Skip to content

Security Hub Controls

Security Hub Controls Configuration

AWS Security Hub controls are customizable rules that define what constitutes a secure configuration for your AWS environment. These controls help enforce compliance with security policies, regulatory standards (e.g., GDPR, HIPAA), and organizational best practices. By configuring controls, you can automate security assessments, identify deviations from desired states, and trigger remediation workflows. This section explains how to define, deploy, and customize controls for compliance scenarios.


Understanding Security Hub Controls

Security Hub controls are categorized into standard controls (predefined by AWS or third-party standards) and custom controls (user-defined). Standard controls align with frameworks like CIS, ISO 27001, and NIST, while custom controls allow tailoring to specific regulatory or organizational requirements.

Key components of a control:
- Title: A unique identifier for the control.
- Description: Contextual details about the control’s purpose.
- Severity: A value of LOW, MEDIUM, or HIGH to prioritize findings.
- Remediation: Optional guidance for addressing non-compliance.
- Input Parameters: Customizable criteria for evaluating compliance (e.g., IAM policy restrictions).


Creating and Customizing Controls

To define a control, use the AWS Management Console, AWS CLI, or SDKs. Custom controls require specifying input parameters to align with compliance policies.

Example: Custom Control for IAM Policy Restrictions

aws securityhub put-control \
  --control '{
    "Id": "custom-iam-policy-restriction",
    "Title": "Restrict IAM User Permissions",
    "Description": "Ensure IAM users have minimal permissions to reduce attack surfaces.",
    "Severity": "MEDIUM",
    "Remediation": {
      "Recommendation": {
        "Text": "Use IAM roles with least privilege and disable unused permissions.",
        "Url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html"
      }
    },
    "InputParameters": {
      "PolicyArn": "arn:aws:iam::123456789012:policy/MinimalAccessPolicy"
    }
  }'

Customization for Compliance:
- For GDPR compliance, configure controls to enforce encryption at rest for S3 buckets.
- For HIPAA, define controls to audit access logs for PHI (Protected Health Information).

Diagram:

[Control Definition]  
    ↓  
[Input Parameters] → [Compliance Policy] → [Security Hub Assessment]  
    ↓  
[Findings] → [Automated Remediation]  


Deploying Controls and Managing Compliance

Once defined, controls are automatically applied to AWS resources. Use AWS Config or CloudTrail to monitor compliance and generate findings.

Example: Associating a Control with AWS Config

  1. In the AWS Management Console, navigate to Security Hub → Controls.
  2. Select a control and click Edit.
  3. Under AWS Config Rules, associate it with a rule (e.g., iam-user-policy-no-unused-permissions).
  4. Enable Automated Remediation to trigger Lambda functions for correction.

Command to List Controls:

aws securityhub list-controls --max-results 5


Automating Compliance with Lambda

Integrate Security Hub findings with AWS Lambda to automate remediation. For example, a Lambda function can disable non-compliant IAM users when a finding is detected.

Example: Lambda Function for IAM User Remediation

import boto3

def lambda_handler(event, context):
    client = boto3.client('iam')
    user_name = event['detail']['findings'][0]['resources'][0]['resource']['arn'].split('/')[-1]
    client.delete_user(UserName=user_name)
    return {
        'statusCode': 200,
        'body': f'User {user_name} disabled due to non-compliance.'
    }

Diagram:

[Security Hub Finding] → [Lambda Trigger] → [IAM User Deletion]  


Key takeaways

  • Define controls using AWS CLI or Console, specifying input parameters for compliance.
  • Customize controls to align with regulatory standards (e.g., GDPR, HIPAA) or internal policies.
  • Deploy controls with AWS Config or CloudTrail to monitor resource compliance.
  • Automate remediation using Lambda to enforce security policies and reduce manual intervention.