Security, Identity & Compliance
    🔐Security, Identity & Compliance

    AWS Security Hub CSPM

    Cloud security posture management: aggregated security findings and compliance checks across AWS accounts

    Security Hub CSPM is a security dashboard that shows everything wrong with your AWS setup in one place. Instead of checking GuardDuty for threats, Config for compliance, and IAM Access Analyzer for permissions separately, Security Hub CSPM collects findings from all of them, plus third-party tools like Palo Alto and Trend Micro. It is like a security manager who collects reports from every department and hands you one prioritized to-do list. It also runs its own continuous checks against standards such as CIS, PCI DSS, and the AWS Foundational Security Best Practices, grading each resource pass or fail so you know what to fix first. Every finding arrives in one common format, so your tools and scripts treat all alerts the same way. A newer companion product called Security Hub sits above it, correlating these signals into exposure findings; this entry covers the posture-management service underneath, the one most teams start with.

    The finding-aggregation and compliance service described here is now branded Security Hub CSPM, while a newer service simply called Security Hub sits above it to correlate exposure findings across CSPM, GuardDuty, Inspector, and Macie. Security Hub CSPM aggregates findings from AWS services (GuardDuty, Inspector, Macie, IAM Access Analyzer, Firewall Manager) and third-party tools (Palo Alto, Trend Micro, etc.). Findings are normalized into AWS Security Finding Format (ASFF) for consistent analysis. It runs automated compliance checks against security standards (CIS, PCI DSS, AWS Foundational Security Best Practices) and assigns severity scores.

    Key Capabilities

    • Aggregates findings from GuardDuty, Inspector, Macie, IAM Access Analyzer, Firewall Manager, and third-party tools into a single normalized view using the AWS Security Finding Format (ASFF)
    • Automated security checks evaluate resources against CIS AWS Foundations, AWS Foundational Security Best Practices, and PCI DSS standards, producing per-resource pass/fail findings
    • Cross-account aggregation consolidates findings from all accounts in an AWS Organizations structure into a single delegated administrator account
    • Custom insights let you create filtered, saved views and track trends in finding counts over time
    • EventBridge integration routes findings to Lambda, ticketing systems, or Slack for automated response and notification workflows
    • Finding suppression lets you mute known accepted risks so they no longer appear as open findings without deleting the underlying record

    Gotchas & Constraints

    Gotcha #1: Security Hub doesn't fix issues; it identifies them. You must implement remediation (manually or via automation). Gotcha #2: Security Hub charges per finding per month and per compliance check; costs can add up in large environments. Constraints: Maximum 10,000 member accounts per administrator account, findings are retained for 90 days, and some compliance checks are region-specific.

    A financial services company operates 100 AWS accounts across 5 regions with strict compliance requirements. Monitoring security across all accounts is overwhelming; each account has GuardDuty, Config, and IAM findings scattered across services. They enable Security Hub in all accounts and regions, designating a central security account as the aggregator. Security Hub collects findings from all accounts and regions into a single dashboard. They enable CIS AWS Foundations Benchmark and PCI DSS compliance checks; Security Hub identifies 500 compliance violations (public S3 buckets, overly permissive security groups, disabled CloudTrail). They prioritize findings by severity and create automated remediation: EventBridge triggers Lambda functions to fix common issues (enable MFA, remove public access from S3). For critical findings (GuardDuty detects compromised credentials), Security Hub sends SNS notifications to the security team. They generate weekly compliance reports for auditors showing progress toward 100% compliance.

    The Result

    centralized security visibility, automated remediation, and continuous compliance monitoring.

    Official AWS Documentation