GovCloud Config rule fixes for FedRAMP Low Conformance Pack #440
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Issue #421 Conformance Pack for FedRamp not deployable in GovCloud
Description of changes:
The FedRAMP Low conformance pack does not function in AWS Gov Cloud. Specifically the rules listed below are not in GovCloud or several other regions. I performed a full analysis of the non-GovCloud Config Rules and provided suggestions for how to update the rules. The full content of my analysis is available in this public spreadsheet: https://docs.google.com/spreadsheets/d/1eKZpe2EPA-8RQkG6bWViwLRrdDeS4yUpvtvUpu_4WEg/edit?usp=sharing
For an example see the documentation below on root-account-mfa-enabled https://docs.aws.amazon.com/config/latest/developerguide/root-account-mfa-enabled.html
These changes have been made in this pull request and I confirmed that this version of the conformance pack successfully deploys in AWS GovCloud.
I confirm these files are made available under CC0 1.0 Universal (https://creativecommons.org/publicdomain/zero/1.0/legalcode)