Skip to main content

Developer preview of the Stax Terraform provider now available

Stax
Stax
Stax Team

The Stax Terraform provider will aid organizations using infrastructure-as-code to manage their AWS environments. The first release of this provider is now available and is released as a developer preview. It is not yet feature-complete and is not considered to be production-ready, rather exclusively for evaluation and feedback purposes.

For more information and to get started, see About the Stax Terraform Provider.

Foundational Technical Review Rule Bundle now available for AWS Partners

Stax
Stax
Stax Team

The new Partner Hosted Foundational Technical Review (FTR) Rule Bundle is designed to assist organizations to prepare for the AWS Partner Hosted FTR. This bundle provides evidence to support the AWS FTR self-assessment, ensuring a smooth and streamlined compliance process.

The Partner Hosted FTR bundle is now available to all organizations. Add the Bundle to Stax to get going. Once added, Stax will perform an initial evaluation and automatically populate the Rules page with the latest results.

Changes to Rule - Unused Amazon EC2 Security Groups Should Be Removed

Stax
Stax
Stax Team

The "Unused Amazon EC2 security groups should be removed" rule is available to help organizations manage their use of security groups.

On 27 June 2023, a fix will be released to correct the outdated logic of this rule which may impact related compliance scores.

The following bundles will be affected:

  • EC2 Best Practices (version 1.0)

  • APRA (versions 1.0, 1.1)

  • The custom organization-level rule, if in use

These changes will be applied automatically by Stax. There will be no impact to service expected as a result of this update.

If you have any questions about this change and what it means for you, please contact support.

"Lambdas have a unique role" rule deprecation

Stax
Stax
Stax Team

The rule “Lambdas have a unique role” will be deprecated in a rules update in 7 days. This rule has been a part of the Stax compliance module for many years, and after careful consideration, we have decided that it no longer serves its intended purpose.

This rule was originally intended to ensure that AWS Lambdas — cloud computing functions — had a unique role within the environment. As cloud computing and serverless functions have evolved, we have determined that this rule does not provide additional security and is no longer necessary.

This rule is only part of the Stax rule catalog, and is not used as part of any compliance or best practice rule bundles.

Organization-level CloudTrail configuration supported for object-level logging for S3 buckets Rules

Stax
Stax
Stax Team

As announced on 09 May 2023, a change has been released for the listed Rules that check if object-level logging is enabled for S3 buckets.

This Rule will now detect when S3 data event logging is enabled on CloudTrail trails configured in member accounts as well as when configured on Organization-level CloudTrail trails.

Bundle NameRule Name
Organization Bundle/catalogEnsure that Object-level logging for write events is enabled for S3 bucket

Ensure that Object-level logging for read events is enabled for S3 bucket
CIS Benchmark v1.3.0, v1.4.0 & v1.5.0CIS 3.10 - Ensure that Object-level logging for write events is enabled for S3 bucket
CIS 3.11 - Ensure that Object-level logging for read events is enabled for S3 bucket

By default, Stax does not configure S3 object-level logging for Stax-managed accounts. An S3 bucket with a high workload could quickly generate thousands of logs in a short amount of time, resulting in increased AWS costs. Find out more about Enabling CloudTrail event logging for S3 buckets and objects.