Changes to Stax Rule names
A number of Rule names have been updated to improve usability and standardize rule names across all Rule Bundles. To find out more, visit the Stax Compliance module guide.
Changed
View All TagsA number of Rule names have been updated to improve usability and standardize rule names across all Rule Bundles. To find out more, visit the Stax Compliance module guide.
As part of our ongoing maintenance and improvement of rules and rule bundles, we are updating rules related to AWS CloudTrail log metric filters. This change will offer a shift towards organization-level CloudTrail configurations, enabling enhanced security and manageability for your resources.
Please be aware that the existing rules will be deprecated in the following bundles:
The deprecated rules are as follows:
The newly introduced rules will take their place with the following rule names respectively:
Please note that the check history for the deprecated rules will not be kept.
If you have any questions about this change and what it means for you, please contact support.
Stax has released a new version of the Cost & Compliance module's service and billing roles, version 33. The following permissions have been added to the roles:
If your AWS accounts are Stax-managed, then you don't need to take any action. Stax will automatically update this role in the coming days.
If you're subscribed only to the Stax Cost & Compliance module, you will need to apply the update yourself.
For any questions about this change, or if you need assistance deploying the updated role, please raise a support case.
Stax has released a new version of the Cost & Compliance module's service and billing roles, version 32. The following permissions have been added to the roles:
backup:GetBackupSelection
backup:ListBackupPlans
backup:ListBackupSelections
If your AWS accounts are Stax-managed, then you don't need to take any action. Stax will automatically update this role in the coming days.
If you're subscribed only to the Stax Cost & Compliance module, you will need to apply the update yourself.
For any questions about this change, or if you need assistance deploying the updated role, please raise a support case.
Default subscription preferences have changed for new users invited to Stax. After joining Stax, new users will now only be subscribed to the Weekly Summary, Wastage Report and New Rule Releases notification types. Users can then manage their notifications and make changes to their preferences.
As announced on 19th April 2023, the GET /20190206/groups/{group_id} route now returns a 404 HTTP status code if the group_id provided has the status of DELETED or does not exist.
Previously, the archived record would be returned for a deleted group and "Groups": [] would be returned if the group did not exist.
As announced on 6th April 2023, the following changes were made to the GET /20190206/users API route:
GET /20190206/api-tokens route should be used insteadstatus_filter query string, e.g. /users?status_filter=DELETEDGET /20190206/users/{user_id} route now returns a 404 HTTP status code if the user_id provided has the status of DELETED. Previously, this would return the archived recordThe Rule*** S3 enforces object encryptionhas been renamed to *** ***Ensure all S3 buckets employ server-side encryption-at-rest, ***in the S3 Best Practices and Organization bundles. This change helps to align the rule name across different bundles making it easier for customers to search for this rule across bundles.
It's important to note that the name of the rule has not been changed in the CIS Benchmark bundle to align with the standard's specification.
Changes have been applied to Stax-managed AWS Organizational Units in accordance with Release 1 from the published release plan. This was initially announced on 4 April 2023.
Stax manages AWS Organizations in alignment with established best practices. As a result, Stax-managed AWS Organizations will be uplifted to adhere to the organizational structure recommended in the AWS Security Reference Architecture and the Organizing Your AWS Environment Using Multiple Accounts whitepaper. In addition to this, new functionality will be introduced to allow tenancies to better utilize Organizational Units (OUs) and service control policies (SCPs).
These changes will be released over the next 8 weeks. For a detailed outline of these changes, see the release plan here.