AWS Security Hub

AWS Security Hub is an Amazon Web Services cloud security posture management service that aggregates alerts from various AWS services and partner products, in a standardized format, using industry-standard best practices.

Key points

  • Now officially named AWS Security Hub CSPM (Cloud Security Posture Management) in current AWS documentation, reflecting its role as the cloud security posture management component of the broader Security Hub product.
  • Automatically runs compliance checks against standards such as the AWS Foundational Security Best Practices standard, the Center for Internet Security (CIS) AWS Foundations Benchmark, the Payment Card Industry Data Security Standard (PCI DSS), NIST SP 800-53 Revision 5, and NIST SP 800-171 Revision 2 (older CLF-C02 material cites “NIST” generically). Also supports newer AI Security Best Practices and AWS Resource Tagging standards, plus a Control Tower service-managed standard.
  • Can be enabled or disabled through the AWS Management Console, the AWS CLI, or infrastructure-as-code tools such as Terraform.
  • Collects findings/alerts from multiple AWS accounts, then analyzes security trends and identifies the highest-priority security issues.
  • Aggregates, organizes, and prioritizes security findings from services such as Amazon GuardDuty, Amazon Macie, Amazon Inspector, IAM Access Analyzer, and AWS Firewall Manager, plus partner tools, and shows current security and compliance status through integrated dashboards.
  • Does not generate its own detection findings — it depends on those source services (and its own compliance checks) to produce findings; contrast with Amazon GuardDuty, which detects threats itself.
  • Security alerts or findings can be investigated further using Amazon Detective or Amazon Cloudwatch event rules.
  • Reduces the time-consuming data conversion effort otherwise needed to collect data from AWS services across accounts.

Pricing

  • Charges apply only for the current Region, not for all Regions in which Security Hub CSPM is enabled.

Sources