Ensure that Amazon Config service is referencing an active Simple Notification Service (SNS) topic in order to send configuration changes notifications to your SNS subscription endpoints for monitoring. These notifications supply useful information regarding each configuration item created by AWS Config and provide a delivery status for each configuration snapshot and configuration history generated by the service.
excellence
When AWS Config is not referencing an active SNS topic, Amazon cannot send notifications to your subscription endpoints anymore, therefore you lose the ability to monitor the configuration changes made within your AWS account via email (or any other communication protocol provided by SNS).
Audit
To determine if Amazon Config service is missing the ability to send notifications due to inactive SNS topic, perform the following actions:
Remediation / Resolution
To update Amazon Config service configurations that reference missing SNS topics, perform the following:
References
- AWS Documentation
- FAQs
- Notifications that AWS Config sends
- Monitoring AWS Config Resource Changes by Email
- AWS Command Line Interface (CLI) Documentation
- configservice
- describe-delivery-channels
- put-delivery-channel
- sns
- get-topic-attributes
- create-topic
- subscribe
- confirm-subscription
Unlock the Remediation Steps
Gain free unlimited access
to our full Knowledge Base
Over 750 rules & best practices
for and
Get started for FREE
You are auditing:
AWS Config Referencing Missing SNS Topic
Risk level: Medium