Check for Amazon Inspector assessment exclusions and resolve them step by step to ensure that your assessment runs can be successfully executed. Exclusions are an output of Amazon Inspector assessment runs that show which of your security checks can't be completed and how to fix the issues that stopped the security checks. For example, issues can be caused by the absence of an agent on the specified target, the use of an unsupported Operating System (OS), or unexpected errors.
This rule can help you with the following compliance standards:
- APRA
- MAS
For further details on compliance standards supported by Conformity, see here.
This rule can help you work with the AWS Well-Architected Framework.
This rule resolution is part of the Conformity Security & Compliance tool for AWS.
Amazon Inspector is an AWS service that helps you improve the security and compliance of your cloud resources. Amazon Inspector assessment exclusions can show you which security checks and resources are not evaluated in an assessment run and provide guidance on how to solve the issues associated with those exclusions. Assessment runs can fail to execute or might complete with errors for multiple reasons. Use exclusions to get guidance and pinpoint the assessment issues, solve them, and successfully execute the assessment runs.
Note: As example, this conformity rule will demonstrate how to analyze and resolve an "Agent not found" assessment exclusion that is produced when the Amazon Inspector agent was not found on the target EC2 instance(s).
Audit
To check for Amazon Inspector post-assessment exclusions, perform the following operations:
Remediation / Resolution
To solve the exclusions produced by your Amazon Inspector assessment runs in order to ensure that the assessment runs can be successfully executed, perform the following operations:
Note: As example, this section provides step by step instructions on how to install the Amazon Inspector agent on Linux-based EC2 instances.References
- AWS Documentation
- Amazon Inspector
- Amazon Inspector FAQs
- Exclusions in Amazon Inspector
- Installing Amazon Inspector agents
- AWS Command Line Interface (CLI) Documentation
- inspector
- list-assessment-runs
- list-exclusions
- describe-exclusions
- ssm
- send-command
- list-commands