comments

@steve-g-nz
Copy link

The template as currently provided fails the StepFunction.1 Security Hub control

Please update the custom-control-tower-initiation.template to include the following:

  • a CloudWatch log group resource
  • execution role updated to include relevant logs IAM policies
  • LoggingConfiguration property added to the two StepFunction StateMachine resources

Additional context
StepFunctions.1

@steve-g-nz steve-g-nz added the enhancement New feature or request label Feb 8, 2024
@snebhu3
Copy link

snebhu3 commented Feb 8, 2024

@steve-g-nz thank you for reaching out.
Please may you provide more context on:

  • What you are trying to do and what is the issue you are facing.
  • Steps to reproduce the issue you are facing

@steve-g-nz
Copy link
Author

@snebhu3 the template as documented deploys step functions that fail the Security Hub control StepFunctions.1 which is part of the AWS Foundational Security Best Practices v1.0.0 standard
To prevent the control from failing the template would need to include logging for the state machines which would require the addition of a Cloudwatch log group and adding the relevant IAM permissions to the execution role

@snebhu3
Copy link

snebhu3 commented Feb 8, 2024

Thank you for the additional context.
I have created an internal backlog to address this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants