Stax-managed GuardDuty now supports AI Protection
You can now enable AI Protection in Stax-managed GuardDuty using the Stax Console, API, and SDK.
For more information, see Using Stax-managed GuardDuty in the docs.
Added
View All TagsYou can now enable AI Protection in Stax-managed GuardDuty using the Stax Console, API, and SDK.
For more information, see Using Stax-managed GuardDuty in the docs.
Stax's new Recommendations feature is now available. It provides guidance and suggestions to help ensure your Stax-managed AWS Organization is configured in line with best practices.
See Recommendations in the docs for a detailed list of all the recommendations available in Stax. More recommendations will be added in time, but for now you can see guidance of when you have AWS Accounts or Foundation Services configured incorrectly, when basic security controls are not enabled, or when there are simple account hygiene steps to be taken to best configure your AWS Organization using Stax.
This feature is available to administrators of all Stax tenancies. To get started, log in to Stax and review the Recommendations pane on the Organization page.
A new Guardrail has been added under the AWS IAM Identity Center header titled Block creation of account-level instances for IAM Identity Center.
This Guardrail will prevent member AWS accounts for creating any account-level instances of IAM Identity Center, ensuring that only a centrally managed IAM Identity Centre exists within the AWS management account.
To enable this visit the configurable service page Configurable Guardrails.
A new configurable service for AWS Organization has been added. This configurable service allows customization for enabling/disabling cross-region Bedrock access.
For more information, refer to the documentation on Configure AWS Organization.
Stax will now automatically enable AWS Organizations trusted access for the AWS User Notification service. Additionally the security account is added as a delegated administrator for the AWS Organization service.
For more information, refer to the documentation on AWS User Notifications.
The Accounts page now supports filtering accounts by Account Type. The Add Filter button now has a Type sub-menu which allows searching and filtering by Account Type.
Users of Workloads can now search the list of deployed Workloads by name, including using partial name matches. For example, searching for "myapp" will return results for "myapp" and "myapplication".
Previously the name search worked by filtering results client-side. This search capability is now performed server-side which allows searching much larger sets of results.
You can now enable the AWS Foundations Benchmark version 5.0.0 standard in AWS Security Hub using Stax with the Stax-managed Security Hub using the Stax Console, API, and SDK.
For more information, see Using Stax-managed Security Hub in the docs.
Configuration options have been added to the AWS Accounts Foundation Services page to allow you to fine-tune security protections for all Stax-managed AWS Accounts.
A new toggle to require Instance Metadata Service Version 2 (IMDSv2) has been added. IMDSv2 compliance is included in the CIS AWS Foundations Benchmark.
Before enabling this protection please ensure that your AWS environment is compatible with IMDSv2
This can be further enforced by applying the two Guardrails:
For more information, refer to the documentation on Configure AWS Accounts.
Further configuration options have been added to the AWS Accounts configurable service page to allow you to fine-tune security protections for all Stax-managed AWS Accounts.
A new toggle to block SSM Document public sharing has been added.
This can be further enforced by applying the Guardrail Block changes to AWS Systems Manager public sharing settings.
For more information, refer to the documentation on Configure AWS Accounts.