Skip to main content
{ Reporting and Compliance / Vulnerability Management }

AWS Security Hub CSPM Posture Report

Delivers a weekly report on Security Hub CSPM coverage across your accounts and regions, what changed in the findings, and anything in the configuration that needs an admin, from disabled controls to broken product integrations.

What this agent does

This read-only agent checks the health of AWS Security Hub CSPM across an organization every week. It finds accounts and enabled regions where Security Hub CSPM is off, the account is not a member of the administrator account, or findings are not aggregated. It compares the enabled standards and controls with a baseline the team approved. It summarizes the Critical and High findings that appeared, were resolved, and were suppressed since last week. It flags anything that needs an admin, such as a product integration that stopped sending findings or a control the team disabled without a reason.

The challenge

Security Hub CSPM only reports on the accounts and regions where it is on. Nothing warns the team when a gap opens. A new account joins the organization while auto-enable is off, so Security Hub CSPM never turns on there. A region is enabled with no Security Hub CSPM. A control is disabled to quiet a noisy finding and never turned back on. Nobody audits who suppressed which finding. A product integration stops delivering, and the dashboard looks cleaner, not broken.

The solution

The agent checks coverage, configuration, integrations, and finding movement in one pass each week and compares them with the previous week and with the approved baseline. It lists what changed and what someone needs to act on, with the fix for each item. Provides a weekly briefing an admin can read in a few minutes.

Workflow

  1. 01

    Check coverage

    Compare the organization's accounts and enabled regions with where Security Hub CSPM is on, a member, and aggregated.

  2. 02

    Check configuration

    Compare enabled standards, controls, and configuration policies with the approved baseline, and check each product integration's status.

  3. 03

    Check activity

    Summarize Critical and High findings that appeared, were resolved, and were suppressed since last week.

  4. 04

    Report

    Publish what changed and what needs action, with the fix for each item.

Agent template

# AWS Security Hub CSPM Posture Report

## Measurable outcomes

Every week, the admin knows which accounts and regions Security Hub CSPM is not covering, how the configuration differs from the baseline, how the Critical and High findings moved, and what needs action. Track covered and uncovered account-region pairs, baseline differences, and open action items on every run.

## Procedure

Once a week, from the delegated administrator account, list the organization's accounts and each account's enabled regions. Flag each account-region pair where Security Hub CSPM is off, where the account is not a member of the administrator, or where findings are not aggregated to the aggregation region. Flag accounts that joined the organization and were not enrolled. Compare the enabled standards and controls in each account-region pair with a baseline I approve. Flag each control that is disabled or enabled outside the baseline, with the disabled reason if one was given. When central configuration is on, compare each configuration policy and its account associations with the baseline. Treat a configuration with no approved baseline as a candidate, never as drift. Check each product integration, and flag any integration that is disabled, or that stopped sending after a week with findings. Summarize the new Critical and High findings, the findings resolved, and the findings suppressed since the last report, with who suppressed each one and the note they left. Flag automation rules that suppress findings, with the rule's criteria. Compare everything with last week's report, and lead with what changed. Give every action item the specific fix. Report a check it cannot run as not checked, never as fine.

## Requirements

It needs read-only AWS Security Hub CSPM access in the delegated administrator account, read-only AWS Organizations access to list accounts, and nothing more. It never changes Security Hub CSPM settings, configuration policies, standards, controls, automation rules, or findings, and never approves a baseline.