CloudHealth Secure State 2021 Rules | 18 NOV 2021 Check for additions and updates to these release notes. |
AWS – Updated Rules
The following rule received query and trigger updates to improve results:
Azure Container Instance
AWS – New Rules
AWS – Updated Rule
The following rule received query and trigger updates to improve results:
GCP – New Rule
GCP – Updated Rules
The following rules received query and trigger updates to improve results, and a change in display name:
Updated Compliance Frameworks
The following frameworks received updated mappings for Azure, AWS, and GCP rules:
AWS – Updated Rules
The following IAM rules received query updates that take into account the limitations set by permissions boundaries to ensure more accurate reporting.
Updated Compliance Frameworks
The following frameworks received updated mappings for Azure, AWS, and GCP rules.
AWS – New Rules
AWS – Updated Rules
The following rules received query and trigger updates to improve accuracy of findings:
Updated Compliance Frameworks
The following frameworks received updated mappings for Azure, AWS and GCP rules:
AWS - New Rules
AWS - Updated Rules
The following rules received query and knowledge base article updates to improve finding results and clarify information, respectively.
Amazon Kinesis Firehose
AWS - Updated Rules
The following rules received query updates to improve accuracy:
Azure - Updated Rules
The following rules received query updates to improve accuracy:
New Compliance Frameworks
The following frameworks were added for the first time for AWS, Azure, and GCP control mappings.
Updated Compliance Frameworks
The following frameworks received new controls:
The following frameworks had their mappings corrected and updated for Azure CIS rules:
AWS – New Rules
The following new rules were added in alignment with AWS Security Hub controls:
Services and Rules:
Expanded support of Amazon ECS
Compliance Updates
AWS – New Rules
New rules were added for AWS Cloudfront and IAM services:
Updated Compliance Frameworks
The following frameworks received new controls:
Azure – New Rules
The following rules were added for Azure AKS:
AWS – New Rule
A new rule for monitoring unused access was added to the AWS IAM service:
GCP – New Rules
New rules inspired by GCP connected threats were added to the GCP Compute service:
AWS – Updated Rules
The following rules received query updates to improve the accuracy of results:
Updated Compliance Frameworks
The following frameworks received new controls:
AWS – New Rule
A new rule was added for the S3 service:
AWS – Updated Rules
The following IAM service rule was updated from a 90 day inactivity period to 45 days:
GCP – Updated Rules
The following rules received query updates to reduce noise, adjusted severities, and minor style updates to titles:
New Compliance Framework
The following framework was created for the first time:
Updated Compliance Framework
The following framework received an additional rules mapping:
AWS API Gateway
The API Gateway service was recently onboarded to Secure State, including the following rules:
GCP – Updated Rules
Rules for the following services received updates to their display titles and knowledge base articles to conform to a new, consistent naming standard.
AWS - New Rules
The AWS Config service was recently onboarded to Secure State, including the following rule:
GCP - New Rules
GCP - Updated Rules
Rules for the following services received updates to their display titles and knowledge base articles to conform to a new, consistent naming standard.
GCP – Updated Rules
The following rules received query updates to improve accuracy of results.
Rules for the following services received updates to their display titles and knowledge base articles to conform to a new, consistent naming standard.
GCP – New Rules
Azure – Updated Rules
AWS – New Rule
Azure – New Rules
AWS – Updated Rules
The following rules received query updates to improve the filtering of results.
GCP – Updated Rules
Rules for the following services received updates to their display titles and knowledge base articles to conform to a new, consistent naming standard.
AWS – Updated Rules
The following rule received an update to optimize its query logic for better efficiency and reduced compute load.
Azure – Updated Rules
The following rule received an update to optimize its query logic for better efficiency and reduced compute load.
Updated Compliance Frameworks
The following framework received updates:
GCP – Updated Rules
Rules for the following services received updates to their display titles and knowledge base articles to conform to a new, consistent naming standard:
AWS Athena
AWS – Updated Rules
The following rule has been deprecated and replaced, as it is not practical to rotate inactive IAM keys:
A new rule has been added that requires inactive keys be deleted:
Customers may see both rules displayed at first. The deprecated rule should be removed from all client interfaces by Friday.
GCP – Updated Rules
Rules for the following services received updates to their display titles and knowledge base articles to conform to a new, consistent naming standard:
Updated Compliance Frameworks
The following frameworks received new controls:
AWS – Updated Rules
The following AWS rules received updates to CIS AWS Foundations Benchmark controls:
Updated Compliance Frameworks
The following framework received new controls:
AWS SageMaker
Azure – New Rules
New Compliance Framework
The following framework was created for the first time:
Updated Compliance Framework
The following framework received new controls:
AWS – Updated Rules
The following rule received a query update to verify key rotation is enabled on customer-managed CMKs:
The following rule received a query update to verify CloudTrail is enabled before checking for CloudWatch integration:
The following rules received query updates to handle external account SNS topics configured with CloudWatch metric alarms:
Updated Compliance Frameworks
The following framework received new rules mappings:
Azure – New Rules
AWS – Updated Rules
The following rules received updates to their queries to resolve an issue where HTTP listeners with HTTPS redirects were triggering violations.
Azure – Updated Rules
Rules for the following services received updates to their display titles and knowledge base articles to conform to a new, consistent naming standard.
AWS Elastic Beanstalk
Azure - Updated Rules
Rules for the following services received updates to their display titles and knowledge base articles to conform to a new, consistent naming standard.
Updated Compliance Frameworks
The following framework was mapped to GCP for the first time:
Azure - Updated Rules
Rules for the following Azure services received new remediation steps in their knowledge base articles:
Rules for the following Azure services received updates to their display titles and knowledge base articles to conform to a new, consistent naming standard.
Updated Compliance Frameworks
The following framework received new rules mappings:
AWS – New Rules
Azure – New Rules
GCP – New Rules
AWS – Updated Rules
Updated the query for following rule to check for active access keys for the root user:
Updated the display name for the following rule:
Updated knowledge base articles for rules that have automatic remediation with links to more information about configuring remediation service. The following services contain one or more rules that can be automatically remediated:
Azure – Updated Rules
Rules for the following services received updates to their display titles and knowledge base articles to conform to a new, consistent naming standard.
Updated knowledge base articles for rules that have automatic remediation with links to more information about configuring remediation service. The following services contain one or more rules that can be automatically remediated:
GCP – Updated Rules
Rules for the following services received updates to their display titles to conform to a new, consistent naming standard.
Updated Compliance Frameworks
The following framework received additional rules mappings:
Azure – Machine Learning
AWS – New Rules
Azure – New Rules
GCP – New Rules
AWS – New Rules
Azure – Updated Rules
Rules for the following services received updates to their display titles and knowledge base articles to conform to a new, consistent naming standard.
GCP – Updated Rules
Display titles for GCP Cloud Armor rules were updated to state the service name.
Updated Compliance Frameworks
The following framework was mapped to GCP for the first time:
AWS – New Rules
AWS – Updated Rules
Added new SSL policies.
Azure – Updated Rules
Updated rule names and KB articles.
Updated Compliance Frameworks
The following framework received additional rules mappings:
Azure HD Insight
Azure – Updated Rules
Updated rule names and KB articles.
Updated Compliance Frameworks
The following framework received additional rules mappings:
AWS – New Rules
Azure – Updated Rules
Updated rule names and KB articles.
AWS - New Rules
GCP - New Rules
Azure - Updated rules
Updated rule names and KB articles.
AWS – New Rules
Azure – New Rules
AWS – Updated Rules
Updated rule triggers.
Updated rule names.
Updated KB articles.
New Compliance Frameworks
Updated Compliance Frameworks
Additional rules mappings.
GCP – New Rules
Added new GCP cloud armor rules.
AWS – Updated Rules
All ELB and ELBv2 rules received updates to their display titles and knowledge base articles to conform to a new, consistent naming standard.
New Compliance Frameworks
Updated Compliance Frameworks
Added new rules mappings.
AWS – New Rules
Added new AWS rules for privilege escalation vectors.
GCP – New Rules
Added new GCP port rules for compute instance and firewall.
AWS – Updated Rules
All ACM and CloudFormation rules received updates to their display titles and knowledge base articles to conform to a new, consistent naming standard.
Updated Compliance Frameworks
Added new rules mappings.
Deprecated Compliance Frameworks
The following framework will be deprecated on 3/25. If you would like to continue using the framework, you can clone it using the "Clone a framework" instructions in the Compliance Management User Guide.
AWS – New Rules
Added new EKS rule with CIS compliance support.
Azure – New Rules
Added new virtual machine and network security group rules for port public access.
AWS – Updated Rules
Updated CIS EKS compliance-related rules for AWS.
Updated additional rules for style consistency.
Azure – Updated Rules
Updated Azure rules for network security group public access.
New Compliance Frameworks
Updated Compliance Frameworks
Google Load Balancer
Azure – New Rules
GCP – Updated Rules
Updated to have separate policies for organization, folder, project and resource:
Updated Compliance Frameworks
Google Cloud Run
Google Container Registry
GCP – New Rules
AWS – Updated Rules
GCP – Updated Rules
Updated to check instance status. Applicable only for instances in running state:
Updated to check for any active root access:
New Compliance Framework
AWS – Deprecated Rules
This rule is no longer applicable due to recent updates in the Azure platform and Azure CIS benchmark:
GCP – New Rules
AWS – Updated Rules
Updated to check for PublicBlockAccess, RestrictPublicBuckets, and IgnorePublicAcls flags during evaluation:
Updated to resolve a scenario where user access keys are created but never used:
Updated to check for application ELBv2 exclusively during evaluation:
New Compliance Framework
AWS – New Rules
GCP – New Rules
New Compliance Frameworks
GCP – New Rules
AWS – New Rules
AWS – Updated Rules
Azure – New Rules
Azure – Updated Rules