Cloud Defense Logo

Products

Solutions

Company

Book A Live Demo

Enable GuardDuty Rule for Access Control

This rule ensures GuardDuty is enabled to enhance security measures.

RuleGuardDuty should be enabled
FrameworkFedRAMP Low Revision 4
Severity
High

Rule Description

The rule specifies that GuardDuty should be enabled for Federal Risk and Authorization Management Program (FedRAMP) Low, as per Revision 4.

Troubleshooting Steps

  1. 1.
    Check if GuardDuty is already enabled for your AWS account.
  2. 2.
    Verify if the AWS account is classified as FedRAMP Low.
  3. 3.
    Ensure that the GuardDuty service is available in the desired region.

Necessary Codes

No necessary codes are mentioned for this rule.

Step-by-Step Guide for Remediation

  1. 1.
    Login to the AWS Management Console using your account with administrative privileges.
  2. 2.
    Open the Amazon GuardDuty console.

Checking if GuardDuty is already enabled

  1. 1.
    In the GuardDuty console, verify if GuardDuty is already enabled for your AWS account.
  2. 2.
    If GuardDuty is already enabled, proceed to the next step. If not, follow the steps below to enable it:

Enabling GuardDuty

  1. 1.
    In the GuardDuty console, click on the "Enable GuardDuty" button.
  2. 2.
    Choose the region where you want to enable GuardDuty.
  3. 3.
    Click on the "Enable" button to start the enabling process.

Verifying FedRAMP Low classification

  1. 1.
    Ensure that your AWS account is classified as FedRAMP Low. If not, follow the necessary steps to meet the requirements of FedRAMP Low classification.

Checking GuardDuty availability in the desired region

  1. 1.

    Verify if GuardDuty is available in the desired region. If not, choose a region where GuardDuty is available and proceed with the steps in that region.

  2. 2.

    Once GuardDuty is enabled in the desired region and your account is classified as FedRAMP Low, the rule will be compliant.

Additional Notes

  • GuardDuty is a continuous security monitoring service offered by AWS to detect suspicious activity and unauthorized behavior in AWS accounts and workloads.
  • It is important to regularly monitor the compliance status of GuardDuty and ensure that it is enabled for the appropriate security levels, such as FedRAMP Low in this case.
  • Regularly review the GuardDuty findings and take necessary actions to address any detected issues or security threats.

Is your System Free of Underlying Vulnerabilities?
Find Out Now