This rule dictates that GuardDuty must be enabled for security purposes.
Rule | GuardDuty should be enabled |
Framework | NIST Cybersecurity Framework (CSF) v1.1 |
Severity | ✔ High |
Rule Description
The GuardDuty service should be enabled in order to meet the requirements of NIST Cybersecurity Framework (CSF) v1. GuardDuty is a managed threat detection service provided by AWS that continuously monitors the AWS environment for any suspicious activities or malicious behavior. By enabling GuardDuty, you enhance your security posture and gain insights into potential security risks and threats within your environment.
Troubleshooting Steps
If you encounter any issues while enabling GuardDuty for NIST CSF v1, follow these troubleshooting steps:
Step 1: Ensure GuardDuty is supported in your AWS region:
Step 2: Verify necessary IAM permissions:
Step 3: Check GuardDuty service quotas:
Step 4: Verify GuardDuty settings:
Necessary Code
There is no specific code required for enabling GuardDuty as it is a managed service provided by AWS. However, you can configure it using the AWS Management Console, AWS CLI (Command Line Interface), or AWS SDKs (Software Development Kits) based on your preference and requirements.
Step-by-Step Guide for Enabling GuardDuty for NIST CSF v1
Follow the steps below to enable GuardDuty for NIST CSF v1:
Step 1: Access the AWS Management Console:
Step 2: Navigate to the GuardDuty service:
Step 3: Create a new detector:
Step 4: Configure GuardDuty settings:
Step 5: Enable email or SNS notifications (optional):
Step 6: Review and monitor GuardDuty findings:
By following these steps, you can successfully enable GuardDuty for NIST Cybersecurity Framework (CSF) v1 and enhance the security of your AWS environment.