AWS Security Hub CSPM
AWS Security Hub CSPM (Cloud Security Posture Management) is the aggregation point for security findings across an AWS estate. It collects findings from other AWS services and from supported third-party products, normalises them into the AWS Security Finding Format (ASFF), and runs its own configuration checks against security standards.
Sources it receives findings from include:
- Amazon GuardDuty
- Amazon Inspector
- Amazon Macie
- AWS Firewall Manager
- AWS IAM Access Analyzer, and other integrated AWS services
- Partner products, via the integrations catalogue
What it does
Section titled “What it does”- Standards checks. Security Hub CSPM runs continuous, account-level checks against the AWS Foundational Security Best Practices standard and external frameworks including CIS, PCI DSS and NIST. Each standard is a set of controls, and the results roll up into a security score per account and per standard.
- One finding format. ASFF means one schema for every source, so filters, insights and automation rules work the same way regardless of which service raised the finding.
- Multi-account aggregation. An administrator account sees findings from every member account, and cross-Region aggregation brings several Regions into one view.
- Automation. Automation rules can update or suppress findings against criteria you define, and the EventBridge integration triggers custom responses — a ticket, a Lambda remediation, a notification.
Prerequisites and limits
Section titled “Prerequisites and limits”Most Security Hub CSPM controls are implemented as service-linked AWS Config rules, so AWS Config must be enabled and recording resources for those controls to produce findings. Security Hub CSPM only processes findings generated after it was enabled — it does not backfill — and it only receives findings in the Region where it is enabled. For full coverage of the CIS AWS Foundations Benchmark checks, it has to be enabled in every supported Region.
A note on the name
Section titled “A note on the name”AWS renamed this service AWS Security Hub CSPM. The unqualified name AWS Security Hub now refers to a broader, tiered offering that correlates and enriches signals into prioritised risk analytics. The console labels, documentation and any older material that simply says “Security Hub” may mean either, so check which one is intended before acting on it.