- Home›
- Amazon Config
Amazon Config
Overview
Amazon Config is a service that enables you to assess, audit, and evaluate the configurations of your Amazon Web Services resources. Config continuously monitors and records your Amazon Web Services resource configurations and allows you to automate the evaluation of recorded configurations against desired configurations. With Config, you can review changes in configurations and relationships between Amazon Web Services resources, dive into detailed resource configuration histories, and determine your overall compliance against the configurations specified in your internal guidelines. This enables you to simplify compliance auditing, security analysis, change management, and operational troubleshooting.
Benefits
Continuous monitoring
Continuous assessment
Operational troubleshooting
Change management
Use cases
Discovery
Amazon Config will discover resources that exist in your account, record their current configuration and capture any changes to these configurations. Config will also retain configuration details for resources that have been deleted. A comprehensive snapshot of all resources and their configuration attributes provides a complete inventory of resources in your account.
Change management
When your resources are created, updated, or deleted, Amazon Config streams these configuration changes to Amazon Simple Notification Service (SNS), so that you are notified of all the configuration changes. Amazon Config represents relationships between resources so that you can assess how a change to one resource may impact other resources.
Continuous audit and compliance
Amazon Config is designed to help you assess compliance with your internal policies and regulatory standards by providing you visibility into the configuration of your Amazon Web Services resources, and evaluating resource configuration changes against your desired configurations.
Compliance as code
Amazon Config allows you to codify your compliance with custom rules in Amazon Lambda that define your internal best practices and guidelines for resource configurations. Using Config, you can automate assessment of your resource configurations and resource changes to ensure continuous compliance and self-governance across your Amazon Web Services infrastructure.
Troubleshooting
Using Amazon Config, you can quickly troubleshoot operational issues by identifying the recent configuration changes to your resources.
Security analysis
Data from Amazon Config enables you to continuously monitor the configurations of your resources and evaluate these configurations for potential security weaknesses. Changes to your resource configurations can trigger Amazon Simple Notification Service (SNS) notifications, which can be sent to your security team to review and take action. After a potential security event, Config enables you to review the configuration history of your resources and examine your security posture.