AWS Config, Security Hub and Audit Manager
AWS Config records what your resources look like over time. Security Hub scores them against standards and collects findings. Audit Manager maps evidence to frameworks. For a first audit, the first two do most of the work.
Turn on AWS Config and Security Hub in every account and region you use, aggregated to a delegated security account. They give you configuration history and a scored, deduplicated list of findings, which covers most of the AWS evidence a SOC 2 or ISO 27001 auditor asks for. Audit Manager is optional: useful if you want AWS evidence mapped to a framework without a separate tool, and redundant if you already use a compliance platform.
| Service | What it does | Evidence it produces | Needed for a first audit? |
|---|---|---|---|
| AWS Config | Records resource configuration and changes; evaluates rules and conformance packs | Configuration timeline, rule compliance history | Yes |
| Security Hub | Runs security standards checks, aggregates findings from GuardDuty, Inspector, Macie and others | Standard scores, findings with workflow status | Yes |
| Audit Manager | Collects evidence from Config, Security Hub and CloudTrail and maps it to frameworks | Assessment reports organized by control | Optional |
AWS Config
Config is the foundation. Once the recorder is on, every change to a recorded resource is kept with a timestamp, which answers the auditor's question "was this true across the whole period?" Managed rules check common settings such as encryption, public access and logging. Conformance packs bundle rules; AWS publishes packs aligned with frameworks including NIST SP 800-53 and CIS, which are useful starting points.
- Record all resource types, or at least all types in your production accounts.
- Use an aggregator in the security account for an organization-wide view.
- Watch cost: Config charges per configuration item recorded, which grows with churn in large container or autoscaling estates. Periodic recording for noisy resource types reduces it.
Security Hub
Security Hub turns Config and other services into a findings list with a score per standard. The AWS Foundational Security Best Practices standard is the most useful for SOC 2; the CIS AWS Foundations Benchmark is common for customers that name CIS.
Its value as evidence depends on workflow. An auditor sampling CC7 will look at findings from the period and ask what happened to them. Use the workflow status (new, notified, suppressed, resolved), suppress controls that genuinely do not apply with a reason, and route high severity findings to tickets.
Audit Manager
Audit Manager has prebuilt frameworks, including one for SOC 2, that pull evidence automatically from AWS sources and let you add manual evidence. It produces an assessment report you can share. Two limits: it only sees AWS, so controls about your identity provider, code repository or people need manual uploads, and auditors still decide what they accept. It suits AWS-heavy companies without a compliance platform.
Other AWS services an auditor will ask about
- CloudTrail
- The audit log. See audit logging.
- GuardDuty
- Threat detection across accounts. Evidence for CC7.2.
- Inspector
- Vulnerability scanning for EC2, ECR and Lambda. See vulnerability management.
- IAM Access Analyzer
- Finds resources shared outside your organization and unused access. Useful for access reviews.
- Macie
- Finds sensitive data in S3. Useful for data classification evidence, optional for most audits.
Is AWS Audit Manager free?
No. Audit Manager charges per resource assessment, and Config and Security Hub have their own usage charges. For a small estate the combined cost is modest; check current AWS pricing against your resource count before enabling everything organization-wide.
Does Security Hub have a SOC 2 standard?
Security Hub's standards are technical benchmarks such as AWS Foundational Security Best Practices and CIS, not SOC 2 itself. Audit Manager has a SOC 2 framework that uses Security Hub and Config results as evidence.
Do we need AWS Config if we use a compliance platform?
Usually yes. Platforms read your current configuration through the API, but Config keeps history, which is what proves a control held across the audit period. Many platforms read Config and Security Hub data themselves.
Want the AWS tooling set up properly?
Firms in the network configure Config, Security Hub and the triage routine.
Get matched