<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[[Turbot On]]]></title><description><![CDATA[Weekly tips, tricks and updates for Turbot customers.]]></description><link>https://on.turbot.com</link><image><url>https://substackcdn.com/image/fetch/$s_!p5XJ!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0bc0c730-9a8a-401c-9db4-d132c3e6d4f5_300x300.png</url><title>[Turbot On]</title><link>https://on.turbot.com</link></image><generator>Substack</generator><lastBuildDate>Fri, 24 Apr 2026 09:30:44 GMT</lastBuildDate><atom:link href="https://on.turbot.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Turbot HQ, Inc.]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[turboton@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[turboton@substack.com]]></itunes:email><itunes:name><![CDATA[David Boeke]]></itunes:name></itunes:owner><itunes:author><![CDATA[David Boeke]]></itunes:author><googleplay:owner><![CDATA[turboton@substack.com]]></googleplay:owner><googleplay:email><![CDATA[turboton@substack.com]]></googleplay:email><googleplay:author><![CDATA[David Boeke]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[20 automations to reduce cloud spend in 2023]]></title><description><![CDATA[How to use Turbot to find operational cost savings.]]></description><link>https://on.turbot.com/p/20-automations-to-reduce-cloud-spend</link><guid isPermaLink="false">https://on.turbot.com/p/20-automations-to-reduce-cloud-spend</guid><dc:creator><![CDATA[David Boeke]]></dc:creator><pubDate>Mon, 06 Feb 2023 18:10:09 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!cmkS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fd3ad76-02cc-4a75-bb0f-083b10728c29_2700x900.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cmkS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fd3ad76-02cc-4a75-bb0f-083b10728c29_2700x900.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cmkS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fd3ad76-02cc-4a75-bb0f-083b10728c29_2700x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!cmkS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fd3ad76-02cc-4a75-bb0f-083b10728c29_2700x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!cmkS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fd3ad76-02cc-4a75-bb0f-083b10728c29_2700x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!cmkS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fd3ad76-02cc-4a75-bb0f-083b10728c29_2700x900.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cmkS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fd3ad76-02cc-4a75-bb0f-083b10728c29_2700x900.jpeg" width="1456" height="485" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7fd3ad76-02cc-4a75-bb0f-083b10728c29_2700x900.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:485,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:702586,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cmkS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fd3ad76-02cc-4a75-bb0f-083b10728c29_2700x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!cmkS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fd3ad76-02cc-4a75-bb0f-083b10728c29_2700x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!cmkS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fd3ad76-02cc-4a75-bb0f-083b10728c29_2700x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!cmkS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fd3ad76-02cc-4a75-bb0f-083b10728c29_2700x900.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>What is the best time to start optimizing your cloud spend?</strong></h3><p>Three months ago&#8230; but the second-best time is&nbsp;<em><strong>today</strong></em>. Quickly implementing Turbot&#8217;s prebuilt automated controls <em><strong>today</strong></em> will allow you to achieve far more savings in 2023 than a built-from-scratch or cross-team manual effort that won&#8217;t start realizing value until mid-year (or later).&nbsp;</p><p>Your cloud costs are increasing daily, but controlling costs can be difficult and the time to execute on these initiatives competes with other priorities for the operations team.&nbsp; This post describes Turbot automations that you can deploy immediately to reduce your cloud spend. The examples will focus on AWS, but the logic and tools apply to all major cloud providers.</p><h3>Tagging strategies for charge-back and show-back</h3><p>The adage &#8212; You can't control what you don't see &#8212; very much applies to cloud cost management. We have seen customers achieve massive cost savings of 30% or more by making sure each of their business units receive an accounting of their current spend each month. This will have even more impact if that business unit is charged for their usage, and it comes out of their budget.&nbsp;</p><p>Tagging resources correctly is critical to segmenting your cloud spend by business unit. Turbot's automated tagging solutions allow you to retroactively tag resources with additional metadata (like cost center) and ensure all newly created resources are tagged correctly. Some example tagging strategies that can be automated using Turbot:</p><ul><li><p>Tag all resources with who created the resource and the resource created time.</p></li><li><p>Propagate tagging metadata from AWS organizations to all resources in an account.</p></li><li><p>Tag all resources with a cost center based on the account deployed to or the individual that created it.</p></li><li><p>Propagate metadata from Service Now or custom databases to all resources.</p></li><li><p>Auto remediate common misspellings and abbreviations in existing tag keys and values.</p></li><li><p>Remediate competing tag strategies to one enterprise standard:</p><ul><li><p>Env:Dev -&gt; environment:development</p></li><li><p>env:Development -&gt; environment:development</p></li></ul></li><li><p>Propagate tags from key resources to dependent resources:</p><ul><li><p>Tag volumes attached to a compute instance with the instance&#8217;s tags.&nbsp;</p></li><li><p>Tag snapshots created from a volume with the volume&#8217;s tags.</p></li><li><p>Tag all resources that are associated with a VPC with the VPC&#8217;s metadata.</p></li></ul></li><li><p>Remediate when new resources are created without correct tags:</p><ul><li><p>Add missing tags to the resource.</p></li><li><p>Create alarms and alert on the resource tagging issue.</p></li><li><p>Terminate newly created resources without correct tags.</p></li></ul></li></ul><div class="embedded-post-wrap" data-attrs="{&quot;id&quot;:36520949,&quot;url&quot;:&quot;https://on.turbot.com/p/turbot-on-tagging-with-context&quot;,&quot;publication_id&quot;:256163,&quot;publication_name&quot;:&quot;[Turbot On]&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0bc0c730-9a8a-401c-9db4-d132c3e6d4f5_300x300.png&quot;,&quot;title&quot;:&quot;[Turbot On] Tagging with Context&quot;,&quot;truncated_body_text&quot;:&quot;Tagging is a crucial component for cloud operations, security and compliance. The most common tagging methodologies rely on owner-assigned resource tags to add external context to resources; however, additional deep context can be added to resources via automation.&quot;,&quot;date&quot;:&quot;2021-05-17T18:44:38.625Z&quot;,&quot;like_count&quot;:1,&quot;comment_count&quot;:0,&quot;bylines&quot;:[{&quot;id&quot;:19112887,&quot;name&quot;:&quot;Bob Tordella&quot;,&quot;previous_name&quot;:null,&quot;photo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/9b15e9e7-88a4-429e-94e3-663ffa55dabb_442x353.png&quot;,&quot;bio&quot;:&quot;Turbot CRO. We provide Enterprise guardrails for Amazon Web Services, Azure, and Google Cloud: Achieve Agility, Ensure Control, Be Best Practice.&quot;,&quot;profile_set_up_at&quot;:&quot;2021-09-30T21:18:51.982Z&quot;,&quot;publicationUsers&quot;:[{&quot;id&quot;:16218,&quot;user_id&quot;:19112887,&quot;publication_id&quot;:256163,&quot;role&quot;:&quot;admin&quot;,&quot;public&quot;:true,&quot;is_primary&quot;:false,&quot;publication&quot;:{&quot;id&quot;:256163,&quot;name&quot;:&quot;[Turbot On]&quot;,&quot;subdomain&quot;:&quot;turboton&quot;,&quot;custom_domain&quot;:&quot;on.turbot.com&quot;,&quot;custom_domain_optional&quot;:false,&quot;hero_text&quot;:&quot;Weekly tips, tricks and updates for Turbot customers.&quot;,&quot;logo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/0bc0c730-9a8a-401c-9db4-d132c3e6d4f5_300x300.png&quot;,&quot;author_id&quot;:18396950,&quot;theme_var_background_pop&quot;:&quot;#D10000&quot;,&quot;created_at&quot;:&quot;2021-01-06T19:06:38.895Z&quot;,&quot;rss_website_url&quot;:null,&quot;email_from_name&quot;:&quot;Turbot News&quot;,&quot;copyright&quot;:&quot;Turbot HQ, Inc.&quot;,&quot;founding_plan_name&quot;:null,&quot;community_enabled&quot;:true,&quot;invite_only&quot;:false,&quot;payments_state&quot;:&quot;disabled&quot;}}],&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null,&quot;inviteAccepted&quot;:true}],&quot;utm_campaign&quot;:null,&quot;belowTheFold&quot;:true,&quot;type&quot;:&quot;newsletter&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="EmbeddedPostToDOM"><a class="embedded-post" native="true" href="https://on.turbot.com/p/turbot-on-tagging-with-context?utm_source=substack&amp;utm_campaign=post_embed&amp;utm_medium=web"><div class="embedded-post-header"><img class="embedded-post-publication-logo" src="https://substackcdn.com/image/fetch/$s_!p5XJ!,w_56,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0bc0c730-9a8a-401c-9db4-d132c3e6d4f5_300x300.png" loading="lazy"><span class="embedded-post-publication-name">[Turbot On]</span></div><div class="embedded-post-title-wrapper"><div class="embedded-post-title">[Turbot On] Tagging with Context</div></div><div class="embedded-post-body">Tagging is a crucial component for cloud operations, security and compliance. The most common tagging methodologies rely on owner-assigned resource tags to add external context to resources; however, additional deep context can be added to resources via automation&#8230;</div><div class="embedded-post-cta-wrapper"><span class="embedded-post-cta">Read more</span></div><div class="embedded-post-meta">5 years ago &#183; 1 like &#183; Bob Tordella</div></a></div><h3>Stopping resources when not in use</h3><p>One of the best things about cloud services is that you only need to pay for what you use. For workloads that don&#8217;t need to be running 24/7 (think development, testing, QA environments) scheduling resources to stop off hours can save over 70% of your cloud usage. Turbot has some great built-in controls to help you automate this across hundreds of cloud service accounts.</p><div class="pullquote"><p>There has never been a dev team in the history of IT that is not guilty of spinning up a few VMs for testing in a sandbox account, getting side-tracked with another urgent priority and forgetting about it until they show up in your cloud bill weeks later. Turbot's automation allows your cloud operations team to solve this problem permanently.</p></div><div class="embedded-post-wrap" data-attrs="{&quot;id&quot;:31638799,&quot;url&quot;:&quot;https://on.turbot.com/p/turbot-on-cost-savings&quot;,&quot;publication_id&quot;:256163,&quot;publication_name&quot;:&quot;[Turbot On]&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0bc0c730-9a8a-401c-9db4-d132c3e6d4f5_300x300.png&quot;,&quot;title&quot;:&quot;[Turbot On] Cost Savings&quot;,&quot;truncated_body_text&quot;:&quot;Ensure instances are stopped before they overrun your cloud budget. For workloads that don&#8217;t need to be running 24/7 (think development, testing, qa environments) scheduling resources to stop off hours can save over 70% of your cloud usage. This week we will look at some scheduling best practices and see how Turbot can help enforce them.&quot;,&quot;date&quot;:&quot;2021-01-19T18:39:30.444Z&quot;,&quot;like_count&quot;:2,&quot;comment_count&quot;:0,&quot;bylines&quot;:[{&quot;id&quot;:19112887,&quot;name&quot;:&quot;Bob Tordella&quot;,&quot;previous_name&quot;:null,&quot;photo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/9b15e9e7-88a4-429e-94e3-663ffa55dabb_442x353.png&quot;,&quot;bio&quot;:&quot;Turbot CRO. We provide Enterprise guardrails for Amazon Web Services, Azure, and Google Cloud: Achieve Agility, Ensure Control, Be Best Practice.&quot;,&quot;profile_set_up_at&quot;:&quot;2021-09-30T21:18:51.982Z&quot;,&quot;publicationUsers&quot;:[{&quot;id&quot;:16218,&quot;user_id&quot;:19112887,&quot;publication_id&quot;:256163,&quot;role&quot;:&quot;admin&quot;,&quot;public&quot;:true,&quot;is_primary&quot;:false,&quot;publication&quot;:{&quot;id&quot;:256163,&quot;name&quot;:&quot;[Turbot On]&quot;,&quot;subdomain&quot;:&quot;turboton&quot;,&quot;custom_domain&quot;:&quot;on.turbot.com&quot;,&quot;custom_domain_optional&quot;:false,&quot;hero_text&quot;:&quot;Weekly tips, tricks and updates for Turbot customers.&quot;,&quot;logo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/0bc0c730-9a8a-401c-9db4-d132c3e6d4f5_300x300.png&quot;,&quot;author_id&quot;:18396950,&quot;theme_var_background_pop&quot;:&quot;#D10000&quot;,&quot;created_at&quot;:&quot;2021-01-06T19:06:38.895Z&quot;,&quot;rss_website_url&quot;:null,&quot;email_from_name&quot;:&quot;Turbot News&quot;,&quot;copyright&quot;:&quot;Turbot HQ, Inc.&quot;,&quot;founding_plan_name&quot;:null,&quot;community_enabled&quot;:true,&quot;invite_only&quot;:false,&quot;payments_state&quot;:&quot;disabled&quot;}}],&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null,&quot;inviteAccepted&quot;:true}],&quot;utm_campaign&quot;:null,&quot;belowTheFold&quot;:true,&quot;type&quot;:&quot;newsletter&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="EmbeddedPostToDOM"><a class="embedded-post" native="true" href="https://on.turbot.com/p/turbot-on-cost-savings?utm_source=substack&amp;utm_campaign=post_embed&amp;utm_medium=web"><div class="embedded-post-header"><img class="embedded-post-publication-logo" src="https://substackcdn.com/image/fetch/$s_!p5XJ!,w_56,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0bc0c730-9a8a-401c-9db4-d132c3e6d4f5_300x300.png" loading="lazy"><span class="embedded-post-publication-name">[Turbot On]</span></div><div class="embedded-post-title-wrapper"><div class="embedded-post-title">[Turbot On] Cost Savings</div></div><div class="embedded-post-body">Ensure instances are stopped before they overrun your cloud budget. For workloads that don&#8217;t need to be running 24/7 (think development, testing, qa environments) scheduling resources to stop off hours can save over 70% of your cloud usage. This week we will look at some scheduling best practices and see how Turbot can help enforce them&#8230;</div><div class="embedded-post-cta-wrapper"><span class="embedded-post-cta">Read more</span></div><div class="embedded-post-meta">5 years ago &#183; 2 likes &#183; Bob Tordella</div></a></div><p>In Turbot, scheduling guardrails are readily available to control your cloud resource usage. You can choose to shutdown instances every night, every weekend, or on a custom schedule with just a few clicks. Turbot currently supports the following cloud services to be automatically scheduled for start/stop:</p><ul><li><p>AWS EC2 Instances</p></li><li><p>AWS RDS Clusters/Instances</p></li><li><p>AWS Redshift Clusters</p></li><li><p>AWS WorkSpaces</p></li><li><p>Azure Virtual Machines</p></li><li><p>GCP Compute Instances</p></li></ul><h3>Finding and removing unused resources</h3><p>Lack of visibility to cost factors and rapid development in the cloud can mean that teams lose track of infrastructure that is no longer needed over time.  Turbot can help your operations team hunt down and destroy these unwanted pests.</p><ul><li><p>Delete unattached storage volumes</p></li><li><p>Delete old snapshots</p></li><li><p>Delete load balancers without targets</p></li><li><p>Delete unattached elastic IP addresses</p></li><li><p>Delete unattached NAT gateways</p></li><li><p>Delete unused internet gateways</p></li><li><p>Unused Secret Manger Secrets</p></li></ul><div class="embedded-post-wrap" data-attrs="{&quot;id&quot;:32123555,&quot;url&quot;:&quot;https://on.turbot.com/p/turbot-on-unattached-storage-volume&quot;,&quot;publication_id&quot;:256163,&quot;publication_name&quot;:&quot;[Turbot On]&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0bc0c730-9a8a-401c-9db4-d132c3e6d4f5_300x300.png&quot;,&quot;title&quot;:&quot;[Turbot On] Unattached Storage Volume Cleanup&quot;,&quot;truncated_body_text&quot;:&quot;The ability to easily create, attach and unattach disk volumes is one of the key benefits of working with IaaS, but it can also become a source of unchecked cost if not watched closely. Even if an Amazon EBS Volume, Azure Compute Disk, or GCP Compute Engine Disk is unattached, you are still billed for their provisioned storage. Surprisingly this adds u&#8230;&quot;,&quot;date&quot;:&quot;2021-02-02T19:25:56.558Z&quot;,&quot;like_count&quot;:6,&quot;comment_count&quot;:0,&quot;bylines&quot;:[{&quot;id&quot;:19112887,&quot;name&quot;:&quot;Bob Tordella&quot;,&quot;previous_name&quot;:null,&quot;photo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/9b15e9e7-88a4-429e-94e3-663ffa55dabb_442x353.png&quot;,&quot;bio&quot;:&quot;Turbot CRO. We provide Enterprise guardrails for Amazon Web Services, Azure, and Google Cloud: Achieve Agility, Ensure Control, Be Best Practice.&quot;,&quot;profile_set_up_at&quot;:&quot;2021-09-30T21:18:51.982Z&quot;,&quot;publicationUsers&quot;:[{&quot;id&quot;:16218,&quot;user_id&quot;:19112887,&quot;publication_id&quot;:256163,&quot;role&quot;:&quot;admin&quot;,&quot;public&quot;:true,&quot;is_primary&quot;:false,&quot;publication&quot;:{&quot;id&quot;:256163,&quot;name&quot;:&quot;[Turbot On]&quot;,&quot;subdomain&quot;:&quot;turboton&quot;,&quot;custom_domain&quot;:&quot;on.turbot.com&quot;,&quot;custom_domain_optional&quot;:false,&quot;hero_text&quot;:&quot;Weekly tips, tricks and updates for Turbot customers.&quot;,&quot;logo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/0bc0c730-9a8a-401c-9db4-d132c3e6d4f5_300x300.png&quot;,&quot;author_id&quot;:18396950,&quot;theme_var_background_pop&quot;:&quot;#D10000&quot;,&quot;created_at&quot;:&quot;2021-01-06T19:06:38.895Z&quot;,&quot;rss_website_url&quot;:null,&quot;email_from_name&quot;:&quot;Turbot News&quot;,&quot;copyright&quot;:&quot;Turbot HQ, Inc.&quot;,&quot;founding_plan_name&quot;:null,&quot;community_enabled&quot;:true,&quot;invite_only&quot;:false,&quot;payments_state&quot;:&quot;disabled&quot;}}],&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null,&quot;inviteAccepted&quot;:true}],&quot;utm_campaign&quot;:null,&quot;belowTheFold&quot;:true,&quot;type&quot;:&quot;newsletter&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="EmbeddedPostToDOM"><a class="embedded-post" native="true" href="https://on.turbot.com/p/turbot-on-unattached-storage-volume?utm_source=substack&amp;utm_campaign=post_embed&amp;utm_medium=web"><div class="embedded-post-header"><img class="embedded-post-publication-logo" src="https://substackcdn.com/image/fetch/$s_!p5XJ!,w_56,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0bc0c730-9a8a-401c-9db4-d132c3e6d4f5_300x300.png" loading="lazy"><span class="embedded-post-publication-name">[Turbot On]</span></div><div class="embedded-post-title-wrapper"><div class="embedded-post-title">[Turbot On] Unattached Storage Volume Cleanup</div></div><div class="embedded-post-body">The ability to easily create, attach and unattach disk volumes is one of the key benefits of working with IaaS, but it can also become a source of unchecked cost if not watched closely. Even if an Amazon EBS Volume, Azure Compute Disk, or GCP Compute Engine Disk is unattached, you are still billed for their provisioned storage. Surprisingly this adds u&#8230;</div><div class="embedded-post-cta-wrapper"><span class="embedded-post-cta">Read more</span></div><div class="embedded-post-meta">5 years ago &#183; 6 likes &#183; Bob Tordella</div></a></div><div class="embedded-post-wrap" data-attrs="{&quot;id&quot;:34163937,&quot;url&quot;:&quot;https://on.turbot.com/p/turbot-on-cleanup-unwanted-internet&quot;,&quot;publication_id&quot;:256163,&quot;publication_name&quot;:&quot;[Turbot On]&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0bc0c730-9a8a-401c-9db4-d132c3e6d4f5_300x300.png&quot;,&quot;title&quot;:&quot;[Turbot On] Cleanup Unwanted Internet Gateways&quot;,&quot;truncated_body_text&quot;:&quot;An Internet Gateway (IGW) attached to an Amazon VPC is a highly available network component that allows Internet connectivity from (or to) your VPC. However, for many Network topologies IGWs are either unnecessary or unwanted. For example, if you are routing all VPC traffic back to your on-premise network, having an IGW present may create risk of unappr&#8230;&quot;,&quot;date&quot;:&quot;2021-03-22T15:24:22.728Z&quot;,&quot;like_count&quot;:1,&quot;comment_count&quot;:2,&quot;bylines&quot;:[{&quot;id&quot;:19112887,&quot;name&quot;:&quot;Bob Tordella&quot;,&quot;previous_name&quot;:null,&quot;photo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/9b15e9e7-88a4-429e-94e3-663ffa55dabb_442x353.png&quot;,&quot;bio&quot;:&quot;Turbot CRO. We provide Enterprise guardrails for Amazon Web Services, Azure, and Google Cloud: Achieve Agility, Ensure Control, Be Best Practice.&quot;,&quot;profile_set_up_at&quot;:&quot;2021-09-30T21:18:51.982Z&quot;,&quot;publicationUsers&quot;:[{&quot;id&quot;:16218,&quot;user_id&quot;:19112887,&quot;publication_id&quot;:256163,&quot;role&quot;:&quot;admin&quot;,&quot;public&quot;:true,&quot;is_primary&quot;:false,&quot;publication&quot;:{&quot;id&quot;:256163,&quot;name&quot;:&quot;[Turbot On]&quot;,&quot;subdomain&quot;:&quot;turboton&quot;,&quot;custom_domain&quot;:&quot;on.turbot.com&quot;,&quot;custom_domain_optional&quot;:false,&quot;hero_text&quot;:&quot;Weekly tips, tricks and updates for Turbot customers.&quot;,&quot;logo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/0bc0c730-9a8a-401c-9db4-d132c3e6d4f5_300x300.png&quot;,&quot;author_id&quot;:18396950,&quot;theme_var_background_pop&quot;:&quot;#D10000&quot;,&quot;created_at&quot;:&quot;2021-01-06T19:06:38.895Z&quot;,&quot;rss_website_url&quot;:null,&quot;email_from_name&quot;:&quot;Turbot News&quot;,&quot;copyright&quot;:&quot;Turbot HQ, Inc.&quot;,&quot;founding_plan_name&quot;:null,&quot;community_enabled&quot;:true,&quot;invite_only&quot;:false,&quot;payments_state&quot;:&quot;disabled&quot;}}],&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null,&quot;inviteAccepted&quot;:true}],&quot;utm_campaign&quot;:null,&quot;belowTheFold&quot;:true,&quot;type&quot;:&quot;newsletter&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="EmbeddedPostToDOM"><a class="embedded-post" native="true" href="https://on.turbot.com/p/turbot-on-cleanup-unwanted-internet?utm_source=substack&amp;utm_campaign=post_embed&amp;utm_medium=web"><div class="embedded-post-header"><img class="embedded-post-publication-logo" src="https://substackcdn.com/image/fetch/$s_!p5XJ!,w_56,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0bc0c730-9a8a-401c-9db4-d132c3e6d4f5_300x300.png" loading="lazy"><span class="embedded-post-publication-name">[Turbot On]</span></div><div class="embedded-post-title-wrapper"><div class="embedded-post-title">[Turbot On] Cleanup Unwanted Internet Gateways</div></div><div class="embedded-post-body">An Internet Gateway (IGW) attached to an Amazon VPC is a highly available network component that allows Internet connectivity from (or to) your VPC. However, for many Network topologies IGWs are either unnecessary or unwanted. For example, if you are routing all VPC traffic back to your on-premise network, having an IGW present may create risk of unappr&#8230;</div><div class="embedded-post-cta-wrapper"><span class="embedded-post-cta">Read more</span></div><div class="embedded-post-meta">5 years ago &#183; 1 like &#183; 2 comments &#183; Bob Tordella</div></a></div><div class="embedded-post-wrap" data-attrs="{&quot;id&quot;:35633977,&quot;url&quot;:&quot;https://on.turbot.com/p/turbot-on-automated-snapshot-cleanup&quot;,&quot;publication_id&quot;:256163,&quot;publication_name&quot;:&quot;[Turbot On]&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0bc0c730-9a8a-401c-9db4-d132c3e6d4f5_300x300.png&quot;,&quot;title&quot;:&quot;[Turbot On] Automated Snapshot Cleanup&quot;,&quot;truncated_body_text&quot;:&quot;One of the key benefits of working with IaaS services Amazon EBS, Amazon RDS, etc. is the ability to programmatically create backups and snapshots, but it can also become a source of unchecked cost if not watched closely. The AWS Backup service, first released in 2019, has the ability to automate backup scheduling and enforce retention policies, but man&#8230;&quot;,&quot;date&quot;:&quot;2021-04-26T17:56:28.986Z&quot;,&quot;like_count&quot;:2,&quot;comment_count&quot;:0,&quot;bylines&quot;:[{&quot;id&quot;:19112887,&quot;name&quot;:&quot;Bob Tordella&quot;,&quot;previous_name&quot;:null,&quot;photo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/9b15e9e7-88a4-429e-94e3-663ffa55dabb_442x353.png&quot;,&quot;bio&quot;:&quot;Turbot CRO. We provide Enterprise guardrails for Amazon Web Services, Azure, and Google Cloud: Achieve Agility, Ensure Control, Be Best Practice.&quot;,&quot;profile_set_up_at&quot;:&quot;2021-09-30T21:18:51.982Z&quot;,&quot;publicationUsers&quot;:[{&quot;id&quot;:16218,&quot;user_id&quot;:19112887,&quot;publication_id&quot;:256163,&quot;role&quot;:&quot;admin&quot;,&quot;public&quot;:true,&quot;is_primary&quot;:false,&quot;publication&quot;:{&quot;id&quot;:256163,&quot;name&quot;:&quot;[Turbot On]&quot;,&quot;subdomain&quot;:&quot;turboton&quot;,&quot;custom_domain&quot;:&quot;on.turbot.com&quot;,&quot;custom_domain_optional&quot;:false,&quot;hero_text&quot;:&quot;Weekly tips, tricks and updates for Turbot customers.&quot;,&quot;logo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/0bc0c730-9a8a-401c-9db4-d132c3e6d4f5_300x300.png&quot;,&quot;author_id&quot;:18396950,&quot;theme_var_background_pop&quot;:&quot;#D10000&quot;,&quot;created_at&quot;:&quot;2021-01-06T19:06:38.895Z&quot;,&quot;rss_website_url&quot;:null,&quot;email_from_name&quot;:&quot;Turbot News&quot;,&quot;copyright&quot;:&quot;Turbot HQ, Inc.&quot;,&quot;founding_plan_name&quot;:null,&quot;community_enabled&quot;:true,&quot;invite_only&quot;:false,&quot;payments_state&quot;:&quot;disabled&quot;}}],&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null,&quot;inviteAccepted&quot;:true}],&quot;utm_campaign&quot;:null,&quot;belowTheFold&quot;:true,&quot;type&quot;:&quot;newsletter&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="EmbeddedPostToDOM"><a class="embedded-post" native="true" href="https://on.turbot.com/p/turbot-on-automated-snapshot-cleanup?utm_source=substack&amp;utm_campaign=post_embed&amp;utm_medium=web"><div class="embedded-post-header"><img class="embedded-post-publication-logo" src="https://substackcdn.com/image/fetch/$s_!p5XJ!,w_56,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0bc0c730-9a8a-401c-9db4-d132c3e6d4f5_300x300.png" loading="lazy"><span class="embedded-post-publication-name">[Turbot On]</span></div><div class="embedded-post-title-wrapper"><div class="embedded-post-title">[Turbot On] Automated Snapshot Cleanup</div></div><div class="embedded-post-body">One of the key benefits of working with IaaS services Amazon EBS, Amazon RDS, etc. is the ability to programmatically create backups and snapshots, but it can also become a source of unchecked cost if not watched closely. The AWS Backup service, first released in 2019, has the ability to automate backup scheduling and enforce retention policies, but man&#8230;</div><div class="embedded-post-cta-wrapper"><span class="embedded-post-cta">Read more</span></div><div class="embedded-post-meta">5 years ago &#183; 2 likes &#183; Bob Tordella</div></a></div><h3>Delete default VPCs in unused regions</h3><p>Did you know that AWS creates 17 VPCs in every new AWS account.  Yes, a VPC is created automatically in every AWS region with multiple subnets and public accessibility via an internet gateway.  Deleting these VPCs can create significant cost savings and cost avoidance.  </p><ul><li><p>If you use AWS Config or similar products that catalog cloud resources, removing these VPCs can reduce your usage of those services by lowering the number of resources you are tracking. </p></li><li><p>These VPCs are often mistakenly used to deploy resources to when using the AWS console, generating waste until discovered. Removing them early eliminates the technical debt and cost of cleaning them up later due to overlapping IP ranges.</p></li><li><p>These VPCs are also frequently used by malicious insiders to hide crypto mining or other personal projects, and we have seen these VPCs used by external bad actors when an account is compromised. With Turbot it is easy to delete them automatically:</p></li></ul><div class="embedded-post-wrap" data-attrs="{&quot;id&quot;:32811179,&quot;url&quot;:&quot;https://on.turbot.com/p/turbot-on-automatic-deletion-of-default&quot;,&quot;publication_id&quot;:256163,&quot;publication_name&quot;:&quot;[Turbot On]&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0bc0c730-9a8a-401c-9db4-d132c3e6d4f5_300x300.png&quot;,&quot;title&quot;:&quot;[Turbot On] Automatic deletion of default VPCs&quot;,&quot;truncated_body_text&quot;:&quot;For new AWS accounts, default VPCs with subnets in every AWS region are created automatically. AWS does this to make it easy for new users to get started quickly; however it&#8217;s a nuisance to manage for your next account and every one after that. Most enterprise customers have dozens, if not hundreds of accounts, and default VPCs add complexity as they a&#8230;&quot;,&quot;date&quot;:&quot;2021-02-22T15:47:23.920Z&quot;,&quot;like_count&quot;:2,&quot;comment_count&quot;:0,&quot;bylines&quot;:[{&quot;id&quot;:19112887,&quot;name&quot;:&quot;Bob Tordella&quot;,&quot;previous_name&quot;:null,&quot;photo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/9b15e9e7-88a4-429e-94e3-663ffa55dabb_442x353.png&quot;,&quot;bio&quot;:&quot;Turbot CRO. We provide Enterprise guardrails for Amazon Web Services, Azure, and Google Cloud: Achieve Agility, Ensure Control, Be Best Practice.&quot;,&quot;profile_set_up_at&quot;:&quot;2021-09-30T21:18:51.982Z&quot;,&quot;publicationUsers&quot;:[{&quot;id&quot;:16218,&quot;user_id&quot;:19112887,&quot;publication_id&quot;:256163,&quot;role&quot;:&quot;admin&quot;,&quot;public&quot;:true,&quot;is_primary&quot;:false,&quot;publication&quot;:{&quot;id&quot;:256163,&quot;name&quot;:&quot;[Turbot On]&quot;,&quot;subdomain&quot;:&quot;turboton&quot;,&quot;custom_domain&quot;:&quot;on.turbot.com&quot;,&quot;custom_domain_optional&quot;:false,&quot;hero_text&quot;:&quot;Weekly tips, tricks and updates for Turbot customers.&quot;,&quot;logo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/0bc0c730-9a8a-401c-9db4-d132c3e6d4f5_300x300.png&quot;,&quot;author_id&quot;:18396950,&quot;theme_var_background_pop&quot;:&quot;#D10000&quot;,&quot;created_at&quot;:&quot;2021-01-06T19:06:38.895Z&quot;,&quot;rss_website_url&quot;:null,&quot;email_from_name&quot;:&quot;Turbot News&quot;,&quot;copyright&quot;:&quot;Turbot HQ, Inc.&quot;,&quot;founding_plan_name&quot;:null,&quot;community_enabled&quot;:true,&quot;invite_only&quot;:false,&quot;payments_state&quot;:&quot;disabled&quot;}}],&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null,&quot;inviteAccepted&quot;:true}],&quot;utm_campaign&quot;:null,&quot;belowTheFold&quot;:true,&quot;type&quot;:&quot;newsletter&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="EmbeddedPostToDOM"><a class="embedded-post" native="true" href="https://on.turbot.com/p/turbot-on-automatic-deletion-of-default?utm_source=substack&amp;utm_campaign=post_embed&amp;utm_medium=web"><div class="embedded-post-header"><img class="embedded-post-publication-logo" src="https://substackcdn.com/image/fetch/$s_!p5XJ!,w_56,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0bc0c730-9a8a-401c-9db4-d132c3e6d4f5_300x300.png" loading="lazy"><span class="embedded-post-publication-name">[Turbot On]</span></div><div class="embedded-post-title-wrapper"><div class="embedded-post-title">[Turbot On] Automatic deletion of default VPCs</div></div><div class="embedded-post-body">For new AWS accounts, default VPCs with subnets in every AWS region are created automatically. AWS does this to make it easy for new users to get started quickly; however it&#8217;s a nuisance to manage for your next account and every one after that. Most enterprise customers have dozens, if not hundreds of accounts, and default VPCs add complexity as they a&#8230;</div><div class="embedded-post-cta-wrapper"><span class="embedded-post-cta">Read more</span></div><div class="embedded-post-meta">5 years ago &#183; 2 likes &#183; Bob Tordella</div></a></div><h3><strong>Remove multiple enabled CloudTrails per account</strong></h3><p>Did you know that your first AWS CloudTrail is free in each account, but you pay if you create multiple trails? Turbot can ensure that you have one global CloudTrail configured in each account and automatically disable additional trails. This setting will continuously monitor this and remove trails created by third party tools or misunderstanding developers.</p><h3><strong>Route53 TTL</strong></h3><p>If you configure a higher TTL for your DNS records, intermediate resolvers cache the records for longer time. As a result, there are fewer queries received by the name servers. Turbot can help you identify records with low TTL values, we suggest increasing the value to one day (86,400s) for production environments with static DNS, one hour (3,600s) for environments with more frequent changes.</p><h3><strong>Instance and volume type savings</strong></h3><p>There are two key strategies at play when considering automating optimization of instance and volume sizes.&nbsp;</p><p>1.&nbsp;&nbsp;&nbsp;&nbsp; Identifying existing non-optimized instance types</p><p>2.&nbsp;&nbsp;&nbsp;&nbsp; Preventing future use of non-optimized instance types.</p><p>Turbot can help with both; our automation can immediately stop (or terminate) usage of instance/volume types that are not approved for use in your cloud and reporting against our CMDB can help you identify where existing infrastructure could be optimized.</p><p>Key strategies here that Turbot can implement:</p><p>1.&nbsp;&nbsp;&nbsp;&nbsp; Enforce use of gp3 instead of gp2/io1 volume types. AWS's newer gp3 volumes are lower cost and higher performance for every price point against the older gp2 volume type, but the AWS console is still defaulting to gp2 instead. Use Turbot to ensure your developers are not leaving money on the table here and creating more technical debt. See:&nbsp;<a href="https://turbot.com/blog/2020/12/aws-ebs-cost-savings/">https://turbot.com/blog/2020/12/aws-ebs-cost-savings/</a></p><p>2.&nbsp;&nbsp;&nbsp;&nbsp; If your workloads support running on ARM processors, you can save up to 40% by switching instance types from power hungry legacy x86 workloads. Turbot can help you identify candidates for switching and automatically stop (or terminate) new instances created using older instance types.</p><p>3.&nbsp;&nbsp;&nbsp;&nbsp; Has your organization purchased reserved instances of a certain class? Use Turbot to ensure dev teams are using the correct class and size of instance to maximize usage of your reserved instances.</p><p>4.&nbsp;&nbsp;&nbsp;&nbsp; Prevent usage of non-standard high-cost instance types by mistake. All three cloud providers have introduced a bevy of massive scale instance types for high performance computing needs (at eye-watering price points). Make sure your dev teams don&#8217;t accidentally spin up that $100/hr instance using Turbot's guardrails to limit provisioning to only approved instance types. This prevents accidental use, and it is super simple to create an exception when a team has budget and need for the extra horse power.</p><h3><strong>Account-based budgeting</strong></h3><p>Turbot can monitor the month-to-date spend for AWS accounts and take actions when accounts are trending to overspend. This can take the form of creating an over-budget alert, preventing new resources from being created or even deleting existing resources from sandbox or playground accounts once a threshold has been exceeded.</p><h3><strong>Why real-time cost remediation?</strong></h3><p>No matter your organizations maturity level with cloud, reducing costs is something that will always be a priority. Using automation to enforce cost controls allows your operations team to focus on the next opportunity while your current automations continuously save you money. When cost savings initiatives are manual, you only get a one-time improvement and the amount of savings will always be limited by the number of people you can have executing those processes.</p><p>If you need any assistance getting this configured in your environment, please reach out to&nbsp;<a href="mailto:support@turbot.com">Turbot Support</a>!</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://on.turbot.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading [Turbot On]! Sign-up to receive notifications of new posts.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Turbot 2022 Recap]]></title><description><![CDATA[Look back at our top feature releases and customer stories from 2022]]></description><link>https://on.turbot.com/p/turbot-2022-recap</link><guid isPermaLink="false">https://on.turbot.com/p/turbot-2022-recap</guid><dc:creator><![CDATA[Bob Tordella]]></dc:creator><pubDate>Wed, 11 Jan 2023 13:21:57 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!738G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ac41f7d-b2a3-4cae-b8a4-9aa02433cdfa_1092x519.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!738G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ac41f7d-b2a3-4cae-b8a4-9aa02433cdfa_1092x519.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!738G!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ac41f7d-b2a3-4cae-b8a4-9aa02433cdfa_1092x519.png 424w, https://substackcdn.com/image/fetch/$s_!738G!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ac41f7d-b2a3-4cae-b8a4-9aa02433cdfa_1092x519.png 848w, https://substackcdn.com/image/fetch/$s_!738G!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ac41f7d-b2a3-4cae-b8a4-9aa02433cdfa_1092x519.png 1272w, https://substackcdn.com/image/fetch/$s_!738G!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ac41f7d-b2a3-4cae-b8a4-9aa02433cdfa_1092x519.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!738G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ac41f7d-b2a3-4cae-b8a4-9aa02433cdfa_1092x519.png" width="1092" height="519" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1ac41f7d-b2a3-4cae-b8a4-9aa02433cdfa_1092x519.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:519,&quot;width&quot;:1092,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:969105,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!738G!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ac41f7d-b2a3-4cae-b8a4-9aa02433cdfa_1092x519.png 424w, https://substackcdn.com/image/fetch/$s_!738G!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ac41f7d-b2a3-4cae-b8a4-9aa02433cdfa_1092x519.png 848w, https://substackcdn.com/image/fetch/$s_!738G!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ac41f7d-b2a3-4cae-b8a4-9aa02433cdfa_1092x519.png 1272w, https://substackcdn.com/image/fetch/$s_!738G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ac41f7d-b2a3-4cae-b8a4-9aa02433cdfa_1092x519.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>It&#8217;s been a busy 2022 at Turbot. We launched Turbot Quick Actions, support for new compliance frameworks, added support for new cloud services, and hundreds of new policies and controls.  We ended the year with over 250 updates to <a href="https://turbot.com/v5/mods">Turbot Mods</a>, and over 35 releases of <a href="https://turbot.com/v5/docs/releases/te">Turbot Enterprise</a> (TE stack). In addition to all the great work we accomplished on Turbot in 2022, we also had <a href="https://steampipe.io/blog/2022-wrapup">a lot to celebrate</a> with our open source project <a href="https://steampipe.io">Steampipe</a>.</p><p>We&#8217;re constantly iterating on Turbot based on your voice of customer feedback and while we&#8217;re excited to bring you even more innovation in 2023, it&#8217;s worth reflecting on all of the new capabilities and use cases that have been unlocked over the last 12 months.&nbsp;</p><p>Here are some of the highlights over the year.</p><h2><strong>Quick Actions</strong></h2><p>Our customers love using Turbot automation to find and fix problems in real-time across hundreds of cloud service accounts. However, there are many situations where the cloud team wants to <strong>quickly take a specific one-time action on a resource</strong> while remaining in the context of their multi-cloud compliance dashboard.</p><p><a href="https://on.turbot.com/p/turbot-on-quick-actions">Quick Actions</a> enable DevOps engineers to instantly remediate cloud configuration issues (e.g. enable encryption on a resource), snooze compliance alarms, or take operational actions (e.g. tag a resource, start/stop an instance) from the Turbot Compliance Dashboard.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_iv3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4d922c96-cf6c-478a-9bc6-98fc1caf71a2_2408x1646.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_iv3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4d922c96-cf6c-478a-9bc6-98fc1caf71a2_2408x1646.png 424w, https://substackcdn.com/image/fetch/$s_!_iv3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4d922c96-cf6c-478a-9bc6-98fc1caf71a2_2408x1646.png 848w, https://substackcdn.com/image/fetch/$s_!_iv3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4d922c96-cf6c-478a-9bc6-98fc1caf71a2_2408x1646.png 1272w, https://substackcdn.com/image/fetch/$s_!_iv3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4d922c96-cf6c-478a-9bc6-98fc1caf71a2_2408x1646.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_iv3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4d922c96-cf6c-478a-9bc6-98fc1caf71a2_2408x1646.png" width="1456" height="995" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/4d922c96-cf6c-478a-9bc6-98fc1caf71a2_2408x1646.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:995,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Screen Shot of Quick Actions context menu.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Screen Shot of Quick Actions context menu." title="Screen Shot of Quick Actions context menu." srcset="https://substackcdn.com/image/fetch/$s_!_iv3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4d922c96-cf6c-478a-9bc6-98fc1caf71a2_2408x1646.png 424w, https://substackcdn.com/image/fetch/$s_!_iv3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4d922c96-cf6c-478a-9bc6-98fc1caf71a2_2408x1646.png 848w, https://substackcdn.com/image/fetch/$s_!_iv3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4d922c96-cf6c-478a-9bc6-98fc1caf71a2_2408x1646.png 1272w, https://substackcdn.com/image/fetch/$s_!_iv3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4d922c96-cf6c-478a-9bc6-98fc1caf71a2_2408x1646.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Cloud Compliance Frameworks</strong></h2><p>Customers often map Turbot controls to their own Governance Risk Compliance (GRC) tools, and use the resulting evidence to prove continuous adherence to internal controls or external standards. Throughout the year we started to port over control frameworks from Steampipe into Turbot.&nbsp; Along with AWS, Azure &amp; GCP CIS benchmarks already supported by Turbot, this year we added support <a href="https://on.turbot.com/p/turbot-on-pci-compliance-controls">Payment Card Industry Data Security Standard (PCI DSS)</a>, <a href="https://on.turbot.com/p/turbot-on-hipaa-compliance-controls">Health Insurance Portability and Accountability (HIPAA)</a>, and <a href="https://on.turbot.com/p/turbot-on-nist-800-53-controls">NIST 800-53</a> controls.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jQKN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe744fe50-889f-4ef5-8026-9caf74baed77_1237x677.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jQKN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe744fe50-889f-4ef5-8026-9caf74baed77_1237x677.png 424w, https://substackcdn.com/image/fetch/$s_!jQKN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe744fe50-889f-4ef5-8026-9caf74baed77_1237x677.png 848w, https://substackcdn.com/image/fetch/$s_!jQKN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe744fe50-889f-4ef5-8026-9caf74baed77_1237x677.png 1272w, https://substackcdn.com/image/fetch/$s_!jQKN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe744fe50-889f-4ef5-8026-9caf74baed77_1237x677.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jQKN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe744fe50-889f-4ef5-8026-9caf74baed77_1237x677.png" width="1237" height="677" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/e744fe50-889f-4ef5-8026-9caf74baed77_1237x677.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:677,&quot;width&quot;:1237,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jQKN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe744fe50-889f-4ef5-8026-9caf74baed77_1237x677.png 424w, https://substackcdn.com/image/fetch/$s_!jQKN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe744fe50-889f-4ef5-8026-9caf74baed77_1237x677.png 848w, https://substackcdn.com/image/fetch/$s_!jQKN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe744fe50-889f-4ef5-8026-9caf74baed77_1237x677.png 1272w, https://substackcdn.com/image/fetch/$s_!jQKN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe744fe50-889f-4ef5-8026-9caf74baed77_1237x677.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Custom Approved Controls</strong></h2><p>The <a href="https://turbot.com/v5/docs/concepts/guardrails/approved">Approved guardrail</a> checks the status of the defined Approved sub-policies for the resource. If the resource is not approved according to <em>any</em> of these policies, an alarm is raised and takes the defined enforcement action (e.g. stops the resource, deletes the resource, etc).</p><p><a href="https://turbot.com/v5/docs/concepts/guardrails/approved#custom-checks">Custom checks</a> were added to be part of the Approved control evaluation, and allow for custom messages to be added which are then displayed in the control details table.</p><p>This provides a middle ground to customers who need more flexibility to define their own control logic with custom messaging without requiring a <a href="https://turbot.com/v5/docs/7-minute-labs/custom-mod">Custom Mod</a> or a Turbot mod to extend the feature.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ndn3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec14d6d5-5469-4f74-90a8-47fd1023f0d5_1336x809.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ndn3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec14d6d5-5469-4f74-90a8-47fd1023f0d5_1336x809.png 424w, https://substackcdn.com/image/fetch/$s_!ndn3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec14d6d5-5469-4f74-90a8-47fd1023f0d5_1336x809.png 848w, https://substackcdn.com/image/fetch/$s_!ndn3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec14d6d5-5469-4f74-90a8-47fd1023f0d5_1336x809.png 1272w, https://substackcdn.com/image/fetch/$s_!ndn3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec14d6d5-5469-4f74-90a8-47fd1023f0d5_1336x809.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ndn3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec14d6d5-5469-4f74-90a8-47fd1023f0d5_1336x809.png" width="1336" height="809" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ec14d6d5-5469-4f74-90a8-47fd1023f0d5_1336x809.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:809,&quot;width&quot;:1336,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:110375,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ndn3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec14d6d5-5469-4f74-90a8-47fd1023f0d5_1336x809.png 424w, https://substackcdn.com/image/fetch/$s_!ndn3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec14d6d5-5469-4f74-90a8-47fd1023f0d5_1336x809.png 848w, https://substackcdn.com/image/fetch/$s_!ndn3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec14d6d5-5469-4f74-90a8-47fd1023f0d5_1336x809.png 1272w, https://substackcdn.com/image/fetch/$s_!ndn3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec14d6d5-5469-4f74-90a8-47fd1023f0d5_1336x809.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>New &amp; Improved Turbot</strong></h2><ul><li><p>Performance &amp; scale:</p><ul><li><p>Made significant performance improvements on the database infrastructure through use of Graviton instance types and GP3 storage.</p></li><li><p>Optimized indexes for increased UI performance.</p></li><li><p>Targeted performance improvements for resource activity views, mod uploads, user grants deletion and the permissions detail views.</p></li><li><p>Added an events priority queue for actions initiated via the UI, that allows these actions to take precedence over the cloud event backlog.</p></li><li><p>Added log warnings when a query is using fuzzy matching, to alert users to poor performing queries.</p></li></ul></li><li><p>New improvements:</p><ul><li><p>Improved the state reasons and details in control messages.</p></li><li><p>Added v5 support for <a href="https://turbot.com/v5/docs/integrations/aws/permissions/user-mode">IAM user mode</a>.</p></li><li><p>Added v5 support for <a href="https://turbot.com/v5/docs/guides/directories/ldap-ldaps">LDAP integrations</a>.</p></li></ul></li><li><p>New capabilities - we are very proud to have the broadest coverage of any CSPM tool on the market.</p><ul><li><p><strong>Turbot now supports 734 resource types, 3,988 control types and 9,313 policy types (22% increase over 2021).</strong></p></li><li><p>79 updated and 10 new mods in 2022.</p></li><li><p>New compliance mods included: Azure CIS v1.2, AWS HIPAA, AWS PCI v3.2.1, AWS NIST 800-53.</p></li></ul></li></ul><h2><strong>Our customers continue to do amazing things</strong></h2><p>The thing that got our team most excited in 2022 was seeing our customers do super cool stuff with Turbot.  Here are a few interesting automation use cases we saw in 2022:</p><ul><li><p>Using Turbot to discover and remove 600,000 unneeded EBS snapshots.</p></li><li><p>Using a custom Service Now workflow to feed project cost center information into Turbot that was used to tag cloud resources.</p></li><li><p>Using <a href="https://turbot.com/v5/docs/guides/iam/advanced">AWS &gt; IAM &gt; Role &gt; Approved</a> custom calculated policy to allow use of GitHub Actions only from specific GitHub repos owned by the organization.</p></li><li><p>Pulling account tagging metadata from AWS organizations to tag all resources in an account with the same cost center metadata.</p></li><li><p>Restricting cross-account bucket access to specific OU&#8217;s in an organization by using Turbot to automatically set bucket policy restrictions using `aws:PrincipalOrgPaths` condition keys.</p></li><li><p>Using <a href="https://turbot.com/v5/docs/guides/firehose">Turbot Firehose</a> to get a real-time streaming view of multi-cloud resource change over time.</p></li><li><p>Using <a href="https://turbot.com/v5/docs/concepts/iam/permissions">Turbot&#8217;s RBAC</a> to manage time-based access to raw data at the AWS level for 600+ researchers.</p></li></ul><h2><strong>Off to the races in 2023</strong></h2><p>We have some exciting new features that are just around the corner and look forward to showing them off soon.  Thanks to all who used and supported Turbot &amp; Steampipe in 2022. Your engagement fuels our passion to keep innovating, and will continue to inspire us in 2023!</p>]]></content:encoded></item><item><title><![CDATA[[Turbot On] NIST 800-53 Controls]]></title><description><![CDATA[Evaluate NIST 800-53 compliance for all your AWS accounts.]]></description><link>https://on.turbot.com/p/turbot-on-nist-800-53-controls</link><guid isPermaLink="false">https://on.turbot.com/p/turbot-on-nist-800-53-controls</guid><dc:creator><![CDATA[Bob Tordella]]></dc:creator><pubDate>Tue, 29 Nov 2022 14:31:33 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!yMhs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F26f07645-77b4-4bb8-a07a-3f10094426f9_5472x3078.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yMhs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F26f07645-77b4-4bb8-a07a-3f10094426f9_5472x3078.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yMhs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F26f07645-77b4-4bb8-a07a-3f10094426f9_5472x3078.png 424w, https://substackcdn.com/image/fetch/$s_!yMhs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F26f07645-77b4-4bb8-a07a-3f10094426f9_5472x3078.png 848w, https://substackcdn.com/image/fetch/$s_!yMhs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F26f07645-77b4-4bb8-a07a-3f10094426f9_5472x3078.png 1272w, https://substackcdn.com/image/fetch/$s_!yMhs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F26f07645-77b4-4bb8-a07a-3f10094426f9_5472x3078.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yMhs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F26f07645-77b4-4bb8-a07a-3f10094426f9_5472x3078.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/26f07645-77b4-4bb8-a07a-3f10094426f9_5472x3078.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:6714209,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yMhs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F26f07645-77b4-4bb8-a07a-3f10094426f9_5472x3078.png 424w, https://substackcdn.com/image/fetch/$s_!yMhs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F26f07645-77b4-4bb8-a07a-3f10094426f9_5472x3078.png 848w, https://substackcdn.com/image/fetch/$s_!yMhs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F26f07645-77b4-4bb8-a07a-3f10094426f9_5472x3078.png 1272w, https://substackcdn.com/image/fetch/$s_!yMhs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F26f07645-77b4-4bb8-a07a-3f10094426f9_5472x3078.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Turbot includes thousands of prescriptive cloud controls to ensure cloud environments are secure and cost-optimized. These controls quickly detect issues as they occur and instantly correct misconfigurations. Customers often map Turbot controls to their own Governance Risk Compliance (GRC) tools, and use the resulting evidence to prove continuous adherence to internal controls or external standards such as <a href="https://turbot.com/blog/2020/05/cis-securesuite-member/">Center for Internet Security (CIS)</a>, <a href="https://on.turbot.com/p/turbot-on-hipaa-compliance-controls">HIPAA</a>, <a href="https://on.turbot.com/p/turbot-on-pci-compliance-controls">PCI</a>, <a href="https://on.turbot.com/p/turbot-on-automated-soc2-compliance">SOC2</a>, etc.&nbsp;</p><p>Over the last year Turbot has open-sourced <a href="https://steampipe.io/">Steampipe.io</a>, a tool that enables cloud engineers to easily query &amp; report across their cloud, code, logs, and more, using the standard language of data: SQL. Steampipe includes thousands of ready-to-use controls and dashboards that deliver insights into your cloud data. These controls and dashboards leverage a suite of plugins that translate cloud APIs into Postgres tables. One of those plugins, by the way, translates the <a href="https://hub.steampipe.io/plugins/turbot/turbot">Turbot v5 API into SQL-queryable tables</a>!</p><p>Cloud teams have asked Turbot to also include industry standards within the Turbot platform. We started by open-sourcing thousands of compliance controls, and enlisting the Steampipe community to provide feedback and contributions. Based on community feedback, we are now starting to port these control frameworks into Turbot.&nbsp; Our first addition in Turbot was the <a href="https://on.turbot.com/p/turbot-on-pci-compliance-controls">Payment Card Industry Data Security Standard (PCI DSS) v3.2.1 standard for AWS</a>, then the <a href="https://on.turbot.com/p/turbot-on-hipaa-compliance-controls">Health Insurance Portability and Accountability (HIPAA) standard for AWS</a>. Note: When mapping to external standards, Turbot leverages either the published industry standard mapping or the <a href="https://docs.aws.amazon.com/config/latest/developerguide/operational-best-practices-for-nist-800-53_rev_4.html">mapping provided by each cloud provider</a>. We are excited to add the NIST 800-53 controls to the platform to complement our existing HIPAA, PCI &amp; CIS Controls, along with AWS, Azure &amp; GCP CIS benchmarks.</p><p><strong>This week&#8217;s [Turbot On] will look at how to enable NIST 800-53 controls across all your AWS accounts in Turbot.</strong></p><h2><strong>Traditional Workflow</strong></h2><p>There are various cloud-native and 3rd-party tools to evaluate cloud infrastructure NIST 800-53 compliance. However cloud-native tools generally work with only one cloud provider, and only do periodic scans.&nbsp; 3rd-party tools may support multiple cloud providers, but fall short on benchmark coverage and, again, scan and report only periodically, missing real-time changes in your environment.&nbsp; These tools often work on a per-account basis, without delivering resource-level granularity. And they are limited in their ability to manage the time-based exceptions that enable you to handle the nuances in your organization.</p><h2><strong>Get it done with Turbot</strong></h2><p>In Turbot, NIST 800-53 guardrails are readily available to control your cloud resource configurations.&nbsp; These guardrails work similar to others, continuously evaluating adherence as changes to your cloud resources occur.&nbsp; First, make sure you have the `<a href="https://turbot.com/v5/mods/turbot/aws-nist-800-53/inspect">@turbot/aws-nist-800-53</a>` mod installed and any <a href="https://turbot.com/v5/mods/turbot/aws-nist-800-53/dependencies">dependent mods</a> installed in your workspace.&nbsp; Then you can enable NIST 800-53 through the following Turbot policy in just a few clicks: `AWS &gt; NIST 800-53`:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wS0R!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3022b3e3-0f6a-45f2-bb32-1e1e63fa54f4_1365x1134.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wS0R!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3022b3e3-0f6a-45f2-bb32-1e1e63fa54f4_1365x1134.png 424w, https://substackcdn.com/image/fetch/$s_!wS0R!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3022b3e3-0f6a-45f2-bb32-1e1e63fa54f4_1365x1134.png 848w, https://substackcdn.com/image/fetch/$s_!wS0R!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3022b3e3-0f6a-45f2-bb32-1e1e63fa54f4_1365x1134.png 1272w, https://substackcdn.com/image/fetch/$s_!wS0R!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3022b3e3-0f6a-45f2-bb32-1e1e63fa54f4_1365x1134.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wS0R!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3022b3e3-0f6a-45f2-bb32-1e1e63fa54f4_1365x1134.png" width="1365" height="1134" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/3022b3e3-0f6a-45f2-bb32-1e1e63fa54f4_1365x1134.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1134,&quot;width&quot;:1365,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:67219,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wS0R!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3022b3e3-0f6a-45f2-bb32-1e1e63fa54f4_1365x1134.png 424w, https://substackcdn.com/image/fetch/$s_!wS0R!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3022b3e3-0f6a-45f2-bb32-1e1e63fa54f4_1365x1134.png 848w, https://substackcdn.com/image/fetch/$s_!wS0R!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3022b3e3-0f6a-45f2-bb32-1e1e63fa54f4_1365x1134.png 1272w, https://substackcdn.com/image/fetch/$s_!wS0R!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3022b3e3-0f6a-45f2-bb32-1e1e63fa54f4_1365x1134.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Setting the configuration via the <a href="https://turbot.com/v5/docs/reference/terraform">Turbot Terraform Provider</a> is just as simple:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aY8a!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5df67570-1833-42cb-a8a2-715282842d7c_1096x302.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aY8a!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5df67570-1833-42cb-a8a2-715282842d7c_1096x302.png 424w, https://substackcdn.com/image/fetch/$s_!aY8a!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5df67570-1833-42cb-a8a2-715282842d7c_1096x302.png 848w, https://substackcdn.com/image/fetch/$s_!aY8a!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5df67570-1833-42cb-a8a2-715282842d7c_1096x302.png 1272w, https://substackcdn.com/image/fetch/$s_!aY8a!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5df67570-1833-42cb-a8a2-715282842d7c_1096x302.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aY8a!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5df67570-1833-42cb-a8a2-715282842d7c_1096x302.png" width="1096" height="302" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/5df67570-1833-42cb-a8a2-715282842d7c_1096x302.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:302,&quot;width&quot;:1096,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:50482,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!aY8a!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5df67570-1833-42cb-a8a2-715282842d7c_1096x302.png 424w, https://substackcdn.com/image/fetch/$s_!aY8a!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5df67570-1833-42cb-a8a2-715282842d7c_1096x302.png 848w, https://substackcdn.com/image/fetch/$s_!aY8a!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5df67570-1833-42cb-a8a2-715282842d7c_1096x302.png 1272w, https://substackcdn.com/image/fetch/$s_!aY8a!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5df67570-1833-42cb-a8a2-715282842d7c_1096x302.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>After enabling this policy, Turbot will immediately evaluate all applicable resources compliance with NIST 800-53.&nbsp; You can view your controls across AWS services:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ufju!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F67aa4d0d-3461-4ad8-bb4f-d0610127d8c2_1060x698.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ufju!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F67aa4d0d-3461-4ad8-bb4f-d0610127d8c2_1060x698.png 424w, https://substackcdn.com/image/fetch/$s_!Ufju!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F67aa4d0d-3461-4ad8-bb4f-d0610127d8c2_1060x698.png 848w, https://substackcdn.com/image/fetch/$s_!Ufju!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F67aa4d0d-3461-4ad8-bb4f-d0610127d8c2_1060x698.png 1272w, https://substackcdn.com/image/fetch/$s_!Ufju!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F67aa4d0d-3461-4ad8-bb4f-d0610127d8c2_1060x698.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ufju!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F67aa4d0d-3461-4ad8-bb4f-d0610127d8c2_1060x698.png" width="1060" height="698" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/67aa4d0d-3461-4ad8-bb4f-d0610127d8c2_1060x698.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:698,&quot;width&quot;:1060,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:61087,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ufju!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F67aa4d0d-3461-4ad8-bb4f-d0610127d8c2_1060x698.png 424w, https://substackcdn.com/image/fetch/$s_!Ufju!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F67aa4d0d-3461-4ad8-bb4f-d0610127d8c2_1060x698.png 848w, https://substackcdn.com/image/fetch/$s_!Ufju!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F67aa4d0d-3461-4ad8-bb4f-d0610127d8c2_1060x698.png 1272w, https://substackcdn.com/image/fetch/$s_!Ufju!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F67aa4d0d-3461-4ad8-bb4f-d0610127d8c2_1060x698.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Drill further into subsections:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4pbQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd5873fe-e45d-4276-a776-d6c527a33c1f_868x532.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4pbQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd5873fe-e45d-4276-a776-d6c527a33c1f_868x532.png 424w, https://substackcdn.com/image/fetch/$s_!4pbQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd5873fe-e45d-4276-a776-d6c527a33c1f_868x532.png 848w, https://substackcdn.com/image/fetch/$s_!4pbQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd5873fe-e45d-4276-a776-d6c527a33c1f_868x532.png 1272w, https://substackcdn.com/image/fetch/$s_!4pbQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd5873fe-e45d-4276-a776-d6c527a33c1f_868x532.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4pbQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd5873fe-e45d-4276-a776-d6c527a33c1f_868x532.png" width="868" height="532" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/dd5873fe-e45d-4276-a776-d6c527a33c1f_868x532.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:532,&quot;width&quot;:868,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:38033,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4pbQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd5873fe-e45d-4276-a776-d6c527a33c1f_868x532.png 424w, https://substackcdn.com/image/fetch/$s_!4pbQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd5873fe-e45d-4276-a776-d6c527a33c1f_868x532.png 848w, https://substackcdn.com/image/fetch/$s_!4pbQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd5873fe-e45d-4276-a776-d6c527a33c1f_868x532.png 1272w, https://substackcdn.com/image/fetch/$s_!4pbQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd5873fe-e45d-4276-a776-d6c527a33c1f_868x532.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Analyze which specific resources are impacted per control:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3YBU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F72051b22-a999-484b-a5ad-bf7bfed2eb9d_999x410.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3YBU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F72051b22-a999-484b-a5ad-bf7bfed2eb9d_999x410.png 424w, https://substackcdn.com/image/fetch/$s_!3YBU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F72051b22-a999-484b-a5ad-bf7bfed2eb9d_999x410.png 848w, https://substackcdn.com/image/fetch/$s_!3YBU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F72051b22-a999-484b-a5ad-bf7bfed2eb9d_999x410.png 1272w, https://substackcdn.com/image/fetch/$s_!3YBU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F72051b22-a999-484b-a5ad-bf7bfed2eb9d_999x410.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3YBU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F72051b22-a999-484b-a5ad-bf7bfed2eb9d_999x410.png" width="999" height="410" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/72051b22-a999-484b-a5ad-bf7bfed2eb9d_999x410.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:410,&quot;width&quot;:999,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:59727,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3YBU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F72051b22-a999-484b-a5ad-bf7bfed2eb9d_999x410.png 424w, https://substackcdn.com/image/fetch/$s_!3YBU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F72051b22-a999-484b-a5ad-bf7bfed2eb9d_999x410.png 848w, https://substackcdn.com/image/fetch/$s_!3YBU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F72051b22-a999-484b-a5ad-bf7bfed2eb9d_999x410.png 1272w, https://substackcdn.com/image/fetch/$s_!3YBU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F72051b22-a999-484b-a5ad-bf7bfed2eb9d_999x410.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Make it happen</strong></h2><p>See for yourself on how easy it is to view your NIST 800-53 requirements across your cloud resources.&nbsp; If you need any assistance please reach out to <a href="mailto:support@turbot.com">Turbot Support</a>, and keep an eye on your inbox for another <a href="https://on.turbot.com/">[Turbot On]</a> post in the near future!</p><p>Cheers,</p><p>Bob</p>]]></content:encoded></item><item><title><![CDATA[[Turbot On] Quick Actions]]></title><description><![CDATA[Fix compliance and operational issues with a push of a button.]]></description><link>https://on.turbot.com/p/turbot-on-quick-actions</link><guid isPermaLink="false">https://on.turbot.com/p/turbot-on-quick-actions</guid><dc:creator><![CDATA[David Boeke]]></dc:creator><pubDate>Thu, 11 Aug 2022 11:27:23 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!3toQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F42cfb750-4a33-4b98-bab3-c3d9ec963c21_1820x1024.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3toQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F42cfb750-4a33-4b98-bab3-c3d9ec963c21_1820x1024.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3toQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F42cfb750-4a33-4b98-bab3-c3d9ec963c21_1820x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!3toQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F42cfb750-4a33-4b98-bab3-c3d9ec963c21_1820x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!3toQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F42cfb750-4a33-4b98-bab3-c3d9ec963c21_1820x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!3toQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F42cfb750-4a33-4b98-bab3-c3d9ec963c21_1820x1024.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3toQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F42cfb750-4a33-4b98-bab3-c3d9ec963c21_1820x1024.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/42cfb750-4a33-4b98-bab3-c3d9ec963c21_1820x1024.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:643468,&quot;alt&quot;:&quot;Header image of a control panel with hundreds of colorful buttons and a single finger pressing one.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Header image of a control panel with hundreds of colorful buttons and a single finger pressing one." title="Header image of a control panel with hundreds of colorful buttons and a single finger pressing one." srcset="https://substackcdn.com/image/fetch/$s_!3toQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F42cfb750-4a33-4b98-bab3-c3d9ec963c21_1820x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!3toQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F42cfb750-4a33-4b98-bab3-c3d9ec963c21_1820x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!3toQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F42cfb750-4a33-4b98-bab3-c3d9ec963c21_1820x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!3toQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F42cfb750-4a33-4b98-bab3-c3d9ec963c21_1820x1024.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>For the last eight years, Turbot has focused on remediation of operational and compliance issues at enterprise scale. Our customers love using Turbot automation to find and fix problems in real-time across hundreds of cloud service accounts. However, there are many situations where cloud professionals want to <strong>quickly take a specific one-time action on a resource</strong> while remaining in the context of their multi-cloud compliance dashboard.</p><h2>Introducing Quick Actions</h2><p>Now generally available in Turbot v5.39.0, Quick Actions enable DevOps engineers to instantly remediate cloud configuration issues (e.g. enable encryption on a resource), snooze compliance alarms, or take operational actions (e.g. tag a resource, start/stop an instance) from the Turbot Compliance Dashboard.</p><p>Action types are specific to the service and the resource, meaning that S3 Buckets support different actions than EC2 instances. After enabling Quick Actions in your workspace (see below), you can browse a list of available actions for a given resource by clicking on the orange &#8220;Actions&#8221; button (located in the top right of each resource detail page):</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_iv3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4d922c96-cf6c-478a-9bc6-98fc1caf71a2_2408x1646.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_iv3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4d922c96-cf6c-478a-9bc6-98fc1caf71a2_2408x1646.png 424w, https://substackcdn.com/image/fetch/$s_!_iv3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4d922c96-cf6c-478a-9bc6-98fc1caf71a2_2408x1646.png 848w, https://substackcdn.com/image/fetch/$s_!_iv3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4d922c96-cf6c-478a-9bc6-98fc1caf71a2_2408x1646.png 1272w, https://substackcdn.com/image/fetch/$s_!_iv3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4d922c96-cf6c-478a-9bc6-98fc1caf71a2_2408x1646.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_iv3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4d922c96-cf6c-478a-9bc6-98fc1caf71a2_2408x1646.png" width="1456" height="995" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/4d922c96-cf6c-478a-9bc6-98fc1caf71a2_2408x1646.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:995,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1307400,&quot;alt&quot;:&quot;Screen Shot of Quick Actions context menu.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Screen Shot of Quick Actions context menu." title="Screen Shot of Quick Actions context menu." srcset="https://substackcdn.com/image/fetch/$s_!_iv3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4d922c96-cf6c-478a-9bc6-98fc1caf71a2_2408x1646.png 424w, https://substackcdn.com/image/fetch/$s_!_iv3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4d922c96-cf6c-478a-9bc6-98fc1caf71a2_2408x1646.png 848w, https://substackcdn.com/image/fetch/$s_!_iv3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4d922c96-cf6c-478a-9bc6-98fc1caf71a2_2408x1646.png 1272w, https://substackcdn.com/image/fetch/$s_!_iv3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4d922c96-cf6c-478a-9bc6-98fc1caf71a2_2408x1646.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Dropdown menu on resource with available actions.</figcaption></figure></div><h2><strong>Traditional Workflow</strong></h2><p>The Turbot console is a powerful tool for exploring cloud resources across large multi-account environments. In the past, when cloud teams discovered an issue within their environment using Turbot alarms, they would have to make a choice between leaving the compliance dashboard and addressing the issue in another tool, or configuring Turbot policies to remediate the problem via automation.</p><p>The choice to fix the issue manually forces the DevOps engineer to&nbsp;switch context from the CMDB and dashboard into other tools to apply the change. By removing that cognitive load, we make that same engineer more productive and effective.</p><h2>Make it green&#8482; with Turbot</h2><p>Now with Quick Actions, the most common functions required by cloud operations teams can be executed immediately, without context switching. The result is increased operator productivity <strong>leading to a&nbsp;clean (all green) compliance dashboard</strong> with full audit trail. The list of available quick actions is growing weekly, and will continue to do so based on customer feedback., Here is a short list of the currently supported resource types across AWS, GCP &amp; Azure:</p><p><strong>Amazon Web Services</strong></p><ul><li><p>EC2 Instances</p></li><li><p>EC2 Volumes &amp; Snapshots</p></li><li><p>Auto-Scaling &amp; Target Groups</p></li><li><p>Load Balancers (All types)</p></li><li><p>Load Balancer Listeners</p></li><li><p>Key Pairs</p></li><li><p>Launch Configurations</p></li><li><p>Launch Template &amp; Versions</p></li><li><p>IAM Users, Roles, Groups</p></li><li><p>Access Keys</p></li><li><p>IAM Policies, Inline Policies</p></li><li><p>Server Certificates</p></li><li><p>KMS Keys</p></li><li><p>Lambda Functions</p></li><li><p>Lambda Alias &amp; Versions</p></li><li><p>RDS DB Clusters &amp; Instances</p></li><li><p>DB Snapshots</p></li><li><p>DB Parameter Groups</p></li><li><p>DB Option &amp; Subnet Groups</p></li><li><p>S3 Buckets</p></li><li><p>SNS Topics &amp; Subscriptions</p></li><li><p>SQS Queues</p></li></ul><p><strong>Google Cloud Platform</strong></p><ul><li><p>Projects</p></li><li><p>Compute Instances</p></li><li><p>Compute Image</p></li><li><p>Instance Templates</p></li><li><p>Node Groups &amp; Templates</p></li><li><p>Compute Health Check</p></li><li><p>HTTPS Health Check</p></li><li><p>Region Health Check</p></li><li><p>Compute Disk</p></li><li><p>Regional Disks</p></li><li><p>Compute Snapshots</p></li></ul><p><strong>Azure Cloud</strong></p><ul><li><p>Virtual Machines</p></li><li><p>Images</p></li><li><p>Snapshots</p></li><li><p>Disk Encryption Sets</p></li><li><p>Compute Availability Sets</p></li><li><p>Compute Disks</p></li><li><p>Virtual Networks</p></li><li><p>Application Security Groups</p></li><li><p>Network Security Groups</p></li><li><p>Network Interface</p></li><li><p>Public IP Addresses</p></li><li><p>Route Tables</p></li><li><p>Subnets</p></li></ul><h2>Typical use cases</h2><ol><li><p><strong>Start/Stop Instances and Databases</strong> &#8211; Forgot to turn off that m5.16xlarge you were testing on last week? Oops! Shut it down right now.</p></li><li><p><strong>Delete Resources</strong> &#8211; Found 90TB of three year old EC2 snapshots? Clean &#8216;em up as you identify them.</p></li><li><p><strong>Snooze Alarms</strong> &#8211; Give that critical app team 90 days of runway to clean up their environment by snoozing their alarms.</p></li><li><p><strong>Tag resources</strong> &#8211; Instantly apply your custom tagging template to the untagged resource you just found.</p></li><li><p><strong>Enable Encryption</strong> &#8211; Found a rogue bucket without default encryption? Turn it back on without breaking a sweat.</p></li></ol><h2><strong>Get started</strong> with Quick Actions</h2><p>The Quick Action feature is available to all Turbot SaaS and Enterprise customers on version 5.39.0 or higher. To enable quick actions in your Turbot workspace, simply set the policy: <code>Turbot &gt; Quick Actions &gt; Enabled == "Enabled" </code>for a single account or the entire environment.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N-Td!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F48137b66-60cd-435d-b637-231093fee8ef_2398x1484.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N-Td!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F48137b66-60cd-435d-b637-231093fee8ef_2398x1484.png 424w, https://substackcdn.com/image/fetch/$s_!N-Td!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F48137b66-60cd-435d-b637-231093fee8ef_2398x1484.png 848w, https://substackcdn.com/image/fetch/$s_!N-Td!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F48137b66-60cd-435d-b637-231093fee8ef_2398x1484.png 1272w, https://substackcdn.com/image/fetch/$s_!N-Td!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F48137b66-60cd-435d-b637-231093fee8ef_2398x1484.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N-Td!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F48137b66-60cd-435d-b637-231093fee8ef_2398x1484.png" width="1456" height="901" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/48137b66-60cd-435d-b637-231093fee8ef_2398x1484.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:901,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1275065,&quot;alt&quot;:&quot;Screen shot of Turbot Quick Actions Enabled policy setting.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Screen shot of Turbot Quick Actions Enabled policy setting." title="Screen shot of Turbot Quick Actions Enabled policy setting." srcset="https://substackcdn.com/image/fetch/$s_!N-Td!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F48137b66-60cd-435d-b637-231093fee8ef_2398x1484.png 424w, https://substackcdn.com/image/fetch/$s_!N-Td!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F48137b66-60cd-435d-b637-231093fee8ef_2398x1484.png 848w, https://substackcdn.com/image/fetch/$s_!N-Td!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F48137b66-60cd-435d-b637-231093fee8ef_2398x1484.png 1272w, https://substackcdn.com/image/fetch/$s_!N-Td!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F48137b66-60cd-435d-b637-231093fee8ef_2398x1484.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>For details on how to limit access to quick actions and create custom permission sets please see <a href="https://turbot.com/v5/docs/guides/quick-actions">this guide in the Turbot docs</a>. If you need any assistance please reach out to <a href="mailto:support@turbot.com">Turbot Support</a>, and keep an eye on your inbox for another <a href="https://on.turbot.com/">[Turbot On]</a> post in the near future! </p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://on.turbot.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading [Turbot On]! Subscribe for free to stay in the loop on all things Turbot.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[[Turbot On] HIPAA Compliance Controls]]></title><description><![CDATA[Evaluate HIPAA compliance for all your AWS accounts.]]></description><link>https://on.turbot.com/p/turbot-on-hipaa-compliance-controls</link><guid isPermaLink="false">https://on.turbot.com/p/turbot-on-hipaa-compliance-controls</guid><dc:creator><![CDATA[Bob Tordella]]></dc:creator><pubDate>Thu, 30 Jun 2022 14:09:52 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!hOD3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf74bb26-a12c-41ae-b075-79b96d024a01_1920x1080.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hOD3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf74bb26-a12c-41ae-b075-79b96d024a01_1920x1080.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hOD3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf74bb26-a12c-41ae-b075-79b96d024a01_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!hOD3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf74bb26-a12c-41ae-b075-79b96d024a01_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!hOD3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf74bb26-a12c-41ae-b075-79b96d024a01_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!hOD3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf74bb26-a12c-41ae-b075-79b96d024a01_1920x1080.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hOD3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf74bb26-a12c-41ae-b075-79b96d024a01_1920x1080.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/bf74bb26-a12c-41ae-b075-79b96d024a01_1920x1080.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:385506,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hOD3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf74bb26-a12c-41ae-b075-79b96d024a01_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!hOD3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf74bb26-a12c-41ae-b075-79b96d024a01_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!hOD3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf74bb26-a12c-41ae-b075-79b96d024a01_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!hOD3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf74bb26-a12c-41ae-b075-79b96d024a01_1920x1080.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Turbot includes thousands of prescriptive cloud controls to ensure cloud environments are secure and cost-optimized. These controls quickly detect issues as they occur and instantly correct misconfigurations. Customers often map Turbot controls to their own Governance Risk Compliance (GRC) tools, and use the resulting evidence to prove continuous adherence to internal controls or external standards such as <a href="https://turbot.com/blog/2020/05/cis-securesuite-member/">Center for Internet Security (CIS)</a>, <a href="https://turbot.com/blog/2016/07/nist-800-53-controls/">NIST 800-53</a>, <a href="https://turbot.com/blog/2018/03/pci-security-compliance/">PCI</a>, <a href="https://turbot.com/blog/2018/04/gdpr-compliance/">GDPR</a>, <a href="https://on.turbot.com/p/turbot-on-automated-soc2-compliance">SOC2</a>, etc.&nbsp;</p><p>Over the last year Turbot has open-sourced <a href="https://steampipe.io">Steampipe.io</a>, a tool that enables cloud engineers to easily query &amp; report across their cloud, code, logs, and more, using the standard language of data: SQL. Steampipe includes thousands of ready-to-use controls and dashboards that deliver insights into your cloud data. These controls and dashboards leverage a suite of plugins that translate cloud APIs into Postgres tables. One of those plugins, by the way, translates the <a href="https://hub.steampipe.io/plugins/turbot/turbot">Turbot v5 API into SQL-queryable tables</a>!</p><p>Cloud teams have asked Turbot to also include industry standards within the Turbot platform. We started by open-sourcing thousands of compliance controls, and enlisting the Steampipe community to provide feedback and contributions. Based on community feedback, we are now starting to port these control frameworks into Turbot.&nbsp; Our first addition in Turbot was the <a href="https://on.turbot.com/p/turbot-on-pci-compliance-controls">Payment Card Industry Data Security Standard (PCI DSS) v3.2.1 standard for AWS</a>, followed by the Health Insurance Portability and Accountability (HIPAA) standard for AWS. Note: When mapping to external standards, Turbot leverages either the published industry standard mapping or the <a href="https://docs.aws.amazon.com/config/latest/developerguide/operational-best-practices-for-hipaa_security.html">mapping provided by each cloud provider</a>. We are excited to add the HIPAA controls to the platform to complement our existing PCI &amp; CIS Controls, along with AWS, Azure &amp; GCP CIS benchmarks.</p><p><strong>This week&#8217;s [Turbot On] will look at how to enable HIPAA controls across all your AWS accounts in Turbot.</strong></p><h2><strong>Traditional Workflow</strong></h2><p>There are various cloud-native and 3rd-party tools to evaluate cloud infrastructure HIPAA compliance. However cloud-native tools generally work with only one cloud provider, and only do periodic scans.&nbsp; 3rd-party tools may support multiple cloud providers, but fall short on benchmark coverage and, again, scan and report only periodically, missing real-time changes in your environment.&nbsp; These tools often work on a per-account basis, without delivering resource-level granularity. And they are limited in their ability to manage the time-based exceptions that enable you to handle the nuances in your organization.</p><h2><strong>Get it done with Turbot</strong></h2><p>In Turbot, HIPAA guardrails are readily available to control your cloud resource configurations.&nbsp; These guardrails work similar to others, continuously evaluating adherence as changes to your cloud resources occur.&nbsp; First, make sure you have the `<a href="https://turbot.com/v5/mods/turbot/aws-hipaa/inspect">@turbot/aws-hipaa</a>` mod installed and any <a href="https://turbot.com/v5/mods/turbot/aws-hipaa/dependencies">dependent mods</a> installed in your workspace.&nbsp; Then you can enable HIPAA through the following Turbot policy in just a few clicks: `AWS &gt; HIPAA`:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dXD5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab77931-0083-4798-b834-01d80ab97485_958x793.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dXD5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab77931-0083-4798-b834-01d80ab97485_958x793.png 424w, https://substackcdn.com/image/fetch/$s_!dXD5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab77931-0083-4798-b834-01d80ab97485_958x793.png 848w, https://substackcdn.com/image/fetch/$s_!dXD5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab77931-0083-4798-b834-01d80ab97485_958x793.png 1272w, https://substackcdn.com/image/fetch/$s_!dXD5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab77931-0083-4798-b834-01d80ab97485_958x793.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dXD5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab77931-0083-4798-b834-01d80ab97485_958x793.png" width="958" height="793" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/0ab77931-0083-4798-b834-01d80ab97485_958x793.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:793,&quot;width&quot;:958,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:44312,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dXD5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab77931-0083-4798-b834-01d80ab97485_958x793.png 424w, https://substackcdn.com/image/fetch/$s_!dXD5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab77931-0083-4798-b834-01d80ab97485_958x793.png 848w, https://substackcdn.com/image/fetch/$s_!dXD5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab77931-0083-4798-b834-01d80ab97485_958x793.png 1272w, https://substackcdn.com/image/fetch/$s_!dXD5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab77931-0083-4798-b834-01d80ab97485_958x793.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Setting the configuration via the <a href="https://turbot.com/v5/docs/reference/terraform">Turbot Terraform Provider</a> is just as simple:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LIcl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd24df25-1864-4ae3-9013-110b6f6c180f_1061x410.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LIcl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd24df25-1864-4ae3-9013-110b6f6c180f_1061x410.png 424w, https://substackcdn.com/image/fetch/$s_!LIcl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd24df25-1864-4ae3-9013-110b6f6c180f_1061x410.png 848w, https://substackcdn.com/image/fetch/$s_!LIcl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd24df25-1864-4ae3-9013-110b6f6c180f_1061x410.png 1272w, https://substackcdn.com/image/fetch/$s_!LIcl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd24df25-1864-4ae3-9013-110b6f6c180f_1061x410.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LIcl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd24df25-1864-4ae3-9013-110b6f6c180f_1061x410.png" width="1061" height="410" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/bd24df25-1864-4ae3-9013-110b6f6c180f_1061x410.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:410,&quot;width&quot;:1061,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:52316,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LIcl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd24df25-1864-4ae3-9013-110b6f6c180f_1061x410.png 424w, https://substackcdn.com/image/fetch/$s_!LIcl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd24df25-1864-4ae3-9013-110b6f6c180f_1061x410.png 848w, https://substackcdn.com/image/fetch/$s_!LIcl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd24df25-1864-4ae3-9013-110b6f6c180f_1061x410.png 1272w, https://substackcdn.com/image/fetch/$s_!LIcl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd24df25-1864-4ae3-9013-110b6f6c180f_1061x410.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>After enabling this policy, Turbot will immediately evaluate all applicable resources compliance with HIPAA.&nbsp; You can view your controls across major sections of the HIPAA standard:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ikVU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F258f098e-26e6-464a-9f45-420bff30b9ad_1175x403.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ikVU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F258f098e-26e6-464a-9f45-420bff30b9ad_1175x403.png 424w, https://substackcdn.com/image/fetch/$s_!ikVU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F258f098e-26e6-464a-9f45-420bff30b9ad_1175x403.png 848w, https://substackcdn.com/image/fetch/$s_!ikVU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F258f098e-26e6-464a-9f45-420bff30b9ad_1175x403.png 1272w, https://substackcdn.com/image/fetch/$s_!ikVU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F258f098e-26e6-464a-9f45-420bff30b9ad_1175x403.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ikVU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F258f098e-26e6-464a-9f45-420bff30b9ad_1175x403.png" width="1175" height="403" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/258f098e-26e6-464a-9f45-420bff30b9ad_1175x403.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:403,&quot;width&quot;:1175,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:24682,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ikVU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F258f098e-26e6-464a-9f45-420bff30b9ad_1175x403.png 424w, https://substackcdn.com/image/fetch/$s_!ikVU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F258f098e-26e6-464a-9f45-420bff30b9ad_1175x403.png 848w, https://substackcdn.com/image/fetch/$s_!ikVU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F258f098e-26e6-464a-9f45-420bff30b9ad_1175x403.png 1272w, https://substackcdn.com/image/fetch/$s_!ikVU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F258f098e-26e6-464a-9f45-420bff30b9ad_1175x403.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Drill further into subsections:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jQKN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe744fe50-889f-4ef5-8026-9caf74baed77_1237x677.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jQKN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe744fe50-889f-4ef5-8026-9caf74baed77_1237x677.png 424w, https://substackcdn.com/image/fetch/$s_!jQKN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe744fe50-889f-4ef5-8026-9caf74baed77_1237x677.png 848w, https://substackcdn.com/image/fetch/$s_!jQKN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe744fe50-889f-4ef5-8026-9caf74baed77_1237x677.png 1272w, https://substackcdn.com/image/fetch/$s_!jQKN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe744fe50-889f-4ef5-8026-9caf74baed77_1237x677.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jQKN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe744fe50-889f-4ef5-8026-9caf74baed77_1237x677.png" width="1237" height="677" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/e744fe50-889f-4ef5-8026-9caf74baed77_1237x677.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:677,&quot;width&quot;:1237,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:51437,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jQKN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe744fe50-889f-4ef5-8026-9caf74baed77_1237x677.png 424w, https://substackcdn.com/image/fetch/$s_!jQKN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe744fe50-889f-4ef5-8026-9caf74baed77_1237x677.png 848w, https://substackcdn.com/image/fetch/$s_!jQKN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe744fe50-889f-4ef5-8026-9caf74baed77_1237x677.png 1272w, https://substackcdn.com/image/fetch/$s_!jQKN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe744fe50-889f-4ef5-8026-9caf74baed77_1237x677.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Drill further to expand the subsections to view particular per cloud service controls:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AHbJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F565ae1bf-93e5-46e5-9461-c44d0231934f_1462x682.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AHbJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F565ae1bf-93e5-46e5-9461-c44d0231934f_1462x682.png 424w, https://substackcdn.com/image/fetch/$s_!AHbJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F565ae1bf-93e5-46e5-9461-c44d0231934f_1462x682.png 848w, https://substackcdn.com/image/fetch/$s_!AHbJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F565ae1bf-93e5-46e5-9461-c44d0231934f_1462x682.png 1272w, https://substackcdn.com/image/fetch/$s_!AHbJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F565ae1bf-93e5-46e5-9461-c44d0231934f_1462x682.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AHbJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F565ae1bf-93e5-46e5-9461-c44d0231934f_1462x682.png" width="1456" height="679" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/565ae1bf-93e5-46e5-9461-c44d0231934f_1462x682.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:679,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:56969,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!AHbJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F565ae1bf-93e5-46e5-9461-c44d0231934f_1462x682.png 424w, https://substackcdn.com/image/fetch/$s_!AHbJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F565ae1bf-93e5-46e5-9461-c44d0231934f_1462x682.png 848w, https://substackcdn.com/image/fetch/$s_!AHbJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F565ae1bf-93e5-46e5-9461-c44d0231934f_1462x682.png 1272w, https://substackcdn.com/image/fetch/$s_!AHbJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F565ae1bf-93e5-46e5-9461-c44d0231934f_1462x682.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Analyze which specific resources are impacted per control:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!M4sv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F24930430-8dac-46c6-8a92-b0659bf31116_1917x636.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!M4sv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F24930430-8dac-46c6-8a92-b0659bf31116_1917x636.png 424w, https://substackcdn.com/image/fetch/$s_!M4sv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F24930430-8dac-46c6-8a92-b0659bf31116_1917x636.png 848w, https://substackcdn.com/image/fetch/$s_!M4sv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F24930430-8dac-46c6-8a92-b0659bf31116_1917x636.png 1272w, https://substackcdn.com/image/fetch/$s_!M4sv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F24930430-8dac-46c6-8a92-b0659bf31116_1917x636.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!M4sv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F24930430-8dac-46c6-8a92-b0659bf31116_1917x636.png" width="1456" height="483" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/24930430-8dac-46c6-8a92-b0659bf31116_1917x636.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:483,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:107156,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!M4sv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F24930430-8dac-46c6-8a92-b0659bf31116_1917x636.png 424w, https://substackcdn.com/image/fetch/$s_!M4sv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F24930430-8dac-46c6-8a92-b0659bf31116_1917x636.png 848w, https://substackcdn.com/image/fetch/$s_!M4sv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F24930430-8dac-46c6-8a92-b0659bf31116_1917x636.png 1272w, https://substackcdn.com/image/fetch/$s_!M4sv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F24930430-8dac-46c6-8a92-b0659bf31116_1917x636.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Inverse the view to visualize all primary controls on a particular resource:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aPJ2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5117c67-9dfc-4ba6-b5e7-4ad47f5dcd03_1567x1840.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aPJ2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5117c67-9dfc-4ba6-b5e7-4ad47f5dcd03_1567x1840.png 424w, https://substackcdn.com/image/fetch/$s_!aPJ2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5117c67-9dfc-4ba6-b5e7-4ad47f5dcd03_1567x1840.png 848w, https://substackcdn.com/image/fetch/$s_!aPJ2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5117c67-9dfc-4ba6-b5e7-4ad47f5dcd03_1567x1840.png 1272w, https://substackcdn.com/image/fetch/$s_!aPJ2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5117c67-9dfc-4ba6-b5e7-4ad47f5dcd03_1567x1840.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aPJ2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5117c67-9dfc-4ba6-b5e7-4ad47f5dcd03_1567x1840.png" width="1456" height="1710" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/e5117c67-9dfc-4ba6-b5e7-4ad47f5dcd03_1567x1840.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1710,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:211719,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!aPJ2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5117c67-9dfc-4ba6-b5e7-4ad47f5dcd03_1567x1840.png 424w, https://substackcdn.com/image/fetch/$s_!aPJ2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5117c67-9dfc-4ba6-b5e7-4ad47f5dcd03_1567x1840.png 848w, https://substackcdn.com/image/fetch/$s_!aPJ2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5117c67-9dfc-4ba6-b5e7-4ad47f5dcd03_1567x1840.png 1272w, https://substackcdn.com/image/fetch/$s_!aPJ2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5117c67-9dfc-4ba6-b5e7-4ad47f5dcd03_1567x1840.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Make it happen</strong></h2><p>See for yourself on how easy it is to view your HIPAA requirements across your cloud resources.&nbsp; If you need any assistance please reach out to <a href="mailto:support@turbot.com">Turbot Support</a>, and keep an eye on your inbox for another <a href="https://on.turbot.com/">[Turbot On]</a> post in the near future!</p><p>Cheers,</p><p>Bob</p>]]></content:encoded></item><item><title><![CDATA[Turbot 2022 Annual SOC 2 Type II Compliance]]></title><description><![CDATA[We're excited to announce that Turbot Cloud (SaaS) has received its annual SOC 2 Type II certification.]]></description><link>https://on.turbot.com/p/turbot-2022-annual-soc-2-type-ii</link><guid isPermaLink="false">https://on.turbot.com/p/turbot-2022-annual-soc-2-type-ii</guid><dc:creator><![CDATA[Bob Tordella]]></dc:creator><pubDate>Wed, 25 May 2022 11:27:08 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!R4cv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3c84ce02-1709-496d-abce-5f4700527b4d_1400x720.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!R4cv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3c84ce02-1709-496d-abce-5f4700527b4d_1400x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!R4cv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3c84ce02-1709-496d-abce-5f4700527b4d_1400x720.png 424w, https://substackcdn.com/image/fetch/$s_!R4cv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3c84ce02-1709-496d-abce-5f4700527b4d_1400x720.png 848w, https://substackcdn.com/image/fetch/$s_!R4cv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3c84ce02-1709-496d-abce-5f4700527b4d_1400x720.png 1272w, https://substackcdn.com/image/fetch/$s_!R4cv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3c84ce02-1709-496d-abce-5f4700527b4d_1400x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!R4cv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3c84ce02-1709-496d-abce-5f4700527b4d_1400x720.png" width="1400" height="720" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/3c84ce02-1709-496d-abce-5f4700527b4d_1400x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1400,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:138092,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!R4cv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3c84ce02-1709-496d-abce-5f4700527b4d_1400x720.png 424w, https://substackcdn.com/image/fetch/$s_!R4cv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3c84ce02-1709-496d-abce-5f4700527b4d_1400x720.png 848w, https://substackcdn.com/image/fetch/$s_!R4cv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3c84ce02-1709-496d-abce-5f4700527b4d_1400x720.png 1272w, https://substackcdn.com/image/fetch/$s_!R4cv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3c84ce02-1709-496d-abce-5f4700527b4d_1400x720.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Customers value Turbot to provide cloud governance solutions to increase their security and compliance posture across their cloud environments. Customers use Turbot to enable policy based automation for AWS, Azure and GCP to discover &amp; correct misconfigurations instantly. Turbot ensures environments are secure &amp; cost optimized at all times elevating the cloud team to do more with less manual effort. To support Turbot's automation, the product features an event driven, real-time CMDB to capture audit trail &amp; asset inventory, 9500+ point-and-click ready policies to set with inheritance &amp; time-based exceptions, multi-cloud timed-based RBAC management, and managed IaC stack deployments.</p><p>Turbot is a powerful governance tool in our customer's cloud environments, earning and maintaining our customers' trust is of the utmost importance to us at Turbot. Our operations, product and engineering teams, are dedicated to ensuring that our products are designed, architected and developed with both the security of our products, and of our customers' data in mind. Because of this we have invested heavily in security, and we are excited to share that Turbot has achieved our annual SOC 2 Type II compliance for <a href="https://turbot.com/v5/">Turbot Cloud (SaaS)</a>.</p><p>With the adoption of industry best practices for controls and processes throughout our environments and software development lifecycle, we strive for best-in-class security. This includes security awareness training for all employees, achieving our <a href="https://turbot.com/blog/2020/05/cis-securesuite-member/">CIS Benchmark Certification</a>, undergoing multiple Well-Architected audits as part of our AWS Advanced Tier <a href="https://turbot.com/blog/2017/06/turbot-recognized-as-an-aws-security-partner/">Security</a> &amp; <a href="https://turbot.com/blog/2018/09/aws-cloud-management-tools/">Cloud Management</a> status, support for our <a href="https://turbot.com/legal/privacy/">privacy policy</a> for <a href="https://turbot.com/blog/2018/04/gdpr-compliance/">GDPR</a>, CCPA, and Privacy Shield, enterprise supplier audits, and continuous penetration testing.</p><p>Ensuring we meet the data security, privacy and compliance needs of our customers is core to our business. This achievement validates our commitment as we strive to earn and maintain our customers' trust, and, as we progress in our compliance journey to help us mature our security posture.</p><p>Our SOC audits are conducted annually each April. The auditors prepare their audit report which is then released each May. Our complete SOC 2 Type II audit report is available to customers and prospects under NDA upon request. Visit our <a href="https://turbot.com/security">Turbot Security</a> page for more information about our security practices.</p><p>If you have any questions please reach out to <a href="mailto:support@turbot.com">Turbot Support</a>, and keep an eye on your inbox for another Turbot post in the near future!</p>]]></content:encoded></item><item><title><![CDATA[[Turbot On] PCI Compliance Controls]]></title><description><![CDATA[Evaluate PCI DSS version 3.2.1 compliance for all your AWS accounts.]]></description><link>https://on.turbot.com/p/turbot-on-pci-compliance-controls</link><guid isPermaLink="false">https://on.turbot.com/p/turbot-on-pci-compliance-controls</guid><dc:creator><![CDATA[Bob Tordella]]></dc:creator><pubDate>Fri, 29 Apr 2022 12:00:42 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ORpg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F54d51548-1b7c-4f73-a1a3-b311bcb23f78_5760x2880.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ORpg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F54d51548-1b7c-4f73-a1a3-b311bcb23f78_5760x2880.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ORpg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F54d51548-1b7c-4f73-a1a3-b311bcb23f78_5760x2880.png 424w, https://substackcdn.com/image/fetch/$s_!ORpg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F54d51548-1b7c-4f73-a1a3-b311bcb23f78_5760x2880.png 848w, https://substackcdn.com/image/fetch/$s_!ORpg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F54d51548-1b7c-4f73-a1a3-b311bcb23f78_5760x2880.png 1272w, https://substackcdn.com/image/fetch/$s_!ORpg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F54d51548-1b7c-4f73-a1a3-b311bcb23f78_5760x2880.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ORpg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F54d51548-1b7c-4f73-a1a3-b311bcb23f78_5760x2880.png" width="1456" height="728" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/54d51548-1b7c-4f73-a1a3-b311bcb23f78_5760x2880.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:728,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:19836155,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ORpg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F54d51548-1b7c-4f73-a1a3-b311bcb23f78_5760x2880.png 424w, https://substackcdn.com/image/fetch/$s_!ORpg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F54d51548-1b7c-4f73-a1a3-b311bcb23f78_5760x2880.png 848w, https://substackcdn.com/image/fetch/$s_!ORpg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F54d51548-1b7c-4f73-a1a3-b311bcb23f78_5760x2880.png 1272w, https://substackcdn.com/image/fetch/$s_!ORpg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F54d51548-1b7c-4f73-a1a3-b311bcb23f78_5760x2880.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Turbot includes thousands of prescriptive cloud controls to ensure cloud environments are secure and cost-optimized. These controls quickly detect issues as they occur and instantly correct misconfigurations. Customers often map Turbot controls to their own Governance Risk Compliance (GRC) tools, and use the resulting evidence to prove continuous adherence to internal controls or external standards such as <a href="https://turbot.com/blog/2020/05/cis-securesuite-member/">Center for Internet Security (CIS)</a>, <a href="https://turbot.com/blog/2016/07/nist-800-53-controls/">NIST 800-53</a>, <a href="https://turbot.com/blog/2017/02/hipaa-phi-security-compliance/">HIPAA</a>, <a href="https://turbot.com/blog/2018/04/gdpr-compliance/">GDPR</a>, <a href="https://on.turbot.com/p/turbot-on-automated-soc2-compliance">SOC2</a>, etc.&nbsp;</p><p>Over the last year Turbot has open-sourced <a href="https://steampipe.io">Steampipe.io</a>, a tool that enables cloud engineers to easily query &amp; report across their cloud, code, logs, and more, using the standard language of data: SQL. Steampipe includes thousands of ready-to-use controls and dashboards that deliver insights into your cloud data. These controls and dashboards leverage a suite of plugins that translate cloud APIs into Postgres tables. One of those plugins, by the way, translates the <a href="https://hub.steampipe.io/plugins/turbot/turbot">Turbot v5 API into SQL-queryable tables</a>!</p><p>Cloud teams have asked Turbot to also include industry standards within the Turbot platform. We started by open-sourcing thousands of compliance controls, and enlisting the Steampipe community to provide feedback and contributions. Based on community feedback, we are now starting to port these control frameworks&nbsp;into Turbot.&nbsp; Our first addition is the Payment Card Industry Data Security Standard (PCI DSS) v3.2.1 standard for AWS. Note: When mapping to external standards, Turbot leverages either the published industry standard mapping or the <a href="https://docs.aws.amazon.com/config/latest/developerguide/operational-best-practices-for-pci-dss.html">mapping provided by each cloud provider</a>. We are excited to add the PCI controls to the platform to complement our existing CIS Controls and AWS, Azure &amp; GCP CIS benchmarks.</p><p><strong>This week&#8217;s [Turbot On] will look at how to enable PCI controls across all your AWS accounts in Turbot.</strong></p><h2>Traditional Workflow</h2><p>There are various cloud-native and 3rd-party tools to evaluate cloud infrastructure PCI compliance. However cloud-native tools generally work with only one cloud provider, and only do periodic scans.&nbsp; 3rd-party tools may support multiple cloud providers, but fall short on benchmark coverage and, again, scan and report only periodically, missing real-time changes in your environment.&nbsp; These tools often work on a per-account basis, without delivering resource-level granularity. And they are limited in their ability to manage the time-based exceptions that enable you to handle the nuances in your organization.</p><h2><strong>Get it done with Turbot</strong></h2><p>In Turbot, PCI guardrails are readily available to control your cloud resource configurations.&nbsp; These guardrails work similar to others, continuously evaluating adherence as changes to your cloud resources occur.&nbsp; First, make sure you have the `<a href="https://turbot.com/v5/mods/turbot/aws-pciv3-2-1/inspect">@turbot/aws-pciv3-2-1</a>` mod installed and any <a href="https://turbot.com/v5/mods/turbot/aws-pciv3-2-1/dependencies">dependent mods</a> installed in your workspace.&nbsp; Then you can enable PCI through the following Turbot policy in just a few clicks: `<strong>AWS &gt; PCI v3.2.1</strong>`:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uQQA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F30f28774-0b04-4067-ac3f-0fe5128fe5ef_1017x822.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uQQA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F30f28774-0b04-4067-ac3f-0fe5128fe5ef_1017x822.png 424w, https://substackcdn.com/image/fetch/$s_!uQQA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F30f28774-0b04-4067-ac3f-0fe5128fe5ef_1017x822.png 848w, https://substackcdn.com/image/fetch/$s_!uQQA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F30f28774-0b04-4067-ac3f-0fe5128fe5ef_1017x822.png 1272w, https://substackcdn.com/image/fetch/$s_!uQQA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F30f28774-0b04-4067-ac3f-0fe5128fe5ef_1017x822.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uQQA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F30f28774-0b04-4067-ac3f-0fe5128fe5ef_1017x822.png" width="1017" height="822" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/30f28774-0b04-4067-ac3f-0fe5128fe5ef_1017x822.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:822,&quot;width&quot;:1017,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:47234,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uQQA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F30f28774-0b04-4067-ac3f-0fe5128fe5ef_1017x822.png 424w, https://substackcdn.com/image/fetch/$s_!uQQA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F30f28774-0b04-4067-ac3f-0fe5128fe5ef_1017x822.png 848w, https://substackcdn.com/image/fetch/$s_!uQQA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F30f28774-0b04-4067-ac3f-0fe5128fe5ef_1017x822.png 1272w, https://substackcdn.com/image/fetch/$s_!uQQA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F30f28774-0b04-4067-ac3f-0fe5128fe5ef_1017x822.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Setting the configuration <a href="https://turbot.com/v5/docs/reference/terraform">via our Terraform Provider</a> is just as simple:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yilA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdf87bfe-08e7-40f7-807a-d3b8358161a3_1096x426.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yilA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdf87bfe-08e7-40f7-807a-d3b8358161a3_1096x426.png 424w, https://substackcdn.com/image/fetch/$s_!yilA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdf87bfe-08e7-40f7-807a-d3b8358161a3_1096x426.png 848w, https://substackcdn.com/image/fetch/$s_!yilA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdf87bfe-08e7-40f7-807a-d3b8358161a3_1096x426.png 1272w, https://substackcdn.com/image/fetch/$s_!yilA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdf87bfe-08e7-40f7-807a-d3b8358161a3_1096x426.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yilA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdf87bfe-08e7-40f7-807a-d3b8358161a3_1096x426.png" width="1096" height="426" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/bdf87bfe-08e7-40f7-807a-d3b8358161a3_1096x426.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:426,&quot;width&quot;:1096,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:56301,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yilA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdf87bfe-08e7-40f7-807a-d3b8358161a3_1096x426.png 424w, https://substackcdn.com/image/fetch/$s_!yilA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdf87bfe-08e7-40f7-807a-d3b8358161a3_1096x426.png 848w, https://substackcdn.com/image/fetch/$s_!yilA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdf87bfe-08e7-40f7-807a-d3b8358161a3_1096x426.png 1272w, https://substackcdn.com/image/fetch/$s_!yilA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdf87bfe-08e7-40f7-807a-d3b8358161a3_1096x426.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>After enabling this policy, Turbot will immediately evaluate all applicable resources compliance with PCI.&nbsp; You can view your controls across services:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ltRA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4406535a-ef67-408e-84ab-68b86485322a_1162x872.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ltRA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4406535a-ef67-408e-84ab-68b86485322a_1162x872.png 424w, https://substackcdn.com/image/fetch/$s_!ltRA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4406535a-ef67-408e-84ab-68b86485322a_1162x872.png 848w, https://substackcdn.com/image/fetch/$s_!ltRA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4406535a-ef67-408e-84ab-68b86485322a_1162x872.png 1272w, https://substackcdn.com/image/fetch/$s_!ltRA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4406535a-ef67-408e-84ab-68b86485322a_1162x872.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ltRA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4406535a-ef67-408e-84ab-68b86485322a_1162x872.png" width="1162" height="872" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/4406535a-ef67-408e-84ab-68b86485322a_1162x872.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:872,&quot;width&quot;:1162,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:75904,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ltRA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4406535a-ef67-408e-84ab-68b86485322a_1162x872.png 424w, https://substackcdn.com/image/fetch/$s_!ltRA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4406535a-ef67-408e-84ab-68b86485322a_1162x872.png 848w, https://substackcdn.com/image/fetch/$s_!ltRA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4406535a-ef67-408e-84ab-68b86485322a_1162x872.png 1272w, https://substackcdn.com/image/fetch/$s_!ltRA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4406535a-ef67-408e-84ab-68b86485322a_1162x872.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Drill further into sub controls of a specific service:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BLCL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F67a3a7df-f85c-43f2-bdd4-5c6949181e9e_1281x758.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BLCL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F67a3a7df-f85c-43f2-bdd4-5c6949181e9e_1281x758.png 424w, https://substackcdn.com/image/fetch/$s_!BLCL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F67a3a7df-f85c-43f2-bdd4-5c6949181e9e_1281x758.png 848w, https://substackcdn.com/image/fetch/$s_!BLCL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F67a3a7df-f85c-43f2-bdd4-5c6949181e9e_1281x758.png 1272w, https://substackcdn.com/image/fetch/$s_!BLCL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F67a3a7df-f85c-43f2-bdd4-5c6949181e9e_1281x758.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BLCL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F67a3a7df-f85c-43f2-bdd4-5c6949181e9e_1281x758.png" width="1281" height="758" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/67a3a7df-f85c-43f2-bdd4-5c6949181e9e_1281x758.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:758,&quot;width&quot;:1281,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:55996,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BLCL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F67a3a7df-f85c-43f2-bdd4-5c6949181e9e_1281x758.png 424w, https://substackcdn.com/image/fetch/$s_!BLCL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F67a3a7df-f85c-43f2-bdd4-5c6949181e9e_1281x758.png 848w, https://substackcdn.com/image/fetch/$s_!BLCL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F67a3a7df-f85c-43f2-bdd4-5c6949181e9e_1281x758.png 1272w, https://substackcdn.com/image/fetch/$s_!BLCL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F67a3a7df-f85c-43f2-bdd4-5c6949181e9e_1281x758.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Analyze which specific resources are impacted:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EI8r!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fba3619f3-cbd8-49ba-bb81-8e1d93a1bbc4_1645x701.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EI8r!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fba3619f3-cbd8-49ba-bb81-8e1d93a1bbc4_1645x701.png 424w, https://substackcdn.com/image/fetch/$s_!EI8r!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fba3619f3-cbd8-49ba-bb81-8e1d93a1bbc4_1645x701.png 848w, https://substackcdn.com/image/fetch/$s_!EI8r!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fba3619f3-cbd8-49ba-bb81-8e1d93a1bbc4_1645x701.png 1272w, https://substackcdn.com/image/fetch/$s_!EI8r!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fba3619f3-cbd8-49ba-bb81-8e1d93a1bbc4_1645x701.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EI8r!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fba3619f3-cbd8-49ba-bb81-8e1d93a1bbc4_1645x701.png" width="1456" height="620" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/ba3619f3-cbd8-49ba-bb81-8e1d93a1bbc4_1645x701.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:620,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:105439,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!EI8r!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fba3619f3-cbd8-49ba-bb81-8e1d93a1bbc4_1645x701.png 424w, https://substackcdn.com/image/fetch/$s_!EI8r!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fba3619f3-cbd8-49ba-bb81-8e1d93a1bbc4_1645x701.png 848w, https://substackcdn.com/image/fetch/$s_!EI8r!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fba3619f3-cbd8-49ba-bb81-8e1d93a1bbc4_1645x701.png 1272w, https://substackcdn.com/image/fetch/$s_!EI8r!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fba3619f3-cbd8-49ba-bb81-8e1d93a1bbc4_1645x701.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Visualize all the resources primary controls including PCI:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KPs8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb25d0bba-5bbc-41be-bcf9-84385dd63b3e_1576x1952.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KPs8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb25d0bba-5bbc-41be-bcf9-84385dd63b3e_1576x1952.png 424w, https://substackcdn.com/image/fetch/$s_!KPs8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb25d0bba-5bbc-41be-bcf9-84385dd63b3e_1576x1952.png 848w, https://substackcdn.com/image/fetch/$s_!KPs8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb25d0bba-5bbc-41be-bcf9-84385dd63b3e_1576x1952.png 1272w, https://substackcdn.com/image/fetch/$s_!KPs8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb25d0bba-5bbc-41be-bcf9-84385dd63b3e_1576x1952.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KPs8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb25d0bba-5bbc-41be-bcf9-84385dd63b3e_1576x1952.png" width="1456" height="1803" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/b25d0bba-5bbc-41be-bcf9-84385dd63b3e_1576x1952.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1803,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:222059,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KPs8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb25d0bba-5bbc-41be-bcf9-84385dd63b3e_1576x1952.png 424w, https://substackcdn.com/image/fetch/$s_!KPs8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb25d0bba-5bbc-41be-bcf9-84385dd63b3e_1576x1952.png 848w, https://substackcdn.com/image/fetch/$s_!KPs8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb25d0bba-5bbc-41be-bcf9-84385dd63b3e_1576x1952.png 1272w, https://substackcdn.com/image/fetch/$s_!KPs8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb25d0bba-5bbc-41be-bcf9-84385dd63b3e_1576x1952.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Make it happen</strong></h2><p>See for yourself on how easy it is to view your PCI requirements across your cloud resources.&nbsp; If you need any assistance please reach out to <a href="mailto:support@turbot.com">Turbot Support</a>, and keep an eye on your inbox for another Turbot post in the near future!</p><p>Cheers,</p><p>Bob</p>]]></content:encoded></item><item><title><![CDATA[[Turbot On] Automated EBS Encryption ]]></title><description><![CDATA[Automate EBS default encryption for all AWS accounts and regions.]]></description><link>https://on.turbot.com/p/turbot-on-automated-ebs-encryption</link><guid isPermaLink="false">https://on.turbot.com/p/turbot-on-automated-ebs-encryption</guid><dc:creator><![CDATA[Bob Tordella]]></dc:creator><pubDate>Tue, 20 Jul 2021 19:53:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!b2Ou!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0c01413a-13af-4ede-9eee-b1b05c7aa27e_2400x1105.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!b2Ou!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0c01413a-13af-4ede-9eee-b1b05c7aa27e_2400x1105.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!b2Ou!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0c01413a-13af-4ede-9eee-b1b05c7aa27e_2400x1105.png 424w, https://substackcdn.com/image/fetch/$s_!b2Ou!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0c01413a-13af-4ede-9eee-b1b05c7aa27e_2400x1105.png 848w, https://substackcdn.com/image/fetch/$s_!b2Ou!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0c01413a-13af-4ede-9eee-b1b05c7aa27e_2400x1105.png 1272w, https://substackcdn.com/image/fetch/$s_!b2Ou!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0c01413a-13af-4ede-9eee-b1b05c7aa27e_2400x1105.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!b2Ou!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0c01413a-13af-4ede-9eee-b1b05c7aa27e_2400x1105.png" width="1456" height="670" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/0c01413a-13af-4ede-9eee-b1b05c7aa27e_2400x1105.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:670,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:542593,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!b2Ou!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0c01413a-13af-4ede-9eee-b1b05c7aa27e_2400x1105.png 424w, https://substackcdn.com/image/fetch/$s_!b2Ou!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0c01413a-13af-4ede-9eee-b1b05c7aa27e_2400x1105.png 848w, https://substackcdn.com/image/fetch/$s_!b2Ou!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0c01413a-13af-4ede-9eee-b1b05c7aa27e_2400x1105.png 1272w, https://substackcdn.com/image/fetch/$s_!b2Ou!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0c01413a-13af-4ede-9eee-b1b05c7aa27e_2400x1105.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A common headache for cloud operations is dealing with infrastructure that wasn&#8217;t optimally deployed from the start.&nbsp;Application teams may not be experts in all areas of infrastructure as code deployment and as such may assume that default settings for their AWS infrastructure implement best practices (like encryption) without the need for them to take an active role in defining all aspects of their infrastructure design.</p><p>It is easy for an inexperienced developer or data scientist to use the AWS console to deploy new instances and add storage to them, however the default settings do not enforce many best practices, including encryption at rest for EBS volumes and snapshots.</p><p>The good news is that AWS is listening and continually rolling out new options to help address these issues.&nbsp;One such feature is the ability to specify default encryption for EBS resources in each region.&nbsp;This means that any new EBS volumes created in that region will automatically get encryption without any action needed by the developer.</p><blockquote><h4><strong>This week&#8217;s [Turbot On] will look at how to automate EBS default encryption across all your accounts and regions.&nbsp;</strong></h4></blockquote><h2>Traditional Model</h2><p>Enabling the default encryption setting must be done for every individual region and account, using this setting in the AWS console:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xy2M!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb189934-fbbc-4329-92e7-d3ef7486185e_1800x1100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xy2M!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb189934-fbbc-4329-92e7-d3ef7486185e_1800x1100.png 424w, https://substackcdn.com/image/fetch/$s_!xy2M!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb189934-fbbc-4329-92e7-d3ef7486185e_1800x1100.png 848w, https://substackcdn.com/image/fetch/$s_!xy2M!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb189934-fbbc-4329-92e7-d3ef7486185e_1800x1100.png 1272w, https://substackcdn.com/image/fetch/$s_!xy2M!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb189934-fbbc-4329-92e7-d3ef7486185e_1800x1100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xy2M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb189934-fbbc-4329-92e7-d3ef7486185e_1800x1100.png" width="1456" height="890" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/cb189934-fbbc-4329-92e7-d3ef7486185e_1800x1100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:890,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:174374,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xy2M!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb189934-fbbc-4329-92e7-d3ef7486185e_1800x1100.png 424w, https://substackcdn.com/image/fetch/$s_!xy2M!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb189934-fbbc-4329-92e7-d3ef7486185e_1800x1100.png 848w, https://substackcdn.com/image/fetch/$s_!xy2M!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb189934-fbbc-4329-92e7-d3ef7486185e_1800x1100.png 1272w, https://substackcdn.com/image/fetch/$s_!xy2M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb189934-fbbc-4329-92e7-d3ef7486185e_1800x1100.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">AWS Console default encryption setting for us-east-1.</figcaption></figure></div><p>Performing this action across a couple regions or accounts is trivial, but ensuring that the setting is consistently applied across 20+ regions and hundreds of accounts is 100% a job for automation!</p><h2><strong>Get it Done with Turbot</strong></h2><p>Turbot&#8217;s automation can ensure that the correct KMS key is setup for EBS default encryption, in <em><strong>every region </strong></em>and <em><strong>across hundreds of accounts</strong></em> simultaneously. Every time a new account is on-boarded, Turbot will identify that the setting is not enabled and set it appropriately without need for any manual intervention.</p><p>One policy setting is all it takes:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vyoA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9240e816-8ee6-4a5a-9397-842537424aaa_980x930.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vyoA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9240e816-8ee6-4a5a-9397-842537424aaa_980x930.png 424w, https://substackcdn.com/image/fetch/$s_!vyoA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9240e816-8ee6-4a5a-9397-842537424aaa_980x930.png 848w, https://substackcdn.com/image/fetch/$s_!vyoA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9240e816-8ee6-4a5a-9397-842537424aaa_980x930.png 1272w, https://substackcdn.com/image/fetch/$s_!vyoA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9240e816-8ee6-4a5a-9397-842537424aaa_980x930.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vyoA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9240e816-8ee6-4a5a-9397-842537424aaa_980x930.png" width="980" height="930" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/9240e816-8ee6-4a5a-9397-842537424aaa_980x930.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:930,&quot;width&quot;:980,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:40004,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vyoA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9240e816-8ee6-4a5a-9397-842537424aaa_980x930.png 424w, https://substackcdn.com/image/fetch/$s_!vyoA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9240e816-8ee6-4a5a-9397-842537424aaa_980x930.png 848w, https://substackcdn.com/image/fetch/$s_!vyoA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9240e816-8ee6-4a5a-9397-842537424aaa_980x930.png 1272w, https://substackcdn.com/image/fetch/$s_!vyoA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9240e816-8ee6-4a5a-9397-842537424aaa_980x930.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Turbot&#8217;s EBS default encryption policy setting.</figcaption></figure></div><p>Setting the configuration <a href="https://turbot.com/v5/docs/reference/terraform">via our Terraform Provider</a> is just as simple:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gEbw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F22c6202d-1353-4c57-a6d1-e0619390ed51_4156x1444.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gEbw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F22c6202d-1353-4c57-a6d1-e0619390ed51_4156x1444.png 424w, https://substackcdn.com/image/fetch/$s_!gEbw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F22c6202d-1353-4c57-a6d1-e0619390ed51_4156x1444.png 848w, https://substackcdn.com/image/fetch/$s_!gEbw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F22c6202d-1353-4c57-a6d1-e0619390ed51_4156x1444.png 1272w, https://substackcdn.com/image/fetch/$s_!gEbw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F22c6202d-1353-4c57-a6d1-e0619390ed51_4156x1444.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gEbw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F22c6202d-1353-4c57-a6d1-e0619390ed51_4156x1444.png" width="1456" height="506" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/22c6202d-1353-4c57-a6d1-e0619390ed51_4156x1444.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:506,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:281267,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gEbw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F22c6202d-1353-4c57-a6d1-e0619390ed51_4156x1444.png 424w, https://substackcdn.com/image/fetch/$s_!gEbw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F22c6202d-1353-4c57-a6d1-e0619390ed51_4156x1444.png 848w, https://substackcdn.com/image/fetch/$s_!gEbw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F22c6202d-1353-4c57-a6d1-e0619390ed51_4156x1444.png 1272w, https://substackcdn.com/image/fetch/$s_!gEbw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F22c6202d-1353-4c57-a6d1-e0619390ed51_4156x1444.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Terraform Smart Folder and Policy template.</figcaption></figure></div><div class="preformatted-block" data-component-name="PreformattedTextBlockToDOM"><label class="hide-text" contenteditable="false">Text within this block will maintain its original spacing when published</label><pre class="text"></pre></div><p>Once this policy is set, Turbot will automatically discover all regions not configured to use default EBS volume encryption and enforce the policy setting. If you are not ready to enforce the change, you can still audit all accounts/regions that do not have the setting enabled, simply change the Turbot policy setting from &#8220;Enforce: &#8230;&#8221; to &#8220;Check: &#8230;&#8221; and Turbot will create alarms for any regions without the correct configuration.</p><p>It is important to note that the default setting is just that. It doesn&#8217;t apply to already provisioned instances and it can be changed/ignored/bypassed by administrators. If EBS default encryption does not meet your organizations use case, or you want to take a more in-depth preventative approach, you can use Turbot&#8217;s EC2 <a href="https://turbot.com/v5/docs/concepts/guardrails/encryption-at-rest">Encryption at Rest</a> controls such as:</p><ul><li><p>&#8216;AWS &gt; EC2 &gt; Instance &gt; Approved &gt; Root Volume Encryption at Rest&#8217;</p></li><li><p>&#8216;AWS &gt; EC2 &gt; Volume &gt; Approved &gt; Encryption at Rest&#8217;</p></li><li><p>&#8216;AWS &gt; EC2 &gt; Snapshot &gt; Approved &gt; Encryption at Rest&#8217; </p></li></ul><p>To implement more stringent resource level policy and exceptions around encryption.</p><div class="preformatted-block" data-component-name="PreformattedTextBlockToDOM"><label class="hide-text" contenteditable="false">Text within this block will maintain its original spacing when published</label><pre class="text"></pre></div><h2><strong>Make it happen</strong></h2><p>See for yourself on how easy it is to manage your encryption at rest requirements across your cloud resources. A <strong>ready-to-run</strong> Terraform template is available to enable this configuration from the <a href="https://github.com/turbot/tdk/tree/master/control_objectives/aws_ec2_encryption_by_default">Turbot Development Kit (TDK)</a>. If you need any assistance please reach out to <a href="mailto:support@turbot.com">Turbot Support</a>, and keep an eye on your inbox for another Turbot tip next week!</p><p>Cheers,</p><p>Bob</p><p></p>]]></content:encoded></item><item><title><![CDATA[[Turbot On] Well-Architected Automation]]></title><description><![CDATA[Automating the AWS Well-Architected Tool across your entire environment.]]></description><link>https://on.turbot.com/p/turbot-on-well-architected-automation</link><guid isPermaLink="false">https://on.turbot.com/p/turbot-on-well-architected-automation</guid><dc:creator><![CDATA[Bob Tordella]]></dc:creator><pubDate>Mon, 12 Jul 2021 18:51:18 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!b4Az!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb7165c5-1c26-4135-b43d-6fca58668573_1820x1024.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!b4Az!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb7165c5-1c26-4135-b43d-6fca58668573_1820x1024.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!b4Az!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb7165c5-1c26-4135-b43d-6fca58668573_1820x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!b4Az!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb7165c5-1c26-4135-b43d-6fca58668573_1820x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!b4Az!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb7165c5-1c26-4135-b43d-6fca58668573_1820x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!b4Az!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb7165c5-1c26-4135-b43d-6fca58668573_1820x1024.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!b4Az!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb7165c5-1c26-4135-b43d-6fca58668573_1820x1024.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/fb7165c5-1c26-4135-b43d-6fca58668573_1820x1024.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:275271,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!b4Az!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb7165c5-1c26-4135-b43d-6fca58668573_1820x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!b4Az!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb7165c5-1c26-4135-b43d-6fca58668573_1820x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!b4Az!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb7165c5-1c26-4135-b43d-6fca58668573_1820x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!b4Az!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb7165c5-1c26-4135-b43d-6fca58668573_1820x1024.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The AWS Well-Architected Framework was initially developed as a whitepaper in 2012 to help architects moving applications to, or building natively on, AWS. The framework asks introspective questions that lead you to best practices and ensure that application teams are getting the most out of cloud native architectures.</p><p>In 2018, AWS released the first version of the Well-Architected Tool. This service from AWS helps walk application teams through assessment of their workloads against well-architected principals. The tool systematizes the way assessments are performed, and allows the application team building on AWS to gain insight from an expert system. The use of the tool is free; teams just define their workload and answer a set of questions regarding operational excellence, security, reliability, performance efficiency, and cost optimization.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!O-lu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F07945c02-425c-4e3e-a641-0a25d2d3600e_1631x548.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!O-lu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F07945c02-425c-4e3e-a641-0a25d2d3600e_1631x548.png 424w, https://substackcdn.com/image/fetch/$s_!O-lu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F07945c02-425c-4e3e-a641-0a25d2d3600e_1631x548.png 848w, https://substackcdn.com/image/fetch/$s_!O-lu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F07945c02-425c-4e3e-a641-0a25d2d3600e_1631x548.png 1272w, https://substackcdn.com/image/fetch/$s_!O-lu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F07945c02-425c-4e3e-a641-0a25d2d3600e_1631x548.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!O-lu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F07945c02-425c-4e3e-a641-0a25d2d3600e_1631x548.png" width="1456" height="489" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/07945c02-425c-4e3e-a641-0a25d2d3600e_1631x548.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:489,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:43765,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!O-lu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F07945c02-425c-4e3e-a641-0a25d2d3600e_1631x548.png 424w, https://substackcdn.com/image/fetch/$s_!O-lu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F07945c02-425c-4e3e-a641-0a25d2d3600e_1631x548.png 848w, https://substackcdn.com/image/fetch/$s_!O-lu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F07945c02-425c-4e3e-a641-0a25d2d3600e_1631x548.png 1272w, https://substackcdn.com/image/fetch/$s_!O-lu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F07945c02-425c-4e3e-a641-0a25d2d3600e_1631x548.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="preformatted-block" data-component-name="PreformattedTextBlockToDOM"><label class="hide-text" contenteditable="false">Text within this block will maintain its original spacing when published</label><pre class="text"></pre></div><blockquote><h4><strong>This week&#8217;s Turbot On looks at how to leverage the AWS Well-Architected tool for large organizations with hundreds (or thousands) of AWS accounts.</strong></h4></blockquote><div class="preformatted-block" data-component-name="PreformattedTextBlockToDOM"><label class="hide-text" contenteditable="false">Text within this block will maintain its original spacing when published</label><pre class="text"></pre></div><p>Turbot has long promoted the benefits of multi-account isolation when it comes to enterprise use of AWS. In this model each application workload is deployed into separate AWS accounts with some common centrally managed infrastructure. This allows the application team to focus on building their application, and the centralized cloud operations and security teams to standardize critical security, compliance and data protection setup that should be consistent across the organization.</p><p>However, this poses two challenges for organizations looking to leverage the AWS Well-Architected Tool. First, the application teams have less knowledge of some key infrastructure for their accounts; if the cloud operations team is deploying their VPC configuration or their CloudTrail logging is centralized, it can make it difficult for the application team to answer many of the questions in the Well-Architected review. Secondly, very large enterprises have a scale issue. Namely, how do you conduct thorough reviews across hundreds of AWS accounts and ensure that the application teams are asking and answering the right questions. </p><div class="preformatted-block" data-component-name="PreformattedTextBlockToDOM"><label class="hide-text" contenteditable="false">Text within this block will maintain its original spacing when published</label><pre class="text"></pre></div><h2><strong>Get it Done with Turbot</strong></h2><p>Turbot&#8217;s automation can ensure that Well-Architected Framework questions are automatically answered, covering aspects of the application and infrastructure architecture that are centrally managed (e.g. Networking, Identity, etc). Automatically answering common questions helps reduce the amount of work required for a Well-Architected review, which removes excuses and decreases the time &amp; effort application teams spend on their assessments.</p><p>Questions can be answered statically and dynamically. </p><ol><li><p><strong>Static answers</strong> can be used when a centralized deployment, tool, process, etc. covers the intent of the question on behalf of the application team. They can also cover the case of &#8216;Not Applicable&#8217; when questions are not relevant to the workload.</p></li><li><p><strong>Dynamic answers</strong> are based on conditional logic. Using Turbot&#8217;s <a href="https://turbot.com/v5/docs/concepts/policies/calculated-faq">Calculated Policies</a>, data from the Turbot CMDB can be used to evaluate the appropriate answer to specific review questions based on resource or Turbot configuration.</p></li></ol><p>Turbot has two Mods that work together for automating the Well-Architected Tool. The &#8216;<strong>aws-wellarchitected</strong>` Mod automates configuration of the Well-Architected Tool and associated Workloads, and the &#8216;<strong>aws-wellarchitected-framework</strong>&#8217; Mod which has 340+ policies that allow your team to automate answers to the default &#8216;<a href="https://docs.aws.amazon.com/wellarchitected/latest/userguide/lenses.html">AWS Well-Architected Tool Framework Lens</a>&#8217;.&nbsp;</p><div class="preformatted-block" data-component-name="PreformattedTextBlockToDOM"><label class="hide-text" contenteditable="false">Text within this block will maintain its original spacing when published</label><pre class="text"></pre></div><h4><strong>Static Example:</strong></h4><p>In this example, our network is centrally managed, so the cloud operations team will configure Turbot to automatically answer questions related to the organization&#8217;s network configuration. In the UI we can browse the framework questions and see potential answers:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4Cc2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd33b08e-b645-44ef-8ad9-c09601282316_2657x1584.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4Cc2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd33b08e-b645-44ef-8ad9-c09601282316_2657x1584.png 424w, https://substackcdn.com/image/fetch/$s_!4Cc2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd33b08e-b645-44ef-8ad9-c09601282316_2657x1584.png 848w, https://substackcdn.com/image/fetch/$s_!4Cc2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd33b08e-b645-44ef-8ad9-c09601282316_2657x1584.png 1272w, https://substackcdn.com/image/fetch/$s_!4Cc2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd33b08e-b645-44ef-8ad9-c09601282316_2657x1584.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4Cc2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd33b08e-b645-44ef-8ad9-c09601282316_2657x1584.png" width="1456" height="868" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/bd33b08e-b645-44ef-8ad9-c09601282316_2657x1584.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:868,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:509584,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4Cc2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd33b08e-b645-44ef-8ad9-c09601282316_2657x1584.png 424w, https://substackcdn.com/image/fetch/$s_!4Cc2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd33b08e-b645-44ef-8ad9-c09601282316_2657x1584.png 848w, https://substackcdn.com/image/fetch/$s_!4Cc2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd33b08e-b645-44ef-8ad9-c09601282316_2657x1584.png 1272w, https://substackcdn.com/image/fetch/$s_!4Cc2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd33b08e-b645-44ef-8ad9-c09601282316_2657x1584.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>To automate the answer to this question across all 300 of our AWS accounts, we only need to set two policies.&nbsp; First, let&#8217;s choose the <strong>&#8216;Enforce non-overlapping private IP address ranges&#8230;&#8217;</strong> answer:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hdpS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb45b8cb9-3dea-4438-95d4-dad2195ddd85_2657x1584.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hdpS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb45b8cb9-3dea-4438-95d4-dad2195ddd85_2657x1584.png 424w, https://substackcdn.com/image/fetch/$s_!hdpS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb45b8cb9-3dea-4438-95d4-dad2195ddd85_2657x1584.png 848w, https://substackcdn.com/image/fetch/$s_!hdpS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb45b8cb9-3dea-4438-95d4-dad2195ddd85_2657x1584.png 1272w, https://substackcdn.com/image/fetch/$s_!hdpS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb45b8cb9-3dea-4438-95d4-dad2195ddd85_2657x1584.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hdpS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb45b8cb9-3dea-4438-95d4-dad2195ddd85_2657x1584.png" width="1456" height="868" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/b45b8cb9-3dea-4438-95d4-dad2195ddd85_2657x1584.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:868,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:383460,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hdpS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb45b8cb9-3dea-4438-95d4-dad2195ddd85_2657x1584.png 424w, https://substackcdn.com/image/fetch/$s_!hdpS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb45b8cb9-3dea-4438-95d4-dad2195ddd85_2657x1584.png 848w, https://substackcdn.com/image/fetch/$s_!hdpS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb45b8cb9-3dea-4438-95d4-dad2195ddd85_2657x1584.png 1272w, https://substackcdn.com/image/fetch/$s_!hdpS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb45b8cb9-3dea-4438-95d4-dad2195ddd85_2657x1584.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Now that the appropriate answer is chosen for our workloads, we tell Turbot to apply the answer via the parent policy:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yEqK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e27e50-4af0-45a7-b147-4a9a12278798_2654x1612.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yEqK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e27e50-4af0-45a7-b147-4a9a12278798_2654x1612.png 424w, https://substackcdn.com/image/fetch/$s_!yEqK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e27e50-4af0-45a7-b147-4a9a12278798_2654x1612.png 848w, https://substackcdn.com/image/fetch/$s_!yEqK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e27e50-4af0-45a7-b147-4a9a12278798_2654x1612.png 1272w, https://substackcdn.com/image/fetch/$s_!yEqK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e27e50-4af0-45a7-b147-4a9a12278798_2654x1612.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yEqK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e27e50-4af0-45a7-b147-4a9a12278798_2654x1612.png" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/a2e27e50-4af0-45a7-b147-4a9a12278798_2654x1612.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:379336,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yEqK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e27e50-4af0-45a7-b147-4a9a12278798_2654x1612.png 424w, https://substackcdn.com/image/fetch/$s_!yEqK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e27e50-4af0-45a7-b147-4a9a12278798_2654x1612.png 848w, https://substackcdn.com/image/fetch/$s_!yEqK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e27e50-4af0-45a7-b147-4a9a12278798_2654x1612.png 1272w, https://substackcdn.com/image/fetch/$s_!yEqK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e27e50-4af0-45a7-b147-4a9a12278798_2654x1612.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>These same controls can also be configured via Turbot&#8217;s Terraform provider:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0hAE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5fab7869-ca22-4924-bebd-32c72f297eef_4400x2468.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0hAE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5fab7869-ca22-4924-bebd-32c72f297eef_4400x2468.png 424w, https://substackcdn.com/image/fetch/$s_!0hAE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5fab7869-ca22-4924-bebd-32c72f297eef_4400x2468.png 848w, https://substackcdn.com/image/fetch/$s_!0hAE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5fab7869-ca22-4924-bebd-32c72f297eef_4400x2468.png 1272w, https://substackcdn.com/image/fetch/$s_!0hAE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5fab7869-ca22-4924-bebd-32c72f297eef_4400x2468.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0hAE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5fab7869-ca22-4924-bebd-32c72f297eef_4400x2468.png" width="1456" height="817" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/5fab7869-ca22-4924-bebd-32c72f297eef_4400x2468.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:817,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:462868,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0hAE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5fab7869-ca22-4924-bebd-32c72f297eef_4400x2468.png 424w, https://substackcdn.com/image/fetch/$s_!0hAE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5fab7869-ca22-4924-bebd-32c72f297eef_4400x2468.png 848w, https://substackcdn.com/image/fetch/$s_!0hAE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5fab7869-ca22-4924-bebd-32c72f297eef_4400x2468.png 1272w, https://substackcdn.com/image/fetch/$s_!0hAE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5fab7869-ca22-4924-bebd-32c72f297eef_4400x2468.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4><strong>Dynamic example 1 - using CMDB resource metadata:</strong></h4><p>In this example, our KMS keys are classified with specific tags which identify they are centrally managed. If the keys are present in the account, you can use Turbot&#8217;s Calculated Policies to lookup information from the CMDB to decide on the answer to specific questions. As an example in &#8220;SEC 08. How do you protect your data at rest?&#8221; One of the available answers is &#8220;Implement secure key management&#8221;.</p><p>Using a calculated policy Turbot checks to see if a specifically tagged KMS key is present in the current account. If Turbot finds the key it sets the answer to the Framework question to be &#8216;True&#8217; if not found, the value is set to false.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dGm1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fac3bd3a3-e592-427d-a401-74b1598886d9_2326x1286.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dGm1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fac3bd3a3-e592-427d-a401-74b1598886d9_2326x1286.png 424w, https://substackcdn.com/image/fetch/$s_!dGm1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fac3bd3a3-e592-427d-a401-74b1598886d9_2326x1286.png 848w, https://substackcdn.com/image/fetch/$s_!dGm1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fac3bd3a3-e592-427d-a401-74b1598886d9_2326x1286.png 1272w, https://substackcdn.com/image/fetch/$s_!dGm1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fac3bd3a3-e592-427d-a401-74b1598886d9_2326x1286.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dGm1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fac3bd3a3-e592-427d-a401-74b1598886d9_2326x1286.png" width="1456" height="805" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/ac3bd3a3-e592-427d-a401-74b1598886d9_2326x1286.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:805,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:231732,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dGm1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fac3bd3a3-e592-427d-a401-74b1598886d9_2326x1286.png 424w, https://substackcdn.com/image/fetch/$s_!dGm1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fac3bd3a3-e592-427d-a401-74b1598886d9_2326x1286.png 848w, https://substackcdn.com/image/fetch/$s_!dGm1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fac3bd3a3-e592-427d-a401-74b1598886d9_2326x1286.png 1272w, https://substackcdn.com/image/fetch/$s_!dGm1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fac3bd3a3-e592-427d-a401-74b1598886d9_2326x1286.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4><strong>Dynamic example 2 - using control states in Turbot:</strong></h4><p>In this example, our organization has encryption at rest requirements for many AWS services. Instead of enumerating checks on all the required services, we will use the <a href="https://turbot.com/v5/mods/turbot/turbot/inspect#/control/categories/resourceEncryptionAtRest">Encryption at Rest</a> control category to evaluate if encryption at rest controls are applied effectively. <a href="https://turbot.com/v5/docs/concepts/controls#control-categories">Control categories</a> aggregate related policies across services and across cloud platforms. You can use Turbot&#8217;s Calculated Policies to look for evidence that Encryption at rest controls are in use to answer the question &#8220;<strong>SEC 08. How do you protect your data at rest?</strong>&#8221;.</p><p>This calculated policy will count the controls in &#8216;<strong>ok&#8217;</strong> and &#8216;<strong>alarm</strong>&#8217; state for a given scope. If Turbot finds evidence that 1 or more controls are in place it sets the answer to the question to &#8216;True&#8217; and if it finds no active controls it will set the value to &#8216;False&#8217;.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EDH_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fee3df2c8-1f34-46c9-b578-2278e9993a54_1962x1296.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EDH_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fee3df2c8-1f34-46c9-b578-2278e9993a54_1962x1296.png 424w, https://substackcdn.com/image/fetch/$s_!EDH_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fee3df2c8-1f34-46c9-b578-2278e9993a54_1962x1296.png 848w, https://substackcdn.com/image/fetch/$s_!EDH_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fee3df2c8-1f34-46c9-b578-2278e9993a54_1962x1296.png 1272w, https://substackcdn.com/image/fetch/$s_!EDH_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fee3df2c8-1f34-46c9-b578-2278e9993a54_1962x1296.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EDH_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fee3df2c8-1f34-46c9-b578-2278e9993a54_1962x1296.png" width="1456" height="962" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/ee3df2c8-1f34-46c9-b578-2278e9993a54_1962x1296.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:962,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:217867,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!EDH_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fee3df2c8-1f34-46c9-b578-2278e9993a54_1962x1296.png 424w, https://substackcdn.com/image/fetch/$s_!EDH_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fee3df2c8-1f34-46c9-b578-2278e9993a54_1962x1296.png 848w, https://substackcdn.com/image/fetch/$s_!EDH_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fee3df2c8-1f34-46c9-b578-2278e9993a54_1962x1296.png 1272w, https://substackcdn.com/image/fetch/$s_!EDH_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fee3df2c8-1f34-46c9-b578-2278e9993a54_1962x1296.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Once any static and or calculated policies are set, Turbot will automatically discover all workloads configured in the Well-Architected Tool and apply the defined answers to the specified questions. These policies can be futher grouped into Turbot Smart Folders to apply to specific classes of AWS accounts (e.g. &#8216;Production&#8217;, &#8216;Development&#8217;, etc.).</p><div class="preformatted-block" data-component-name="PreformattedTextBlockToDOM"><label class="hide-text" contenteditable="false">Text within this block will maintain its original spacing when published</label><pre class="text"></pre></div><h2><strong>Make it happen</strong></h2><p>See for yourself how Turbot can help you manage Workload Assessments at scale. As you are working towards setting these policies, an initial baseline to get started is available from the <a href="https://github.com/turbot/tdk/tree/master/baselines/aws/aws_well_architected_tool">Turbot Development Kit (TDK)</a>. Additional calculated policy examples for dynamic answers (<a href="https://github.com/turbot/tdk/tree/master/calculated_policies/aws_well-architected_security_key_management">resource data</a> and <a href="https://github.com/turbot/tdk/tree/master/calculated_policies/aws_well-architected_security_encryption">control states</a>) are also available in the TDK in the calculated policies section. If you need any assistance please reach out to <a href="mailto:support@turbot.com">Turbot Support</a>, and keep an eye on your inbox for another Turbot tip next week!</p><p>Cheers,</p><p>Bob</p>]]></content:encoded></item><item><title><![CDATA[[Turbot On] ECR Vulnerability Scanning]]></title><description><![CDATA[Automate vulnerability scanning in all your ECR repositories.]]></description><link>https://on.turbot.com/p/turbot-on-ecr-vulnerability-scanning</link><guid isPermaLink="false">https://on.turbot.com/p/turbot-on-ecr-vulnerability-scanning</guid><dc:creator><![CDATA[Bob Tordella]]></dc:creator><pubDate>Mon, 28 Jun 2021 17:52:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!8Oj3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb78c3a8a-a897-4b97-a557-26d40b7df374_1813x900.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8Oj3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb78c3a8a-a897-4b97-a557-26d40b7df374_1813x900.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8Oj3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb78c3a8a-a897-4b97-a557-26d40b7df374_1813x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!8Oj3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb78c3a8a-a897-4b97-a557-26d40b7df374_1813x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!8Oj3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb78c3a8a-a897-4b97-a557-26d40b7df374_1813x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!8Oj3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb78c3a8a-a897-4b97-a557-26d40b7df374_1813x900.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8Oj3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb78c3a8a-a897-4b97-a557-26d40b7df374_1813x900.jpeg" width="1456" height="723" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/b78c3a8a-a897-4b97-a557-26d40b7df374_1813x900.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:723,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:142271,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8Oj3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb78c3a8a-a897-4b97-a557-26d40b7df374_1813x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!8Oj3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb78c3a8a-a897-4b97-a557-26d40b7df374_1813x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!8Oj3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb78c3a8a-a897-4b97-a557-26d40b7df374_1813x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!8Oj3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb78c3a8a-a897-4b97-a557-26d40b7df374_1813x900.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Amazon Elastic Container Registry (Amazon ECR) can be used to host private container image repositories in AWS. This allows teams great flexibility in choice of centralizing or federating repositories for your application teams.</p><p>One of the key benefits of moving to a container architecture for your application is to microsegment application functionality with immutable containers for greater security. To maintain that secure configuration, the software libraries used in each container should be scanned for vulnerabilities.</p><p>The <a href="https://github.com/quay/clair">open source Clair project</a> maintains a list of known vulnerabilities and tools for static analysis of your application containers. Amazon ECR uses the Common Vulnerabilities and Exposures (CVEs) database from the Clair project and provides a list of scan findings. You can review the scan findings for information about the security of the container images that are being deployed.</p><p>You can manually scan container images stored in Amazon ECR. Or, alternatively, you can configure your repositories to scan images when you push them to a repository.&nbsp;</p><h4><strong>In today&#8217;s Turbot On we look at how you can easily enable Turbot to enforce automated scanning of every container when they are pushed to your repositories.</strong></h4><div class="preformatted-block" data-component-name="PreformattedTextBlockToDOM"><label class="hide-text" contenteditable="false">Text within this block will maintain its original spacing when published</label><pre class="text"></pre></div><h2><strong>Traditional Workflow</strong></h2><p>The popularity of ECR with application development teams means that you may have dozens (or hundreds) of ECR Repositories across your environment and new ones will be created at any time. Relying on application teams to manually enable scan on push configuration in their development environments can lead to last minute discovery of issues as those teams release software. Automation is needed to support discovery of existing and future ECR repositories, and automated configuration of the scan on push setting.</p><div class="preformatted-block" data-component-name="PreformattedTextBlockToDOM"><label class="hide-text" contenteditable="false">Text within this block will maintain its original spacing when published</label><pre class="text"></pre></div><h2><strong>Get it done with Turbot</strong></h2><p>In Turbot, Amazon ECR Repository guardrails are readily available to control your cloud resource configurations. We can set the Turbot automation `<strong>AWS &gt; ECR &gt; Repository &gt; Scan on Push</strong>` policy in just a few clicks:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2MDJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6c369946-ad84-461d-a4ac-ae1964f2585c_1523x1319.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2MDJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6c369946-ad84-461d-a4ac-ae1964f2585c_1523x1319.png 424w, https://substackcdn.com/image/fetch/$s_!2MDJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6c369946-ad84-461d-a4ac-ae1964f2585c_1523x1319.png 848w, https://substackcdn.com/image/fetch/$s_!2MDJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6c369946-ad84-461d-a4ac-ae1964f2585c_1523x1319.png 1272w, https://substackcdn.com/image/fetch/$s_!2MDJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6c369946-ad84-461d-a4ac-ae1964f2585c_1523x1319.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2MDJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6c369946-ad84-461d-a4ac-ae1964f2585c_1523x1319.png" width="1456" height="1261" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/6c369946-ad84-461d-a4ac-ae1964f2585c_1523x1319.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1261,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:113011,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2MDJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6c369946-ad84-461d-a4ac-ae1964f2585c_1523x1319.png 424w, https://substackcdn.com/image/fetch/$s_!2MDJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6c369946-ad84-461d-a4ac-ae1964f2585c_1523x1319.png 848w, https://substackcdn.com/image/fetch/$s_!2MDJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6c369946-ad84-461d-a4ac-ae1964f2585c_1523x1319.png 1272w, https://substackcdn.com/image/fetch/$s_!2MDJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6c369946-ad84-461d-a4ac-ae1964f2585c_1523x1319.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Setting the configuration <a href="https://turbot.com/v5/docs/reference/terraform">via our Terraform Provider</a> is just as simple:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CJzs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4a6c820c-239a-4ff3-a324-ed2845c2a699_3192x1820.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CJzs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4a6c820c-239a-4ff3-a324-ed2845c2a699_3192x1820.png 424w, https://substackcdn.com/image/fetch/$s_!CJzs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4a6c820c-239a-4ff3-a324-ed2845c2a699_3192x1820.png 848w, https://substackcdn.com/image/fetch/$s_!CJzs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4a6c820c-239a-4ff3-a324-ed2845c2a699_3192x1820.png 1272w, https://substackcdn.com/image/fetch/$s_!CJzs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4a6c820c-239a-4ff3-a324-ed2845c2a699_3192x1820.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CJzs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4a6c820c-239a-4ff3-a324-ed2845c2a699_3192x1820.png" width="1456" height="830" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/4a6c820c-239a-4ff3-a324-ed2845c2a699_3192x1820.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:830,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:262983,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CJzs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4a6c820c-239a-4ff3-a324-ed2845c2a699_3192x1820.png 424w, https://substackcdn.com/image/fetch/$s_!CJzs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4a6c820c-239a-4ff3-a324-ed2845c2a699_3192x1820.png 848w, https://substackcdn.com/image/fetch/$s_!CJzs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4a6c820c-239a-4ff3-a324-ed2845c2a699_3192x1820.png 1272w, https://substackcdn.com/image/fetch/$s_!CJzs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4a6c820c-239a-4ff3-a324-ed2845c2a699_3192x1820.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>After setting these policies, Turbot will identify all ECR repositories without Scan on Push enabled and then handle remediation (i.e. enable Scan on Push).&nbsp;</p><p>If you are not yet ready to enforce remediation, you can still assess your environment&#8217;s ECR Repository Scan on Push compliance by setting the value of the policy to &#8216;<strong>Check: Enabled</strong>&#8217; at the Turbot level. In &#8216;Check&#8217; mode Turbot will alarm on Amazon ECR Repositories that do not have Scan on Push in place. After review of the alarms, selectively apply the enforcement settings or create exceptions as desired.&nbsp;</p><p>Given that Scan on Push may not be applicable for all repositories, make use of Turbot&#8217;s <a href="https://turbot.com/v5/docs/guides/managing-policies#creating-an-exception">policy exceptions</a> and <a href="https://turbot.com/v5/docs/concepts/policies/values-settings#expiration">time-based expiration</a> settings features to mark exceptions to the rule or automatically reset a configuration when the exception expires.</p><div class="preformatted-block" data-component-name="PreformattedTextBlockToDOM"><label class="hide-text" contenteditable="false">Text within this block will maintain its original spacing when published</label><pre class="text"></pre></div><h2><strong>Make it happen</strong></h2><p>See for yourself how easy it is to manage your image scanning requirements across your cloud resources. A <strong>ready-to-run</strong> Terraform template is available to enable this configuration from the <a href="https://github.com/turbot/tdk/tree/master/control_objectives/aws_ecr_repo_scan_on_push">Turbot Development Kit (TDK)</a>. If you need any assistance please reach out to <a href="mailto:support@turbot.com">Turbot Support</a>, and keep an eye on your inbox for another Turbot tip next week!</p><p>Cheers,</p><p>Bob</p>]]></content:encoded></item><item><title><![CDATA[Turbot Product Updates]]></title><description><![CDATA[Monthly highlights of Turbot product changes]]></description><link>https://on.turbot.com/p/turbot-product-updates-5e1</link><guid isPermaLink="false">https://on.turbot.com/p/turbot-product-updates-5e1</guid><dc:creator><![CDATA[Bob Tordella]]></dc:creator><pubDate>Thu, 24 Jun 2021 17:59:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!SUSX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F548c86eb-b010-4cbc-8fd0-4ebaf85b1920_6365x4243.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SUSX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F548c86eb-b010-4cbc-8fd0-4ebaf85b1920_6365x4243.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SUSX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F548c86eb-b010-4cbc-8fd0-4ebaf85b1920_6365x4243.png 424w, https://substackcdn.com/image/fetch/$s_!SUSX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F548c86eb-b010-4cbc-8fd0-4ebaf85b1920_6365x4243.png 848w, https://substackcdn.com/image/fetch/$s_!SUSX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F548c86eb-b010-4cbc-8fd0-4ebaf85b1920_6365x4243.png 1272w, https://substackcdn.com/image/fetch/$s_!SUSX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F548c86eb-b010-4cbc-8fd0-4ebaf85b1920_6365x4243.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SUSX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F548c86eb-b010-4cbc-8fd0-4ebaf85b1920_6365x4243.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/548c86eb-b010-4cbc-8fd0-4ebaf85b1920_6365x4243.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:17409468,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!SUSX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F548c86eb-b010-4cbc-8fd0-4ebaf85b1920_6365x4243.png 424w, https://substackcdn.com/image/fetch/$s_!SUSX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F548c86eb-b010-4cbc-8fd0-4ebaf85b1920_6365x4243.png 848w, https://substackcdn.com/image/fetch/$s_!SUSX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F548c86eb-b010-4cbc-8fd0-4ebaf85b1920_6365x4243.png 1272w, https://substackcdn.com/image/fetch/$s_!SUSX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F548c86eb-b010-4cbc-8fd0-4ebaf85b1920_6365x4243.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Turbot Mod Changes</h2><ul><li><p>AWS SageMaker controls for Model, Training Job, Endpoint, Service</p></li><li><p>Improvements on AWS Event Rule sorting in CMDB data to remain consistent</p></li><li><p>EC2 Instance CMDB supporting EC2:BidEvictedEvent for spot instances</p></li><li><p>EC2 Snapshot discovery and CMDB handling improvements</p></li><li><p>Turbot Firehose updated templates in support of StreamAlert integration</p></li></ul><p>Additional updates can be found in the full <a href="https://turbot.com/v5/docs/releases/mods">Release Notes</a>.</p><div class="preformatted-block" data-component-name="PreformattedTextBlockToDOM"><label class="hide-text" contenteditable="false">Text within this block will maintain its original spacing when published</label><pre class="text"></pre></div><h2>Turbot UI Changes</h2><ul><li><p>AWS External ID while in protected mode now accepts a custom suffix input copied into the UI.</p></li><li><p>Aging calculations in all reports now correctly calculate the duration.</p></li></ul><p>Additional updates can be found in the <a href="https://turbot.com/v5/docs/releases/te">full TE Release Notes</a>.</p><div class="preformatted-block" data-component-name="PreformattedTextBlockToDOM"><label class="hide-text" contenteditable="false">Text within this block will maintain its original spacing when published</label><pre class="text"></pre></div><h2>Turbot Enterprise Changes</h2><p>The current recommended deployment versions for Turbot Enterprise are updated here: <a href="https://turbot.com/v5/docs/releases">https://turbot.com/v5/docs/releases</a></p><blockquote><p>Apollo becoming new default UI</p></blockquote><p>In the upcoming v5.37.0 release, the default UI for all Turbot users will become the Turbot Console Apollo UI. For users already using the Apollo UI, no change will occur, and for users who still prefer the original UI, you can switch back with a link in the header of the console. For Turbot Cloud (SaaS) customers this change will occur automatically.&nbsp; For Turbot Enterprise customers this change will occur when you upgrade to the v5.37.0 release or higher.</p><p>The existing (non-Apollo) console will be considered deprecated in the v5.37.0 release, and in a few months, the v5.40.0 release will fully remove the non-Apollo UI. This will not impact APIs, but will impact saved URLs pointing to specific screens in the old UI.</p><p>Since its release in Nov 2020, the Apollo UI is the preferred UI among Turbot users. You can learn more about Apollo in our <a href="https://www.youtube.com/watch?v=z7VmiU4FFfM">highlights video</a>.</p><div class="preformatted-block" data-component-name="PreformattedTextBlockToDOM"><label class="hide-text" contenteditable="false">Text within this block will maintain its original spacing when published</label><pre class="text"></pre></div><h4>Key Performance Improvements:</h4><ul><li><p>Moving resources to new locations in the hierarchy is more responsive in the UI.</p></li><li><p>Cleanup of unused tables (action_history) and unused indexes (controls_history, resources_history, and policy_values_history) to reduce DB disk space.</p></li><li><p>Critical database indexes are now re-created weekly to improve performance.</p></li><li><p>Improved handling for long running control to avoid infinite execution.</p></li></ul><ul><li><p>DB parameter group support for 11.10, 11.11, 12.6 and 13.2.</p></li><li><p>Postgres version 13.2 is now the default selection; Turbot continues to support Postgres 11 and 12.&nbsp; New installations will default to Postgres 13.x.&nbsp; When appropriate, we will recommend an update path from 11.x &amp; 12.x to 13.x</p><div class="preformatted-block" data-component-name="PreformattedTextBlockToDOM"><label class="hide-text" contenteditable="false">Text within this block will maintain its original spacing when published</label><pre class="text"></pre></div></li></ul><h4>Full Release Notes:</h4><ul><li><p><a href="https://turbot.com/v5/docs/releases/te">Turbot Enterprise</a></p></li><li><p><a href="https://turbot.com/v5/docs/releases/tef">Turbot Enterprise Foundation (TEF)</a></p></li><li><p><a href="https://turbot.com/v5/docs/releases/ted">Turbot Enterprise Database (TED)</a></p></li></ul><div class="preformatted-block" data-component-name="PreformattedTextBlockToDOM"><label class="hide-text" contenteditable="false">Text within this block will maintain its original spacing when published</label><pre class="text"></pre></div><h4>Turbot Developer Tools</h4><p><strong>Terraform</strong> - <a href="https://turbot.com/v5/docs/releases/terraform">https://turbot.com/v5/docs/releases/terraform</a></p><ul><li><p>FAQ Guide - <a href="https://turbot.com/v5/docs/faq/terraform-faq#how-do-i-create-a-resource-with-multiple-akas">How do I create a resource with multiple AKAs?</a></p></li></ul><p><strong>Turbot CLI</strong> - <a href="https://turbot.com/v5/docs/releases/cli">https://turbot.com/v5/docs/releases/cli</a></p><ul><li><p>FAQ guide - <a href="https://turbot.com/v5/docs/faq/general-faq#can-i-use-cligraphql-command-to-get-the-list-of-current-users-and-their-associated-grants">Can I use cli/graphql command to get the list of current users and their associated grants?</a></p></li></ul><p><strong>Turbot Plugin for Steampipe: </strong><a href="https://hub.steampipe.io/plugins/turbot/turbot">https://hub.steampipe.io/plugins/turbot/turbot</a></p><ul><li><p>Initial release of the plugin provides an open source CLI to instantly query Turbot&#8217;s API using SQL!&nbsp; The initial tables supported are controls, policies, resources, smart folders and tags.</p></li></ul><p>You can <a href="https://github.com/turbot/steampipe-plugin-turbot">contribute to the project</a> and keep us posted on any feedback and suggestions.</p><div class="preformatted-block" data-component-name="PreformattedTextBlockToDOM"><label class="hide-text" contenteditable="false">Text within this block will maintain its original spacing when published</label><pre class="text"></pre></div><h4>Turbot On Posts</h4><ul><li><p><a href="https://on.turbot.com/p/turbot-on-managing-default-routes">[Turbot On] Managing default routes &#8216;0.0.0.0/0&#8217;</a> - how to manage security group rules for public facing accounts.&nbsp;</p></li><li><p><a href="https://on.turbot.com/p/turbot-on-custom-cmdb-data">[Turbot On] Custom CMDB Data</a> - how to import your org&#8217;s custom reference data into the Turbot CMDB.</p></li><li><p><a href="https://on.turbot.com/p/turbot-on-s3-bucket-logging">[Turbot On] S3 Bucket Logging</a> - how to automate server access logging on your S3 buckets.</p></li><li><p><a href="https://on.turbot.com/p/turbot-on-encryption-at-rest-for">[Turbot On] Encryption at Rest for SNS</a> - how to enforce encryption at rest to all your Amazon SNS topics.</p></li><li><p><a href="https://on.turbot.com/p/turbot-product-updates">[Turbot On] Turbot Product Updates</a> - April highlights of Turbot product changes.</p></li></ul>]]></content:encoded></item><item><title><![CDATA[[Turbot On] Managing default routes '0.0.0.0/0']]></title><description><![CDATA[How to manage security group rules for public facing accounts.]]></description><link>https://on.turbot.com/p/turbot-on-managing-default-routes</link><guid isPermaLink="false">https://on.turbot.com/p/turbot-on-managing-default-routes</guid><dc:creator><![CDATA[Bob Tordella]]></dc:creator><pubDate>Mon, 21 Jun 2021 17:25:08 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!mIhC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F353c238e-121c-45c6-b35a-3340954709ae_1600x900.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mIhC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F353c238e-121c-45c6-b35a-3340954709ae_1600x900.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mIhC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F353c238e-121c-45c6-b35a-3340954709ae_1600x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!mIhC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F353c238e-121c-45c6-b35a-3340954709ae_1600x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!mIhC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F353c238e-121c-45c6-b35a-3340954709ae_1600x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!mIhC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F353c238e-121c-45c6-b35a-3340954709ae_1600x900.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mIhC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F353c238e-121c-45c6-b35a-3340954709ae_1600x900.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/353c238e-121c-45c6-b35a-3340954709ae_1600x900.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:106255,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mIhC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F353c238e-121c-45c6-b35a-3340954709ae_1600x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!mIhC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F353c238e-121c-45c6-b35a-3340954709ae_1600x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!mIhC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F353c238e-121c-45c6-b35a-3340954709ae_1600x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!mIhC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F353c238e-121c-45c6-b35a-3340954709ae_1600x900.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The default route &#8216;0.0.0.0/0&#8217; is treated as evil by many organizations; most security scanning tools will flag any security group containing a default route as insecure. The default route is often improperly used when troubleshooting connectivity issues and frequently used by lazy developers as a shortcut. However, there are many legitimate uses of the default route.</p><p>Given that the deployment of public facing websites, web apps and open APIs are increasing in number (even for large enterprises), it makes sense to find more nuanced ways of providing governance for these accounts and the security groups within them.</p><h4>This week [Turbot On] focuses on how to write governance controls for public facing security groups.&nbsp; We will use AWS as an example, but the same principals and process will work for Azure and GCP as well.</h4><h2><strong>Traditional Workflow</strong></h2><p>Many large organizations have historically outsourced public facing websites and web applications to 3rd parties to reduce the liability of having public endpoints into their data centers.&nbsp; In the world of cloud-based systems, this makes little sense, but the phobia of the default route continues to persist. We see organizations struggle with how to manage exceptions for these types of applications. Groups that leave the false positive alarms in place suffer from alert fatigue and teams that turn them off expose themselves to real vulnerabilities.</p><h2><strong>Get it done with Turbot</strong></h2><p>Turbot&#8217;s <a href="https://turbot.com/v5/docs/guides/managing-policies/OCL">Object Constraint Language</a> (OCL) gives you great flexibility and control over security group rules.&nbsp; OCL works using simple REJECT and APPROVE filters. It executes from top to bottom and the first matching filter wins. Cleverly constructing the order of the filter statements allows for a wide variety of policy implementations.&nbsp; We can implement these rules individually for ingress and egress rules using policies like AWS &gt; VPC &gt; Security Group &gt; Ingress Rules &gt; Approved &gt; Rules:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!eQuR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3b2fff31-9c7f-4bbc-8856-0c4e21bada5b_1697x1114.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!eQuR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3b2fff31-9c7f-4bbc-8856-0c4e21bada5b_1697x1114.png 424w, https://substackcdn.com/image/fetch/$s_!eQuR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3b2fff31-9c7f-4bbc-8856-0c4e21bada5b_1697x1114.png 848w, https://substackcdn.com/image/fetch/$s_!eQuR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3b2fff31-9c7f-4bbc-8856-0c4e21bada5b_1697x1114.png 1272w, https://substackcdn.com/image/fetch/$s_!eQuR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3b2fff31-9c7f-4bbc-8856-0c4e21bada5b_1697x1114.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!eQuR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3b2fff31-9c7f-4bbc-8856-0c4e21bada5b_1697x1114.png" width="1456" height="956" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/3b2fff31-9c7f-4bbc-8856-0c4e21bada5b_1697x1114.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:956,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:203883,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!eQuR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3b2fff31-9c7f-4bbc-8856-0c4e21bada5b_1697x1114.png 424w, https://substackcdn.com/image/fetch/$s_!eQuR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3b2fff31-9c7f-4bbc-8856-0c4e21bada5b_1697x1114.png 848w, https://substackcdn.com/image/fetch/$s_!eQuR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3b2fff31-9c7f-4bbc-8856-0c4e21bada5b_1697x1114.png 1272w, https://substackcdn.com/image/fetch/$s_!eQuR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3b2fff31-9c7f-4bbc-8856-0c4e21bada5b_1697x1114.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In the simple rule above, we reject any ingress rule that uses the IPV4 default route (0.0.0.0/0) or the IPV6 default route (::/0).&nbsp; For our public facing web application let&#8217;s create a rule that allows http/https traffic (ports 80 and 443) with a default route source, but denies other usage of it:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lATL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc69bf5ae-f5c7-4e4e-adb3-0f49b28e8088_1697x1114.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lATL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc69bf5ae-f5c7-4e4e-adb3-0f49b28e8088_1697x1114.png 424w, https://substackcdn.com/image/fetch/$s_!lATL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc69bf5ae-f5c7-4e4e-adb3-0f49b28e8088_1697x1114.png 848w, https://substackcdn.com/image/fetch/$s_!lATL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc69bf5ae-f5c7-4e4e-adb3-0f49b28e8088_1697x1114.png 1272w, https://substackcdn.com/image/fetch/$s_!lATL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc69bf5ae-f5c7-4e4e-adb3-0f49b28e8088_1697x1114.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lATL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc69bf5ae-f5c7-4e4e-adb3-0f49b28e8088_1697x1114.png" width="1456" height="956" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/c69bf5ae-f5c7-4e4e-adb3-0f49b28e8088_1697x1114.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:956,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:234668,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lATL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc69bf5ae-f5c7-4e4e-adb3-0f49b28e8088_1697x1114.png 424w, https://substackcdn.com/image/fetch/$s_!lATL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc69bf5ae-f5c7-4e4e-adb3-0f49b28e8088_1697x1114.png 848w, https://substackcdn.com/image/fetch/$s_!lATL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc69bf5ae-f5c7-4e4e-adb3-0f49b28e8088_1697x1114.png 1272w, https://substackcdn.com/image/fetch/$s_!lATL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc69bf5ae-f5c7-4e4e-adb3-0f49b28e8088_1697x1114.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In this example the first check looks for a security group rule matching ports 80 or 443 with ingress from the default route. If it matches, the APPROVE rule is applied and processing stops on that rule (each rule in a security group is evaluated independently). If the first rule does not match, then the next check would reject <em><strong>any other port</strong></em> with default route ingress.&nbsp;</p><p>Like all policies, these can also be set via <a href="https://registry.terraform.io/providers/turbot/turbot/latest/docs">Turbot&#8217;s Terraform provider</a>.&nbsp; Here is an example of creating a Smart Folder named &#8220;<strong>public_web_sg_check</strong>&#8221; with the same rules. Using a smart folder allows you to attach the same policies to multiple accounts.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8FqR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F337b8a4d-e098-41ff-926c-2f23ef70c115_1431x1041.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8FqR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F337b8a4d-e098-41ff-926c-2f23ef70c115_1431x1041.png 424w, https://substackcdn.com/image/fetch/$s_!8FqR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F337b8a4d-e098-41ff-926c-2f23ef70c115_1431x1041.png 848w, https://substackcdn.com/image/fetch/$s_!8FqR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F337b8a4d-e098-41ff-926c-2f23ef70c115_1431x1041.png 1272w, https://substackcdn.com/image/fetch/$s_!8FqR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F337b8a4d-e098-41ff-926c-2f23ef70c115_1431x1041.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8FqR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F337b8a4d-e098-41ff-926c-2f23ef70c115_1431x1041.png" width="1431" height="1041" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/337b8a4d-e098-41ff-926c-2f23ef70c115_1431x1041.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1041,&quot;width&quot;:1431,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Text\n\nDescription automatically generated&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Text

Description automatically generated" title="Text

Description automatically generated" srcset="https://substackcdn.com/image/fetch/$s_!8FqR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F337b8a4d-e098-41ff-926c-2f23ef70c115_1431x1041.png 424w, https://substackcdn.com/image/fetch/$s_!8FqR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F337b8a4d-e098-41ff-926c-2f23ef70c115_1431x1041.png 848w, https://substackcdn.com/image/fetch/$s_!8FqR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F337b8a4d-e098-41ff-926c-2f23ef70c115_1431x1041.png 1272w, https://substackcdn.com/image/fetch/$s_!8FqR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F337b8a4d-e098-41ff-926c-2f23ef70c115_1431x1041.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>After setting this policy, Turbot will identify all security group rules that match REJECT statements as alarms, allowing you to request remediation of the improper security groups from the app team.</p><p>If you are ready to enforce automated remediation, you can change the policy setting from &#8216;<strong>Check: Approved&#8217; </strong>to &#8216;<strong>Enforce: Delete unapproved&#8217;</strong> and Turbot&#8217;s automation will delete all security group rules that match a REJECT statement.</p><h2><strong>Make it happen</strong></h2><p>See for yourself how easy it is to manage your network ingress and egress rules across all your cloud services. A <strong>ready-to-run</strong> Terraform template is available to enable this configuration from the <a href="https://github.com/turbot/tdk/tree/master/control_objectives/aws_vpc_security_group_rules">Turbot Development Kit (TDK)</a>. If you need any assistance, please reach out to <a href="mailto:support@turbot.com">Turbot Support</a>, and keep an eye on your inbox for another Turbot tip next week!</p><p>Cheers,</p><p>Bob</p>]]></content:encoded></item><item><title><![CDATA[[Turbot On] Custom CMDB Data]]></title><description><![CDATA[Import your org's custom reference data into the Turbot CMDB.]]></description><link>https://on.turbot.com/p/turbot-on-custom-cmdb-data</link><guid isPermaLink="false">https://on.turbot.com/p/turbot-on-custom-cmdb-data</guid><dc:creator><![CDATA[Bob Tordella]]></dc:creator><pubDate>Mon, 14 Jun 2021 20:13:54 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NCAl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F08869413-eb4b-4747-a3f3-d355f4a5136a_1600x900.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NCAl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F08869413-eb4b-4747-a3f3-d355f4a5136a_1600x900.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NCAl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F08869413-eb4b-4747-a3f3-d355f4a5136a_1600x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!NCAl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F08869413-eb4b-4747-a3f3-d355f4a5136a_1600x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!NCAl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F08869413-eb4b-4747-a3f3-d355f4a5136a_1600x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!NCAl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F08869413-eb4b-4747-a3f3-d355f4a5136a_1600x900.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NCAl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F08869413-eb4b-4747-a3f3-d355f4a5136a_1600x900.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/08869413-eb4b-4747-a3f3-d355f4a5136a_1600x900.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:195379,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NCAl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F08869413-eb4b-4747-a3f3-d355f4a5136a_1600x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!NCAl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F08869413-eb4b-4747-a3f3-d355f4a5136a_1600x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!NCAl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F08869413-eb4b-4747-a3f3-d355f4a5136a_1600x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!NCAl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F08869413-eb4b-4747-a3f3-d355f4a5136a_1600x900.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Having correct metadata for a resource is crucial for automated resolution of operations, security and compliance incidents. Teams often rely on <a href="https://on.turbot.com/p/automating-resource-owner-tags">owner-assigned resource tags</a> to add external context to resources; however, additional deep-context can be added to resources via the Turbot CMDB.</p><h3><strong>This week, [Turbot On] will look at how to import and use custom CMDB data using the Turbot Files feature.</strong></h3><p></p><blockquote><p>If you&#8217;re intrigued the idea of building custom automated governance controls, please consider registering for our talk at <a href="https://www.awsfest2021.com/">AWS Fest 2021</a> on June 22nd. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xO7W!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3e233a9-4c08-4d51-8113-0ae608f04f6c_1200x628.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xO7W!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3e233a9-4c08-4d51-8113-0ae608f04f6c_1200x628.png 424w, https://substackcdn.com/image/fetch/$s_!xO7W!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3e233a9-4c08-4d51-8113-0ae608f04f6c_1200x628.png 848w, https://substackcdn.com/image/fetch/$s_!xO7W!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3e233a9-4c08-4d51-8113-0ae608f04f6c_1200x628.png 1272w, https://substackcdn.com/image/fetch/$s_!xO7W!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3e233a9-4c08-4d51-8113-0ae608f04f6c_1200x628.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xO7W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3e233a9-4c08-4d51-8113-0ae608f04f6c_1200x628.png" width="546" height="285.74" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/b3e233a9-4c08-4d51-8113-0ae608f04f6c_1200x628.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:628,&quot;width&quot;:1200,&quot;resizeWidth&quot;:546,&quot;bytes&quot;:89036,&quot;alt&quot;:&quot;Banner Ad for AWS Fest 2021&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Banner Ad for AWS Fest 2021" title="Banner Ad for AWS Fest 2021" srcset="https://substackcdn.com/image/fetch/$s_!xO7W!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3e233a9-4c08-4d51-8113-0ae608f04f6c_1200x628.png 424w, https://substackcdn.com/image/fetch/$s_!xO7W!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3e233a9-4c08-4d51-8113-0ae608f04f6c_1200x628.png 848w, https://substackcdn.com/image/fetch/$s_!xO7W!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3e233a9-4c08-4d51-8113-0ae608f04f6c_1200x628.png 1272w, https://substackcdn.com/image/fetch/$s_!xO7W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3e233a9-4c08-4d51-8113-0ae608f04f6c_1200x628.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Ops as Code: Going beyond CIS with custom controls</figcaption></figure></div><p>Our CTO will be discussing the pros and cons of industry benchmarks vs. custom controls, and doing a live coding demo to show how easy it is to get started.</p></blockquote><p></p><h2><strong>Traditional Workflow</strong></h2><p>Databases outside of the CMDB often contain reference data (and master data) that is important to cloud operations and security:&nbsp;&#8216;cost centers&#8217;, &#8216;approved project IDs&#8217;, &#8216;distribution lists&#8217; and &#8216;data classification&#8217; just to name a few.&nbsp;This type of data changes over time but its correctness can be very important when automating governance controls.</p><p>Requiring application teams to create and update tagging metadata is notoriously difficult to enforce. Even when the teams do maintain data, simple data entry mistakes, alternate spellings and capitalization mismatches are very common errors.</p><h2><strong>Turbot Files</strong></h2><p>A Turbot &#8216;<em>File&#8217;</em> is a text-based data object that typically contains a JSON formatted string. Once the object is imported into the Turbot CMDB, the data in it can then be referenced at runtime in <em>Calculated Policies</em> and <em>Stacks</em>.</p><ul><li><p>A <em>File</em> resource can contain any arbitrary data. Customers will often utilize a JSON schema to make it easier to reference data inside each file.</p></li><li><p>A <em>File</em> resource can be a child of the root Turbot resource or a <a href="https://turbot.com/v5/docs/guides/working-with-folders">Turbot Folder</a>.</p></li><li><p>The name (internally called `aka`) of the <em>File</em> resource is user-definable.</p><p></p></li></ul><h2><strong>Get it done with Turbot</strong></h2><p>Turbot Files can be managed using standard <a href="https://turbot.com/v5/docs/reference/graphql">GraphQL</a> API or the <a href="https://turbot.com/v5/docs/reference/terraform">Turbot Terraform Provider</a>. Management can be automated in a variety of ways depending on your organization's requirements. Some examples:</p><ul><li><p>Use a trigger to update the Turbot File whenever asset data in an inventory management tool changes.</p></li><li><p>Write a shell script to pull data from a third party API and update the File with the Turbot CLI.</p></li><li><p>Manually update the File via Terraform.</p></li><li><p>Write a Lambda to update the File via the GraphQL API.</p></li></ul><p>In this example we will use a Terraform template to create a Turbot File in order to add application metadata to our CMDB. Once the data is imported we will use it to enhance our tagging controls. </p><p>This Terraform template contains a File resource (note the name of the resource is &#8220;dmiapps&#8221;). Applying the template adds the JSON object specified in `content` to our Turbot workspace.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zpQD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6322a9d0-073a-4324-9968-084e2ed415cb_1341x1600.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zpQD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6322a9d0-073a-4324-9968-084e2ed415cb_1341x1600.png 424w, https://substackcdn.com/image/fetch/$s_!zpQD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6322a9d0-073a-4324-9968-084e2ed415cb_1341x1600.png 848w, https://substackcdn.com/image/fetch/$s_!zpQD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6322a9d0-073a-4324-9968-084e2ed415cb_1341x1600.png 1272w, https://substackcdn.com/image/fetch/$s_!zpQD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6322a9d0-073a-4324-9968-084e2ed415cb_1341x1600.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zpQD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6322a9d0-073a-4324-9968-084e2ed415cb_1341x1600.png" width="1341" height="1600" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/6322a9d0-073a-4324-9968-084e2ed415cb_1341x1600.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1600,&quot;width&quot;:1341,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zpQD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6322a9d0-073a-4324-9968-084e2ed415cb_1341x1600.png 424w, https://substackcdn.com/image/fetch/$s_!zpQD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6322a9d0-073a-4324-9968-084e2ed415cb_1341x1600.png 848w, https://substackcdn.com/image/fetch/$s_!zpQD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6322a9d0-073a-4324-9968-084e2ed415cb_1341x1600.png 1272w, https://substackcdn.com/image/fetch/$s_!zpQD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6322a9d0-073a-4324-9968-084e2ed415cb_1341x1600.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote></blockquote><p>Now that we have our Turbot File created we can use the metadata inside of it as a data-source for our calculated policies.&nbsp;For example, we can use <a href="https://turbot.com/v5/docs/concepts/guardrails/tagging">Turbot&#8217;s tagging controls</a> to tag resources using metadata from the &#8220;dmiapps&#8221; file.&nbsp;To demonstrate the approach we will use a calculated policy to tag our S3 Buckets with the correct values based on the enclosing AWS Account.</p><p>The GraphQL query (see &#8220;Step 1&#8221; below) retrieves both the bucket resource&#8217;s metadata object, and the data from the &#8220;dmiapps&#8221; file<em>.</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Tb2o!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3f6bf28a-00ab-4b72-b534-ecfa9c81aff4_1327x1256.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Tb2o!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3f6bf28a-00ab-4b72-b534-ecfa9c81aff4_1327x1256.png 424w, https://substackcdn.com/image/fetch/$s_!Tb2o!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3f6bf28a-00ab-4b72-b534-ecfa9c81aff4_1327x1256.png 848w, https://substackcdn.com/image/fetch/$s_!Tb2o!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3f6bf28a-00ab-4b72-b534-ecfa9c81aff4_1327x1256.png 1272w, https://substackcdn.com/image/fetch/$s_!Tb2o!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3f6bf28a-00ab-4b72-b534-ecfa9c81aff4_1327x1256.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Tb2o!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3f6bf28a-00ab-4b72-b534-ecfa9c81aff4_1327x1256.png" width="1327" height="1256" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/3f6bf28a-00ab-4b72-b534-ecfa9c81aff4_1327x1256.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1256,&quot;width&quot;:1327,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:156136,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Tb2o!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3f6bf28a-00ab-4b72-b534-ecfa9c81aff4_1327x1256.png 424w, https://substackcdn.com/image/fetch/$s_!Tb2o!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3f6bf28a-00ab-4b72-b534-ecfa9c81aff4_1327x1256.png 848w, https://substackcdn.com/image/fetch/$s_!Tb2o!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3f6bf28a-00ab-4b72-b534-ecfa9c81aff4_1327x1256.png 1272w, https://substackcdn.com/image/fetch/$s_!Tb2o!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3f6bf28a-00ab-4b72-b534-ecfa9c81aff4_1327x1256.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>As seen in <strong>Step 2</strong>, above, we can then extract the AWS account ID from the resource and use it to lookup keyed values stored in the &#8220;dmiapps&#8221; file.</p><p>The provided example can easily be adjusted for any resource that can be tagged (across all supported cloud services).<strong> </strong>The best part is that whenever the Turbot File is updated (e.g. a new app is added, change in App owner, etc.), any affected tags will automatically be updated as well.</p><p>Now that our tagging template above is set via a calculated policy, we can begin enforcing the tagging control by setting the Tags policy value to `<strong>Enforce: Set tags</strong>`:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pqgt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8398dcc-9327-4767-8508-226941ba94c2_1473x1348.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pqgt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8398dcc-9327-4767-8508-226941ba94c2_1473x1348.png 424w, https://substackcdn.com/image/fetch/$s_!pqgt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8398dcc-9327-4767-8508-226941ba94c2_1473x1348.png 848w, https://substackcdn.com/image/fetch/$s_!pqgt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8398dcc-9327-4767-8508-226941ba94c2_1473x1348.png 1272w, https://substackcdn.com/image/fetch/$s_!pqgt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8398dcc-9327-4767-8508-226941ba94c2_1473x1348.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pqgt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8398dcc-9327-4767-8508-226941ba94c2_1473x1348.png" width="1456" height="1332" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/f8398dcc-9327-4767-8508-226941ba94c2_1473x1348.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1332,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:135170,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pqgt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8398dcc-9327-4767-8508-226941ba94c2_1473x1348.png 424w, https://substackcdn.com/image/fetch/$s_!pqgt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8398dcc-9327-4767-8508-226941ba94c2_1473x1348.png 848w, https://substackcdn.com/image/fetch/$s_!pqgt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8398dcc-9327-4767-8508-226941ba94c2_1473x1348.png 1272w, https://substackcdn.com/image/fetch/$s_!pqgt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8398dcc-9327-4767-8508-226941ba94c2_1473x1348.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>After setting this policy, Turbot will identify all resources that do not have the tags applied correctly, and then handle their remediation (i.e. set the tags).</p><p>If you are not yet ready to enforce remediation, you can still assess (and get alerts for) what resources do not have matching tags by changing the policy setting from `<strong>Enforce: Set tags</strong>` to `<strong>Check: Tags are correct</strong>`.</p><h2><strong>Make it happen</strong></h2><p>See for yourself how easy it is to manage your custom CMDB metadata configurations across all your cloud resources. A <strong>ready-to-run</strong> Terraform template is available to enable this configuration from the <a href="https://github.com/turbot/tdk/tree/master/control_objectives/turbot_file_app_data_tagging">Turbot Development Kit (TDK)</a>. If you need any assistance please reach out to <a href="mailto:support@turbot.com">Turbot Support</a>, and keep an eye on your inbox for another Turbot tip next week!</p><p>Cheers,</p><p>Bob</p>]]></content:encoded></item><item><title><![CDATA[[Turbot On] S3 Bucket Logging]]></title><description><![CDATA[Automate server access logging on your S3 buckets.]]></description><link>https://on.turbot.com/p/turbot-on-s3-bucket-logging</link><guid isPermaLink="false">https://on.turbot.com/p/turbot-on-s3-bucket-logging</guid><dc:creator><![CDATA[Bob Tordella]]></dc:creator><pubDate>Mon, 07 Jun 2021 15:23:27 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!lv2J!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F290cdcdb-fbf7-4e0b-852c-fe380b03dbce_1600x900.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lv2J!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F290cdcdb-fbf7-4e0b-852c-fe380b03dbce_1600x900.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lv2J!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F290cdcdb-fbf7-4e0b-852c-fe380b03dbce_1600x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!lv2J!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F290cdcdb-fbf7-4e0b-852c-fe380b03dbce_1600x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!lv2J!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F290cdcdb-fbf7-4e0b-852c-fe380b03dbce_1600x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!lv2J!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F290cdcdb-fbf7-4e0b-852c-fe380b03dbce_1600x900.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lv2J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F290cdcdb-fbf7-4e0b-852c-fe380b03dbce_1600x900.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/290cdcdb-fbf7-4e0b-852c-fe380b03dbce_1600x900.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:313681,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lv2J!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F290cdcdb-fbf7-4e0b-852c-fe380b03dbce_1600x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!lv2J!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F290cdcdb-fbf7-4e0b-852c-fe380b03dbce_1600x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!lv2J!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F290cdcdb-fbf7-4e0b-852c-fe380b03dbce_1600x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!lv2J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F290cdcdb-fbf7-4e0b-852c-fe380b03dbce_1600x900.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>One aspect of cloud compliance I often see overlooked is audit readiness. If you work in any regulated industry or host data for your customers, you will eventually have your cloud environments audited. </p><p>When addressing an audit finding it is critical that you can answer the key questions of <strong>who</strong>, <strong>what</strong>, and <strong>when </strong>data was accessed or changed. Fail to answer these questions and your processes will be considered<strong> &#8220;out of control&#8221;</strong>. Availability of logs to answer these questions can be the key difference between a minor audit finding (e.g. improved training) and having to revamp your whole change control process.</p><blockquote><h4><strong>This week [Turbot On] will look at how to automate server access logging for Amazon S3 buckets.</strong></h4></blockquote><p>Server access logging provides detailed records for requests that are made to an Amazon S3 bucket.&nbsp;With logging enabled, the access log record contains the request type, the resources that are specified in the request, and the time and date that the request was processed.&nbsp;Access logging allows security teams and auditors to understand how authenticated users are interacting with your S3 buckets.&nbsp;</p><h2><strong>Traditional Workflow</strong></h2><p>The AWS console or APIs can be used to enable and disable access logging. When you enable this feature, Amazon periodically collects access log records, consolidates the records in log files, and then uploads log files to a target bucket as S3 objects.&nbsp;</p><p>Configuration considerations can increase complexity:</p><ul><li><p>The target bucket for logging must be in the same region as the source bucket.</p></li><li><p>The target bucket must be owned by the same account as the source bucket.</p></li><li><p>Multiple source buckets logging into the same target bucket may need different prefixes.</p></li><li><p>Setting appropriate permissions on the logging bucket for separation of duties.</p></li><li><p>Setting lifecycle policies for the logs based on the organization&#8217;s approved log retention period.</p></li></ul><p>This means that we need to create a logging destination bucket in each region we operate in, setup lifecycle policies on it, and configure it so the application team can read, but not delete from the bucket. One it is created we need to update every bucket in the account to point to that location with a designated prefix, and make sure they stay configured that way over time. </p><p>While it is possible to configure this manually for a few buckets across a couple regions, automation will be needed to support larger environments.</p><h2><strong>Get it done with Turbot</strong></h2><p>In Turbot, <a href="https://turbot.com/v5/docs/concepts/guardrails/access-logging">access logging</a> guardrails control your cloud resource configurations.&nbsp;The key policy setting for access logging can be found directly under the resource in the policy hierarchy: <em><strong>AWS &gt; S3 &gt; Bucket &gt; Access Logging</strong></em>. Policy sub-settings determine the target bucket and how to prefix the logs inside the bucket: </p><ul><li><p><em>AWS &gt; S3 &gt; Bucket &gt; Access Logging &gt;<strong> Bucket </strong></em></p></li><li><p><em>AWS &gt; S3 &gt; Bucket &gt; Access Logging &gt; <strong>Key Prefix</strong></em></p></li></ul><p>Using <a href="https://turbot.com/v5/docs/7-minute-labs/calc-policy">calculated policies</a>, you can implement dynamic naming conventions to handle unique buckets per account, region and service as applicable. By using our prebuilt default logging settings for the destination and prefix, we can enable Turbot&#8217;s automation with just a few clicks:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!A3WW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9f4cecc4-43c6-4306-aab3-542b65e15c01_957x898.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!A3WW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9f4cecc4-43c6-4306-aab3-542b65e15c01_957x898.png 424w, https://substackcdn.com/image/fetch/$s_!A3WW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9f4cecc4-43c6-4306-aab3-542b65e15c01_957x898.png 848w, https://substackcdn.com/image/fetch/$s_!A3WW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9f4cecc4-43c6-4306-aab3-542b65e15c01_957x898.png 1272w, https://substackcdn.com/image/fetch/$s_!A3WW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9f4cecc4-43c6-4306-aab3-542b65e15c01_957x898.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!A3WW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9f4cecc4-43c6-4306-aab3-542b65e15c01_957x898.png" width="957" height="898" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/9f4cecc4-43c6-4306-aab3-542b65e15c01_957x898.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:898,&quot;width&quot;:957,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:78140,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!A3WW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9f4cecc4-43c6-4306-aab3-542b65e15c01_957x898.png 424w, https://substackcdn.com/image/fetch/$s_!A3WW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9f4cecc4-43c6-4306-aab3-542b65e15c01_957x898.png 848w, https://substackcdn.com/image/fetch/$s_!A3WW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9f4cecc4-43c6-4306-aab3-542b65e15c01_957x898.png 1272w, https://substackcdn.com/image/fetch/$s_!A3WW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9f4cecc4-43c6-4306-aab3-542b65e15c01_957x898.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Turbot&#8217;s web console policy setting for S3 Access Logging</figcaption></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!L1gR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F28f6c9ea-d14d-409d-b66a-d49b9427371a_2796x1600.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!L1gR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F28f6c9ea-d14d-409d-b66a-d49b9427371a_2796x1600.png 424w, https://substackcdn.com/image/fetch/$s_!L1gR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F28f6c9ea-d14d-409d-b66a-d49b9427371a_2796x1600.png 848w, https://substackcdn.com/image/fetch/$s_!L1gR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F28f6c9ea-d14d-409d-b66a-d49b9427371a_2796x1600.png 1272w, https://substackcdn.com/image/fetch/$s_!L1gR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F28f6c9ea-d14d-409d-b66a-d49b9427371a_2796x1600.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!L1gR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F28f6c9ea-d14d-409d-b66a-d49b9427371a_2796x1600.png" width="1456" height="833" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/28f6c9ea-d14d-409d-b66a-d49b9427371a_2796x1600.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:833,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:238019,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!L1gR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F28f6c9ea-d14d-409d-b66a-d49b9427371a_2796x1600.png 424w, https://substackcdn.com/image/fetch/$s_!L1gR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F28f6c9ea-d14d-409d-b66a-d49b9427371a_2796x1600.png 848w, https://substackcdn.com/image/fetch/$s_!L1gR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F28f6c9ea-d14d-409d-b66a-d49b9427371a_2796x1600.png 1272w, https://substackcdn.com/image/fetch/$s_!L1gR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F28f6c9ea-d14d-409d-b66a-d49b9427371a_2796x1600.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Setting the policy via Turbot&#8217;s Terraform Provider is just as easy.</figcaption></figure></div><p></p><blockquote><p>After setting these policies, Turbot will identify all S3 buckets that do not have access logging enabled, and remediate them (i.e. enable the logging configuration).</p></blockquote><p>If you are not yet ready to enforce remediation, you can still assess what buckets don&#8217;t have access logging enabled by setting the policy value to &#8216;<strong>Check: Enabled</strong>&#8217;.&nbsp;In &#8216;<strong>Check</strong>&#8217; mode Turbot will alarm on buckets which do not have access logging in place. It&#8217;s also possible to check that a specific logging configuration is in place by using the alternate setting: &#8216;<strong>Check: Enabled to Access Logging &gt; Bucket</strong>&#8217;. After review of the alarms, you can selectively apply the enforcement settings or create exceptions as desired.&nbsp;</p><p>Given that access logging may not be appropriate for all buckets (e.g. development), make use of Turbot&#8217;s <a href="https://turbot.com/v5/docs/guides/managing-policies#creating-an-exception">policy exceptions</a> as necessary to achieve your desired compliance outcome across all environments.</p><h2><strong>Make it happen</strong></h2><p>See for yourself how easy it is to manage your access logging configurations across your cloud resources. A <strong>ready-to-run</strong> Terraform template is available to enable this configuration from the <a href="https://github.com/turbot/tdk/tree/master/control_objectives/aws_s3_access_logging">Turbot Development Kit (TDK)</a>. If you need any assistance please reach out to <a href="mailto:support@turbot.com">Turbot Support</a>, and keep an eye on your inbox for another Turbot tip next week!</p><p>Cheers,</p><p>Bob</p><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[[Turbot On] Encryption at Rest for SNS ]]></title><description><![CDATA[How to enforce encryption at rest to all your Amazon SNS topics.]]></description><link>https://on.turbot.com/p/turbot-on-encryption-at-rest-for</link><guid isPermaLink="false">https://on.turbot.com/p/turbot-on-encryption-at-rest-for</guid><dc:creator><![CDATA[Bob Tordella]]></dc:creator><pubDate>Tue, 01 Jun 2021 16:31:14 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!4j_V!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F88cd2edf-7c6a-4c49-b48c-239dc4aa52c9_3200x1800.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4j_V!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F88cd2edf-7c6a-4c49-b48c-239dc4aa52c9_3200x1800.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4j_V!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F88cd2edf-7c6a-4c49-b48c-239dc4aa52c9_3200x1800.jpeg 424w, https://substackcdn.com/image/fetch/$s_!4j_V!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F88cd2edf-7c6a-4c49-b48c-239dc4aa52c9_3200x1800.jpeg 848w, https://substackcdn.com/image/fetch/$s_!4j_V!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F88cd2edf-7c6a-4c49-b48c-239dc4aa52c9_3200x1800.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!4j_V!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F88cd2edf-7c6a-4c49-b48c-239dc4aa52c9_3200x1800.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4j_V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F88cd2edf-7c6a-4c49-b48c-239dc4aa52c9_3200x1800.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/88cd2edf-7c6a-4c49-b48c-239dc4aa52c9_3200x1800.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:688100,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4j_V!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F88cd2edf-7c6a-4c49-b48c-239dc4aa52c9_3200x1800.jpeg 424w, https://substackcdn.com/image/fetch/$s_!4j_V!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F88cd2edf-7c6a-4c49-b48c-239dc4aa52c9_3200x1800.jpeg 848w, https://substackcdn.com/image/fetch/$s_!4j_V!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F88cd2edf-7c6a-4c49-b48c-239dc4aa52c9_3200x1800.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!4j_V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F88cd2edf-7c6a-4c49-b48c-239dc4aa52c9_3200x1800.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://aws.amazon.com/sns/">Amazon Simple Notification Service</a> (Amazon SNS) is a messaging Platform as a Service (PaaS) that is frequently used as part of cloud-native, loosely-coupled application architectures (e.g. microservices, distributed systems, etc.). Turbot itself uses SNS in conjunction with CloudWatch events and SQS as a highly reliable and subscribable message queue. If your SNS topics are processing sensitive data, it makes sense to encrypt them in transit and at rest.</p><h3><strong>This week we will look at how Turbot can automate checking and enforcement of encryption at rest for your Amazon SNS topics.</strong></h3><h2><strong>Traditional Workflow</strong></h2><p>In a cloud native architecture, SNS topics are often created programmatically (i.e. a software factory that creates new lambda functions, might also create a new SNS topic to enable pub/sub messaging for the function. This means that your large scale applications may have hundreds or thousands of topics under management. </p><p>Furthermore, limitations in the past with cross service KMS key access prevented some applications from using encryption with SNS. If your applications were built a few years ago, those applications may not have updated their architecture and could still be generating new topics without encryption.&nbsp;Manually looking for them and remediating the issues is a tedious and time consuming task.</p><h2><strong>Get it done with Turbot</strong></h2><p>In Turbot, Amazon SNS Topics guardrails are readily available to control your cloud resource configurations.&nbsp;We can set the Turbot automation `<strong>AWS &gt; SNS &gt; Topic&gt; Encryption at Rest</strong>` policy in just a few clicks:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yhZL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8b025fb-d800-400e-829e-4aea5f8bc7c3_961x1065.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yhZL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8b025fb-d800-400e-829e-4aea5f8bc7c3_961x1065.png 424w, https://substackcdn.com/image/fetch/$s_!yhZL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8b025fb-d800-400e-829e-4aea5f8bc7c3_961x1065.png 848w, https://substackcdn.com/image/fetch/$s_!yhZL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8b025fb-d800-400e-829e-4aea5f8bc7c3_961x1065.png 1272w, https://substackcdn.com/image/fetch/$s_!yhZL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8b025fb-d800-400e-829e-4aea5f8bc7c3_961x1065.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yhZL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8b025fb-d800-400e-829e-4aea5f8bc7c3_961x1065.png" width="961" height="1065" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/d8b025fb-d800-400e-829e-4aea5f8bc7c3_961x1065.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1065,&quot;width&quot;:961,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:85580,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yhZL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8b025fb-d800-400e-829e-4aea5f8bc7c3_961x1065.png 424w, https://substackcdn.com/image/fetch/$s_!yhZL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8b025fb-d800-400e-829e-4aea5f8bc7c3_961x1065.png 848w, https://substackcdn.com/image/fetch/$s_!yhZL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8b025fb-d800-400e-829e-4aea5f8bc7c3_961x1065.png 1272w, https://substackcdn.com/image/fetch/$s_!yhZL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8b025fb-d800-400e-829e-4aea5f8bc7c3_961x1065.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><strong>Set a policy to take corrective action for enabling encryption at rest.</strong></figcaption></figure></div><p></p><p>Setting the configuration via Turbot&#8217;s Terraform provider is just as easy:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cCgX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc2dc156-fba8-4775-a7c8-d5961ccf5d12_1444x772.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cCgX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc2dc156-fba8-4775-a7c8-d5961ccf5d12_1444x772.png 424w, https://substackcdn.com/image/fetch/$s_!cCgX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc2dc156-fba8-4775-a7c8-d5961ccf5d12_1444x772.png 848w, https://substackcdn.com/image/fetch/$s_!cCgX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc2dc156-fba8-4775-a7c8-d5961ccf5d12_1444x772.png 1272w, https://substackcdn.com/image/fetch/$s_!cCgX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc2dc156-fba8-4775-a7c8-d5961ccf5d12_1444x772.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cCgX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc2dc156-fba8-4775-a7c8-d5961ccf5d12_1444x772.png" width="1444" height="772" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/fc2dc156-fba8-4775-a7c8-d5961ccf5d12_1444x772.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:772,&quot;width&quot;:1444,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:107644,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cCgX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc2dc156-fba8-4775-a7c8-d5961ccf5d12_1444x772.png 424w, https://substackcdn.com/image/fetch/$s_!cCgX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc2dc156-fba8-4775-a7c8-d5961ccf5d12_1444x772.png 848w, https://substackcdn.com/image/fetch/$s_!cCgX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc2dc156-fba8-4775-a7c8-d5961ccf5d12_1444x772.png 1272w, https://substackcdn.com/image/fetch/$s_!cCgX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc2dc156-fba8-4775-a7c8-d5961ccf5d12_1444x772.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Terraform template to set the <strong>AWS &gt;SNS &gt; Topic &gt; Encryption at Rest</strong> policy.</figcaption></figure></div><p>After setting these policies, Turbot will identify all SNS Topics without a configured AWS KMS managed key, and then handle remediation (i.e. set the correct encryption configuration).</p><p>If you are not yet ready to enforce remediation, you can still assess your environment&#8217;s SNS encryption compliance by setting the value of the policy to &#8216;<strong>Check: AWS managed key or higher</strong>&#8217; at the Turbot level.&nbsp;In &#8216;Check&#8217; mode Turbot will alarm on Amazon SNS Topics that do not have encryption at rest in place. After review of the alarms, selectively apply the enforcement settings or create exceptions as desired.&nbsp;</p><p>Given that encryption may not be applicable for all topics, make use of Turbot&#8217;s <a href="https://turbot.com/v5/docs/guides/managing-policies#creating-an-exception">policy exceptions</a> and <a href="https://turbot.com/v5/docs/concepts/policies/values-settings#expiration">time-based expiration</a> settings features to mark exceptions to the rule or automatically reset a configuration when the exception expires.</p><h2><strong>Make it happen</strong></h2><p>See for yourself how easy it is to manage your encryption configurations across your cloud resources. A <strong>ready-to-run</strong> Terraform template is available to enable this configuration from the <a href="https://github.com/turbot/tdk/tree/master/control_objectives/aws_sns_topic_encryption_at_rest">Turbot Development Kit (TDK)</a>. If you need any assistance please reach out to <a href="mailto:support@turbot.com">Turbot Support</a>, and keep an eye on your inbox for another Turbot tip next week!</p><p>Cheers,</p><p>Bob</p>]]></content:encoded></item><item><title><![CDATA[Turbot Product Updates]]></title><description><![CDATA[Monthly highlights of Turbot product changes]]></description><link>https://on.turbot.com/p/turbot-product-updates</link><guid isPermaLink="false">https://on.turbot.com/p/turbot-product-updates</guid><dc:creator><![CDATA[Bob Tordella]]></dc:creator><pubDate>Wed, 26 May 2021 20:35:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gE-Z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F600aaccf-f50e-4c3c-b54a-9ff573f102a4_5550x3700.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gE-Z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F600aaccf-f50e-4c3c-b54a-9ff573f102a4_5550x3700.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gE-Z!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F600aaccf-f50e-4c3c-b54a-9ff573f102a4_5550x3700.png 424w, https://substackcdn.com/image/fetch/$s_!gE-Z!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F600aaccf-f50e-4c3c-b54a-9ff573f102a4_5550x3700.png 848w, https://substackcdn.com/image/fetch/$s_!gE-Z!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F600aaccf-f50e-4c3c-b54a-9ff573f102a4_5550x3700.png 1272w, https://substackcdn.com/image/fetch/$s_!gE-Z!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F600aaccf-f50e-4c3c-b54a-9ff573f102a4_5550x3700.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gE-Z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F600aaccf-f50e-4c3c-b54a-9ff573f102a4_5550x3700.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/600aaccf-f50e-4c3c-b54a-9ff573f102a4_5550x3700.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:22952778,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gE-Z!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F600aaccf-f50e-4c3c-b54a-9ff573f102a4_5550x3700.png 424w, https://substackcdn.com/image/fetch/$s_!gE-Z!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F600aaccf-f50e-4c3c-b54a-9ff573f102a4_5550x3700.png 848w, https://substackcdn.com/image/fetch/$s_!gE-Z!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F600aaccf-f50e-4c3c-b54a-9ff573f102a4_5550x3700.png 1272w, https://substackcdn.com/image/fetch/$s_!gE-Z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F600aaccf-f50e-4c3c-b54a-9ff573f102a4_5550x3700.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Turbot Mod Changes</strong></h2><ul><li><p>AWS EC2 Mod improvements when tagging events occurred</p></li><li><p>AWS ECR Image controls added</p></li><li><p>AWS SageMaker controls for Code Repository, Endpoint Configuration, Lifecycle Configuration</p></li><li><p>AWS Well-Architected Tool Tagging control</p></li><li><p>Azure Network Security Group rules have an added condition for service tags approved</p></li><li><p>GCP Firebase controls for Android App, Firebase Project, Web App, and iOS App</p></li><li><p>New services and resources added for Turbot AWS Permissions; Connect, Cloud Directory, DataSync, MWAA, Cloud Map, Direct Connect, Translate, Rekognition, Cognito, AWS Tagging, Chatbot, Device Farm, Polly, Macie2, IAM Access Analyzer, AppFlow, Billing</p></li><li><p>Turbot Event Handler custom rules -- custom options to reduce unused high volume AWS EC2 and AWS VPC events</p></li><li><p>Additional updates can be found in the full<strong> <a href="https://turbot.com/v5/docs/releases/mods">Release Notes</a>.</strong></p></li></ul><div class="preformatted-block" data-component-name="PreformattedTextBlockToDOM"><label class="hide-text" contenteditable="false">Text within this block will maintain its original spacing when published</label><pre class="text"> </pre></div><h2><strong>Turbot UI Changes</strong></h2><blockquote><p><strong>Turbot Best Practice Reports</strong></p></blockquote><p>Turbot&#8217;s best practice reports combine key controls for given resources into a single easy to read report.  The image below shows a combined report for S3 buckets pulling to together results for nine separate controls into a single line item for each bucket.  These reports are based on your policies settings and can be exported to CSV.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PwiB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9d77d31e-b076-4316-bfaf-0e284fa4bd33_2878x1168.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PwiB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9d77d31e-b076-4316-bfaf-0e284fa4bd33_2878x1168.png 424w, https://substackcdn.com/image/fetch/$s_!PwiB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9d77d31e-b076-4316-bfaf-0e284fa4bd33_2878x1168.png 848w, https://substackcdn.com/image/fetch/$s_!PwiB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9d77d31e-b076-4316-bfaf-0e284fa4bd33_2878x1168.png 1272w, https://substackcdn.com/image/fetch/$s_!PwiB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9d77d31e-b076-4316-bfaf-0e284fa4bd33_2878x1168.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PwiB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9d77d31e-b076-4316-bfaf-0e284fa4bd33_2878x1168.png" width="1456" height="591" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/9d77d31e-b076-4316-bfaf-0e284fa4bd33_2878x1168.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:591,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:355723,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PwiB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9d77d31e-b076-4316-bfaf-0e284fa4bd33_2878x1168.png 424w, https://substackcdn.com/image/fetch/$s_!PwiB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9d77d31e-b076-4316-bfaf-0e284fa4bd33_2878x1168.png 848w, https://substackcdn.com/image/fetch/$s_!PwiB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9d77d31e-b076-4316-bfaf-0e284fa4bd33_2878x1168.png 1272w, https://substackcdn.com/image/fetch/$s_!PwiB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9d77d31e-b076-4316-bfaf-0e284fa4bd33_2878x1168.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">AWS S3 Best Practices Report</figcaption></figure></div><h4>15 New Turbot Reports<strong>:&nbsp;</strong></h4><ul><li><p>Turbot Best Practice - AWS S3 Buckets (See above)</p></li><li><p>Oldest Azure Compute Disks</p></li><li><p>Well-Architected Tool Workloads</p></li><li><p>Azure Compute Disks Resource Details</p></li><li><p>Unencrypted AWS CloudWatch Log Groups</p></li><li><p>AWS EC2 Instance AMI usage</p></li><li><p>AWS Default VPC</p></li><li><p>AWS EC2 AMIs</p></li><li><p>AWS Public Route 53 Hosted Zones</p></li><li><p>Recent User Login</p></li><li><p>Detached GCP Compute Engine Disks</p></li><li><p>Unencrypted AWS CloudTrail Trails</p></li><li><p>Aging AWS Access Keys</p></li><li><p>Aging Turbot Access Keys</p></li><li><p>Mods Admin List shows more information on the latest available version and last updated</p></li></ul><p>Additional updates can be found in the <strong><a href="https://turbot.com/v5/docs/releases/te">full TE Release Notes</a>.</strong></p><div class="preformatted-block" data-component-name="PreformattedTextBlockToDOM"><label class="hide-text" contenteditable="false">Text within this block will maintain its original spacing when published</label><pre class="text"> </pre></div><h2><strong>Turbot Enterprise Changes</strong></h2><p>The current recommended deployment versions for Turbot Enterprise are updated here: <a href="https://turbot.com/v5/docs/releases">https://turbot.com/v5/docs/releases</a></p><div class="preformatted-block" data-component-name="PreformattedTextBlockToDOM"><label class="hide-text" contenteditable="false">Text within this block will maintain its original spacing when published</label><pre class="text"> </pre></div><blockquote><p><strong>External ID Best Practices</strong></p></blockquote><p>The Turbot UI now auto-generates complex random external IDs to adhere to best practices and organizations can enforce use of unique external IDs using the `AWS &gt; Account &gt; Turbot IAM Role &gt; External ID &gt; Protection` policy.  <a href="https://turbot.com/v5/docs/faq/general-faq#what-is-turbot-aws-iam-role-external-id-protection">See the v5 FAQs for more info</a>.</p><blockquote><p><strong>Apollo becoming new default UI</strong></p></blockquote><p>In the upcoming v5.37.0 release, the default UI for all Turbot users will become the Turbot Console Apollo UI. For users already using the Apollo UI, no change will occur, and for users who still prefer the original UI, you can switch back with a link in the header of the console. For Turbot Cloud (SaaS) customers this change will occur automatically.&nbsp; For Turbot Enterprise customers this change will occur when you upgrade to the v5.37.0 release or higher.</p><p>The existing (non-Apollo) console will be considered deprecated in the v5.37.0 release, and in a few months, the v5.40.0 release will fully remove the non-Apollo UI. This will not impact APIs, but will impact saved URLs pointing to specific screens in the old UI.</p><p>Since its release in Nov 2020, the Apollo UI is the preferred UI among Turbot users. You can learn more about Apollo in our <a href="https://www.youtube.com/watch?v=z7VmiU4FFfM">highlights video</a>.</p><blockquote><p><strong>Postgres 13 support</strong></p></blockquote><p>Starting with TED v1.20.1 new installations will default to using Postgres 13. Existing Postgres 11 &amp; 12 installs will not be impacted and no action needs to be taken now. When appropriate, we will recommend an update path.</p><div class="preformatted-block" data-component-name="PreformattedTextBlockToDOM"><label class="hide-text" contenteditable="false">Text within this block will maintain its original spacing when published</label><pre class="text"> </pre></div><h4><strong>Key Performance Improvements:&nbsp;</strong></h4><ul><li><p>Moving resources to new locations in the hierarchy is more responsive in the UI.</p></li><li><p>Process logs are saved to S3 as a single operation, reducing request costs.</p></li><li><p>Cleanup of unused tables (action_history) and unused indexes (controls_history, resources_history, and policy_values_history) to reduce DB disk space.</p></li><li><p>Critical database indexes are now re-created weekly to improve performance.</p></li><li><p>Workspace will now pause on processing events during a TE upgrade.</p><div class="preformatted-block" data-component-name="PreformattedTextBlockToDOM"><label class="hide-text" contenteditable="false">Text within this block will maintain its original spacing when published</label><pre class="text"> </pre></div></li></ul><h4><strong>Full Release Notes:</strong></h4><ul><li><p><a href="https://turbot.com/v5/docs/releases/te">Turbot Enterprise</a></p></li><li><p><a href="https://turbot.com/v5/docs/releases/tef">Turbot Enterprise Foundation (TEF)</a></p></li><li><p><a href="https://turbot.com/v5/docs/releases/ted">Turbot Enterprise Database (TED)</a></p></li></ul><div class="preformatted-block" data-component-name="PreformattedTextBlockToDOM"><label class="hide-text" contenteditable="false">Text within this block will maintain its original spacing when published</label><pre class="text"> </pre></div><h4><strong>Turbot Developer Tools:</strong></h4><p><strong>Terraform </strong>- <a href="https://turbot.com/v5/docs/releases/terraform">https://turbot.com/v5/docs/releases/terraform</a></p><ul><li><p>Turbot&#8217;s Terraform Provider v1.8.2 has been tested compatible with Terraform version 14 and 15.</p></li></ul><p><strong>Turbot CLI</strong> - <a href="https://turbot.com/v5/docs/releases/cli">https://turbot.com/v5/docs/releases/cli</a></p><ul><li><p>FAQ guide - <a href="https://turbot.com/v5/docs/faq/general-faq#can-i-generate-aws-access-keys-programmatically">Can I generate AWS Access Keys programmatically?</a></p><div class="preformatted-block" data-component-name="PreformattedTextBlockToDOM"><label class="hide-text" contenteditable="false">Text within this block will maintain its original spacing when published</label><pre class="text"> </pre></div></li></ul><h4><strong>Turbot On Posts:</strong></h4><ul><li><p><strong><a href="https://on.turbot.com/p/turbot-on-tagging-with-context">[Turbot On] Tagging with Context</a></strong> - how to automate the application of resource tags from CMDB metadata.&nbsp;</p></li><li><p><strong><a href="https://on.turbot.com/p/turbot-on-s3-public-access-blocks">[Turbot On] S3 Public Access Blocks</a></strong> - how to automate AWS S3 account and bucket level public access blocks.&nbsp;</p></li><li><p><strong><a href="https://on.turbot.com/p/gcp-firewall-rule-logging">[Turbot On] GCP Firewall Rule Logging</a></strong> - how to automatically enable GCP Firewall Logging for one or more firewall rules.</p></li><li><p><strong><a href="https://on.turbot.com/p/turbot-on-automated-snapshot-cleanup">[Turbot On] Automated Snapshot Cleanup</a></strong> - how to save big by cleaning up older snapshots on a retention schedule.</p></li></ul>]]></content:encoded></item><item><title><![CDATA[[Turbot On] DynamoDB Table Backup]]></title><description><![CDATA[Automatically enable continuous backups with point-in-time recovery of your DynamoDB Tables.]]></description><link>https://on.turbot.com/p/turbot-on-dynamodb-table-backup</link><guid isPermaLink="false">https://on.turbot.com/p/turbot-on-dynamodb-table-backup</guid><dc:creator><![CDATA[Bob Tordella]]></dc:creator><pubDate>Mon, 24 May 2021 16:10:58 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!4Gku!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1b9072d3-94b5-446d-b0e6-792104562e29_3199x1800.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4Gku!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1b9072d3-94b5-446d-b0e6-792104562e29_3199x1800.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4Gku!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1b9072d3-94b5-446d-b0e6-792104562e29_3199x1800.jpeg 424w, https://substackcdn.com/image/fetch/$s_!4Gku!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1b9072d3-94b5-446d-b0e6-792104562e29_3199x1800.jpeg 848w, https://substackcdn.com/image/fetch/$s_!4Gku!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1b9072d3-94b5-446d-b0e6-792104562e29_3199x1800.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!4Gku!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1b9072d3-94b5-446d-b0e6-792104562e29_3199x1800.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4Gku!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1b9072d3-94b5-446d-b0e6-792104562e29_3199x1800.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/1b9072d3-94b5-446d-b0e6-792104562e29_3199x1800.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:590401,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4Gku!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1b9072d3-94b5-446d-b0e6-792104562e29_3199x1800.jpeg 424w, https://substackcdn.com/image/fetch/$s_!4Gku!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1b9072d3-94b5-446d-b0e6-792104562e29_3199x1800.jpeg 848w, https://substackcdn.com/image/fetch/$s_!4Gku!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1b9072d3-94b5-446d-b0e6-792104562e29_3199x1800.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!4Gku!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1b9072d3-94b5-446d-b0e6-792104562e29_3199x1800.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>With heightened emphasis on security and encryption of data in the cloud, an often overlooked aspect of data protection is backup and recovery of your organizations data. In the cloud, developers have programmatic access to delete resources and a simple slip of the CLI can sometimes lead to unrecoverable data loss. Ensuring that backups are created and available in the cloud is critical to being able to recover in these circumstances.</p><h3><strong>This week we will look at how Turbot can automate enabling continuous backups with Point-in-Time Recovery of your Amazon DynamoDB tables.</strong></h3><h2><strong>Traditional Workflow</strong></h2><p>When database service capabilities were managed by central teams, developers didn&#8217;t need to worry about backups. The owner of the ITSM service that managed their database ensured robust configuration and protection of enterprise data assets.&nbsp; Cloud databases have similar capabilities, albeit with the condition that the development team must elect to enable and configure the backup services, a configuration step that can be forgotten, or in some cases enabled and then turned off at later points in time. Monitoring the current configuration of all your databases and ensuring that they meet the organization's data retention and backup requirements should be an automated governance control for all cloud databases.</p><h2><strong>Get it done with Turbot</strong></h2><p>In Turbot, Amazon DynamoDB Table guardrails are readily available to control your cloud resource configurations.&nbsp; We can set the Turbot automation `<strong>AWS &gt; DynamoDB &gt; Table &gt; Point-in-Time Recovery</strong>` policy in just a few clicks:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!klqw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fea4c5d71-d258-4e25-967e-ce0160b63d42_1157x1027.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!klqw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fea4c5d71-d258-4e25-967e-ce0160b63d42_1157x1027.png 424w, https://substackcdn.com/image/fetch/$s_!klqw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fea4c5d71-d258-4e25-967e-ce0160b63d42_1157x1027.png 848w, https://substackcdn.com/image/fetch/$s_!klqw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fea4c5d71-d258-4e25-967e-ce0160b63d42_1157x1027.png 1272w, https://substackcdn.com/image/fetch/$s_!klqw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fea4c5d71-d258-4e25-967e-ce0160b63d42_1157x1027.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!klqw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fea4c5d71-d258-4e25-967e-ce0160b63d42_1157x1027.png" width="1157" height="1027" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/ea4c5d71-d258-4e25-967e-ce0160b63d42_1157x1027.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1027,&quot;width&quot;:1157,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:104421,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!klqw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fea4c5d71-d258-4e25-967e-ce0160b63d42_1157x1027.png 424w, https://substackcdn.com/image/fetch/$s_!klqw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fea4c5d71-d258-4e25-967e-ce0160b63d42_1157x1027.png 848w, https://substackcdn.com/image/fetch/$s_!klqw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fea4c5d71-d258-4e25-967e-ce0160b63d42_1157x1027.png 1272w, https://substackcdn.com/image/fetch/$s_!klqw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fea4c5d71-d258-4e25-967e-ce0160b63d42_1157x1027.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><strong>Set a policy to take corrective action for enabling point-in-time recovery.</strong></figcaption></figure></div><div class="preformatted-block" data-component-name="PreformattedTextBlockToDOM"><label class="hide-text" contenteditable="false">Text within this block will maintain its original spacing when published</label><pre class="text">      </pre></div><p>Setting the configuration via Turbot&#8217;s Terraform provider is just as easy:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5IvF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfe0af1d-c67b-4bf3-83ac-7cb921f4a8f0_1484x700.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5IvF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfe0af1d-c67b-4bf3-83ac-7cb921f4a8f0_1484x700.png 424w, https://substackcdn.com/image/fetch/$s_!5IvF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfe0af1d-c67b-4bf3-83ac-7cb921f4a8f0_1484x700.png 848w, https://substackcdn.com/image/fetch/$s_!5IvF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfe0af1d-c67b-4bf3-83ac-7cb921f4a8f0_1484x700.png 1272w, https://substackcdn.com/image/fetch/$s_!5IvF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfe0af1d-c67b-4bf3-83ac-7cb921f4a8f0_1484x700.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5IvF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfe0af1d-c67b-4bf3-83ac-7cb921f4a8f0_1484x700.png" width="1456" height="687" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/dfe0af1d-c67b-4bf3-83ac-7cb921f4a8f0_1484x700.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:687,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:105445,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5IvF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfe0af1d-c67b-4bf3-83ac-7cb921f4a8f0_1484x700.png 424w, https://substackcdn.com/image/fetch/$s_!5IvF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfe0af1d-c67b-4bf3-83ac-7cb921f4a8f0_1484x700.png 848w, https://substackcdn.com/image/fetch/$s_!5IvF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfe0af1d-c67b-4bf3-83ac-7cb921f4a8f0_1484x700.png 1272w, https://substackcdn.com/image/fetch/$s_!5IvF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfe0af1d-c67b-4bf3-83ac-7cb921f4a8f0_1484x700.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Terraform template to set the <strong>AWS &gt;DynamoDB &gt; Table &gt; Point-in-Time Recovery</strong> policy in Turbot<strong>.</strong></p><p>After setting these policies, Turbot will identify all DynamoDB tables that are not enabled for point-in-time recovery, and then handle remediation (i.e. enable the configuration).</p><p>If you are not yet ready to enforce remediation, you can still assess the impact of this in your environment by setting the value to '<strong>Check: Enabled</strong>` at the Turbot level.&nbsp; In &#8216;Check&#8217; mode Turbot will alarm on tables which do not have point-in-time recovery in place. After review of the alarms, selectively apply the enforcement settings or create exceptions as desired.&nbsp;</p><p>Given that continuous backups may not be appropriate for all tables (e.g. development), make use of Turbot&#8217;s <a href="https://turbot.com/v5/docs/guides/managing-policies#creating-an-exception">policy exceptions</a> as necessary to achieve your desired compliance outcome across all environments.</p><h2><strong>Make it happen</strong></h2><p>See for yourself how easy it is to manage your backup configurations across your cloud resources. A <strong>ready-to-run</strong> Terraform template is available to enable this configuration from the <a href="https://github.com/turbot/tdk/tree/master/control_objectives/aws_dynamodb_backups_pit_recovery">Turbot Development Kit (TDK)</a>. If you need any assistance please reach out to <a href="mailto:support@turbot.com">Turbot Support</a>, and keep an eye on your inbox for another Turbot tip next week!</p><p>Cheers,</p><p>Bob</p>]]></content:encoded></item><item><title><![CDATA[[Turbot On] Tagging with Context]]></title><description><![CDATA[Automate application of resource tags from CMDB metadata.]]></description><link>https://on.turbot.com/p/turbot-on-tagging-with-context</link><guid isPermaLink="false">https://on.turbot.com/p/turbot-on-tagging-with-context</guid><dc:creator><![CDATA[Bob Tordella]]></dc:creator><pubDate>Mon, 17 May 2021 18:44:38 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!w4Vf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5be6ee6d-b843-47f9-bcab-20db13d3f72d_1600x900.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!w4Vf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5be6ee6d-b843-47f9-bcab-20db13d3f72d_1600x900.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!w4Vf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5be6ee6d-b843-47f9-bcab-20db13d3f72d_1600x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!w4Vf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5be6ee6d-b843-47f9-bcab-20db13d3f72d_1600x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!w4Vf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5be6ee6d-b843-47f9-bcab-20db13d3f72d_1600x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!w4Vf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5be6ee6d-b843-47f9-bcab-20db13d3f72d_1600x900.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!w4Vf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5be6ee6d-b843-47f9-bcab-20db13d3f72d_1600x900.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/5be6ee6d-b843-47f9-bcab-20db13d3f72d_1600x900.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!w4Vf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5be6ee6d-b843-47f9-bcab-20db13d3f72d_1600x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!w4Vf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5be6ee6d-b843-47f9-bcab-20db13d3f72d_1600x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!w4Vf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5be6ee6d-b843-47f9-bcab-20db13d3f72d_1600x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!w4Vf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5be6ee6d-b843-47f9-bcab-20db13d3f72d_1600x900.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Tagging is a crucial component for cloud operations, security and compliance. The most common tagging methodologies rely on <a href="https://on.turbot.com/p/automating-resource-owner-tags">owner-assigned resource tags</a> to add external context to resources; however, additional deep context can be added to resources via automation.</p><h4><strong>This week we will look at how to &#8220;level up&#8221; your tagging game using automation and additional context from the Turbot CMDB</strong></h4><h2><strong>Traditional Workflow</strong></h2><p>Quick and transparent visibility to resource metadata can save precious minutes during an incident, but compliance from application teams to create and update tags is notoriously difficult to enforce. This leaves the cloud team in the unenviable position of nagging application teams to complete tagging of their resources.</p><p>For information that is dynamic, the problem is even more difficult. We don&#8217;t recommend trying to implement tagging standards for dynamic data unless you are using automation to implement it.</p><h2><strong>Get it done with Turbot</strong></h2><p><a href="https://turbot.com/v5/docs/concepts/guardrails/tagging">Turbot&#8217;s tagging controls</a>  <strong>are consistent across AWS, Azure and GCP</strong> resources. Furthermore, all resource metadata is stored in Turbot&#8217;s cloud scale CMDB and updated in real-time as configurations change.&nbsp; Any detailed information in the CMDB can be leveraged for your resource tagging templates. For example, an AWS EC2 instance has over 100 fields that could be used in tag templates:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!c7FI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44fead9d-bf5b-447a-bde7-b88294136116_1714x1264.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!c7FI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44fead9d-bf5b-447a-bde7-b88294136116_1714x1264.png 424w, https://substackcdn.com/image/fetch/$s_!c7FI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44fead9d-bf5b-447a-bde7-b88294136116_1714x1264.png 848w, https://substackcdn.com/image/fetch/$s_!c7FI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44fead9d-bf5b-447a-bde7-b88294136116_1714x1264.png 1272w, https://substackcdn.com/image/fetch/$s_!c7FI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44fead9d-bf5b-447a-bde7-b88294136116_1714x1264.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!c7FI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44fead9d-bf5b-447a-bde7-b88294136116_1714x1264.png" width="1456" height="1074" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/44fead9d-bf5b-447a-bde7-b88294136116_1714x1264.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1074,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:128508,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!c7FI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44fead9d-bf5b-447a-bde7-b88294136116_1714x1264.png 424w, https://substackcdn.com/image/fetch/$s_!c7FI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44fead9d-bf5b-447a-bde7-b88294136116_1714x1264.png 848w, https://substackcdn.com/image/fetch/$s_!c7FI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44fead9d-bf5b-447a-bde7-b88294136116_1714x1264.png 1272w, https://substackcdn.com/image/fetch/$s_!c7FI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44fead9d-bf5b-447a-bde7-b88294136116_1714x1264.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>To demonstrate the approach we will use a Turbot calculated policy to tag our EC2 instances with their corresponding <code>ImageId</code>, <code>Instance Type</code>, <code>SubnetId</code> and <code>VpcID</code>:</p><p></p><p><em><strong>First, set the calculated policy query:</strong></em></p><pre><code>{
  instance {
&nbsp;&nbsp;&nbsp;&nbsp;ImageId
&nbsp;&nbsp;&nbsp;&nbsp;InstanceType
&nbsp;&nbsp;&nbsp;&nbsp;SubnetId
&nbsp;&nbsp;&nbsp;&nbsp;VpcId
&nbsp;&nbsp;}
}</code></pre><p></p><p><em><strong>Then, the calculated policy output template:</strong></em></p><pre><code>Image: "{{ $.instance.ImageId }}"
Type: "{{ $.instance.InstanceType }}"
Subnet: "{{ $.instance.SubnetId }}"
VPC: "{{ $.instance.VpcId }}"</code></pre><p></p><p><em><strong>Finally, set a standard policy to enforce the Tag control:</strong></em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-sKi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff84dc911-1088-4a4c-89c9-d44a0416a0c5_969x797.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-sKi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff84dc911-1088-4a4c-89c9-d44a0416a0c5_969x797.png 424w, https://substackcdn.com/image/fetch/$s_!-sKi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff84dc911-1088-4a4c-89c9-d44a0416a0c5_969x797.png 848w, https://substackcdn.com/image/fetch/$s_!-sKi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff84dc911-1088-4a4c-89c9-d44a0416a0c5_969x797.png 1272w, https://substackcdn.com/image/fetch/$s_!-sKi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff84dc911-1088-4a4c-89c9-d44a0416a0c5_969x797.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-sKi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff84dc911-1088-4a4c-89c9-d44a0416a0c5_969x797.png" width="969" height="797" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/f84dc911-1088-4a4c-89c9-d44a0416a0c5_969x797.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:797,&quot;width&quot;:969,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:58799,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-sKi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff84dc911-1088-4a4c-89c9-d44a0416a0c5_969x797.png 424w, https://substackcdn.com/image/fetch/$s_!-sKi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff84dc911-1088-4a4c-89c9-d44a0416a0c5_969x797.png 848w, https://substackcdn.com/image/fetch/$s_!-sKi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff84dc911-1088-4a4c-89c9-d44a0416a0c5_969x797.png 1272w, https://substackcdn.com/image/fetch/$s_!-sKi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff84dc911-1088-4a4c-89c9-d44a0416a0c5_969x797.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The example above can easily be adjusted for any resource that can be tagged:</p><ul><li><p>The tagging controls and templates are always found as a subset of the resource e.g.: <strong>`{Cloud Provider} &gt; {Service} &gt; {Resource} &gt; Tags &gt; Template`</strong></p></li><li><p>The naming and functions are consistent across all cloud providers &amp; resources.</p></li><li><p>In addition, whenever the underlying configuration changes, Turbot will update the tags with new correct values.</p><p></p></li></ul><p><strong>Setting the configuration via Turbot&#8217;s Terraform provider is just as easy:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xp1W!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F335fc3bd-506f-4239-afd3-4ed8414cc695_1518x1604.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xp1W!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F335fc3bd-506f-4239-afd3-4ed8414cc695_1518x1604.png 424w, https://substackcdn.com/image/fetch/$s_!xp1W!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F335fc3bd-506f-4239-afd3-4ed8414cc695_1518x1604.png 848w, https://substackcdn.com/image/fetch/$s_!xp1W!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F335fc3bd-506f-4239-afd3-4ed8414cc695_1518x1604.png 1272w, https://substackcdn.com/image/fetch/$s_!xp1W!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F335fc3bd-506f-4239-afd3-4ed8414cc695_1518x1604.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xp1W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F335fc3bd-506f-4239-afd3-4ed8414cc695_1518x1604.png" width="1456" height="1538" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/335fc3bd-506f-4239-afd3-4ed8414cc695_1518x1604.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1538,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:221079,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xp1W!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F335fc3bd-506f-4239-afd3-4ed8414cc695_1518x1604.png 424w, https://substackcdn.com/image/fetch/$s_!xp1W!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F335fc3bd-506f-4239-afd3-4ed8414cc695_1518x1604.png 848w, https://substackcdn.com/image/fetch/$s_!xp1W!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F335fc3bd-506f-4239-afd3-4ed8414cc695_1518x1604.png 1272w, https://substackcdn.com/image/fetch/$s_!xp1W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F335fc3bd-506f-4239-afd3-4ed8414cc695_1518x1604.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Terraform template to set the <strong>AWS &gt;EC2 &gt; Instance &gt; Tags and Tags &gt; Template.</strong></figcaption></figure></div><p></p><p>After setting this policy, Turbot will identify all resources that do not have the tags applied correctly, and then handle their remediation (i.e. set the tags).</p><p>If you are not yet ready to enforce remediation, you can still assess (and get alerts for) what resources do not have matching tags by changing the policy setting from `<strong>Enforce: Tags are correct </strong>`to `<strong>Check: Tags are correct</strong>`.</p><h2><strong>Make it happen</strong></h2><p>See for yourself how easy it is to manage your tagging configurations across your cloud resources. A <strong>ready-to-run</strong> Terraform template is available to enable this configuration from the <a href="https://github.com/turbot/tdk/tree/master/calculated_policies/resource_tagging">Turbot Development Kit (TDK)</a>. If you need any assistance please reach out to <a href="mailto:support@turbot.com">Turbot Support</a>, and keep an eye on your inbox for another Turbot tip next week!</p><p>Cheers,</p><p>Bob</p>]]></content:encoded></item><item><title><![CDATA[[Turbot On] S3 Public Access Blocks ]]></title><description><![CDATA[Automate AWS S3 account and bucket level public access blocks.]]></description><link>https://on.turbot.com/p/turbot-on-s3-public-access-blocks</link><guid isPermaLink="false">https://on.turbot.com/p/turbot-on-s3-public-access-blocks</guid><dc:creator><![CDATA[Bob Tordella]]></dc:creator><pubDate>Mon, 10 May 2021 17:52:37 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!5wwD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fef284530-a750-446a-839a-433b1366a2bb_3199x1800.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5wwD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fef284530-a750-446a-839a-433b1366a2bb_3199x1800.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5wwD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fef284530-a750-446a-839a-433b1366a2bb_3199x1800.jpeg 424w, https://substackcdn.com/image/fetch/$s_!5wwD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fef284530-a750-446a-839a-433b1366a2bb_3199x1800.jpeg 848w, https://substackcdn.com/image/fetch/$s_!5wwD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fef284530-a750-446a-839a-433b1366a2bb_3199x1800.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!5wwD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fef284530-a750-446a-839a-433b1366a2bb_3199x1800.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5wwD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fef284530-a750-446a-839a-433b1366a2bb_3199x1800.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/ef284530-a750-446a-839a-433b1366a2bb_3199x1800.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:258127,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5wwD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fef284530-a750-446a-839a-433b1366a2bb_3199x1800.jpeg 424w, https://substackcdn.com/image/fetch/$s_!5wwD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fef284530-a750-446a-839a-433b1366a2bb_3199x1800.jpeg 848w, https://substackcdn.com/image/fetch/$s_!5wwD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fef284530-a750-446a-839a-433b1366a2bb_3199x1800.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!5wwD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fef284530-a750-446a-839a-433b1366a2bb_3199x1800.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Newly created S3 buckets are secure and private by default, but AWS S3 provides features that allows administrators to share buckets with other authenticated and unauthenticated (public) entities.&nbsp; This makes it possible to share a bucket between different applications running in separate AWS accounts, and to use the S3 service to host public information (e.g. a static website).</p><p>However, we often see developers relax permissions for a bucket or make bucket access public to try and resolve/troubleshoot a permissions issue. If not immediately remediated, this can lead to a data breach down the road. Given that these types of lapses occur <a href="https://news.google.com/search?q=s3+public+bucket+breach">all too frequently</a>, AWS has implemented new features to give organizations more control over the ability to enable public access.</p><h4><strong>This week we will look at the two types of AWS S3 public access blocks and show you how to use Turbot to ensure they are automatically enabled across all of your accounts and buckets.</strong></h4><p></p><h2><strong>S3 Account Public Access Blocks</strong></h2><p>Account-level public access blocks have the ability to eliminate public access in both access control lists (ACLs) and in S3 bucket IAM resource policies.&nbsp; You also have the option to block the creation of any new public access and/or to retroactively apply those settings to existing ACLs and bucket policies.&nbsp; This work can be easily accomplished through the console UI for a single account, but retroactively enabling those settings across hundreds of accounts (and making sure they are not turned off) is a job for automation.</p><p></p><h2><strong>S3 Bucket Public Access Blocks</strong></h2><p>Bucket-level public access blocks apply protection in broad strokes, but won&#8217;t work in use cases where some bucket sharing is necessary.&nbsp; For example, a customer might want to share a bucket between their data lake account and separate accounts that perform compute functions on the data.&nbsp; In these circumstances you can use bucket level access blocks (instead of account level) to allow for some public or cross-account sharing on a bucket-by-bucket basis.</p><p>Enabling these public blocks across thousands of buckets, maintaining exception lists and ensuring that the configuration does not drift, is not something that can be done manually, it requires an automated continuous compliance solution.</p><p></p><h2><strong>Get it done with Turbot</strong></h2><p>In Turbot, AWS S3 public access block settings are readily available to control your cloud resource configurations.&nbsp; Setting the correct Turbot policies can be accomplished with just a few clicks:</p><h4><strong>AWS S3 Account-Level Public Access Block:</strong></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Tq7X!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44394269-6363-4b6b-a0fc-eab036fdc1e6_992x846.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Tq7X!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44394269-6363-4b6b-a0fc-eab036fdc1e6_992x846.png 424w, https://substackcdn.com/image/fetch/$s_!Tq7X!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44394269-6363-4b6b-a0fc-eab036fdc1e6_992x846.png 848w, https://substackcdn.com/image/fetch/$s_!Tq7X!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44394269-6363-4b6b-a0fc-eab036fdc1e6_992x846.png 1272w, https://substackcdn.com/image/fetch/$s_!Tq7X!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44394269-6363-4b6b-a0fc-eab036fdc1e6_992x846.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Tq7X!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44394269-6363-4b6b-a0fc-eab036fdc1e6_992x846.png" width="992" height="846" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/44394269-6363-4b6b-a0fc-eab036fdc1e6_992x846.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:846,&quot;width&quot;:992,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:65119,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Tq7X!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44394269-6363-4b6b-a0fc-eab036fdc1e6_992x846.png 424w, https://substackcdn.com/image/fetch/$s_!Tq7X!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44394269-6363-4b6b-a0fc-eab036fdc1e6_992x846.png 848w, https://substackcdn.com/image/fetch/$s_!Tq7X!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44394269-6363-4b6b-a0fc-eab036fdc1e6_992x846.png 1272w, https://substackcdn.com/image/fetch/$s_!Tq7X!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44394269-6363-4b6b-a0fc-eab036fdc1e6_992x846.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><strong>Configure which account level public access policy settings are needed.</strong></figcaption></figure></div><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!eYKY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcba6548e-b734-4b3a-80c6-8da2d4a15c4d_999x828.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!eYKY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcba6548e-b734-4b3a-80c6-8da2d4a15c4d_999x828.png 424w, https://substackcdn.com/image/fetch/$s_!eYKY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcba6548e-b734-4b3a-80c6-8da2d4a15c4d_999x828.png 848w, https://substackcdn.com/image/fetch/$s_!eYKY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcba6548e-b734-4b3a-80c6-8da2d4a15c4d_999x828.png 1272w, https://substackcdn.com/image/fetch/$s_!eYKY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcba6548e-b734-4b3a-80c6-8da2d4a15c4d_999x828.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!eYKY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcba6548e-b734-4b3a-80c6-8da2d4a15c4d_999x828.png" width="999" height="828" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/cba6548e-b734-4b3a-80c6-8da2d4a15c4d_999x828.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:828,&quot;width&quot;:999,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:63760,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!eYKY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcba6548e-b734-4b3a-80c6-8da2d4a15c4d_999x828.png 424w, https://substackcdn.com/image/fetch/$s_!eYKY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcba6548e-b734-4b3a-80c6-8da2d4a15c4d_999x828.png 848w, https://substackcdn.com/image/fetch/$s_!eYKY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcba6548e-b734-4b3a-80c6-8da2d4a15c4d_999x828.png 1272w, https://substackcdn.com/image/fetch/$s_!eYKY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcba6548e-b734-4b3a-80c6-8da2d4a15c4d_999x828.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><strong>Set the policy to take corrective action at the account level.</strong></figcaption></figure></div><p></p><h4><strong>AWS S3 Bucket Public Access Block:</strong></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fV9z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fda5540a9-2362-4ee4-8360-49420ef1bbbd_994x849.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fV9z!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fda5540a9-2362-4ee4-8360-49420ef1bbbd_994x849.png 424w, https://substackcdn.com/image/fetch/$s_!fV9z!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fda5540a9-2362-4ee4-8360-49420ef1bbbd_994x849.png 848w, https://substackcdn.com/image/fetch/$s_!fV9z!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fda5540a9-2362-4ee4-8360-49420ef1bbbd_994x849.png 1272w, https://substackcdn.com/image/fetch/$s_!fV9z!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fda5540a9-2362-4ee4-8360-49420ef1bbbd_994x849.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fV9z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fda5540a9-2362-4ee4-8360-49420ef1bbbd_994x849.png" width="994" height="849" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/da5540a9-2362-4ee4-8360-49420ef1bbbd_994x849.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:849,&quot;width&quot;:994,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:63016,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fV9z!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fda5540a9-2362-4ee4-8360-49420ef1bbbd_994x849.png 424w, https://substackcdn.com/image/fetch/$s_!fV9z!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fda5540a9-2362-4ee4-8360-49420ef1bbbd_994x849.png 848w, https://substackcdn.com/image/fetch/$s_!fV9z!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fda5540a9-2362-4ee4-8360-49420ef1bbbd_994x849.png 1272w, https://substackcdn.com/image/fetch/$s_!fV9z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fda5540a9-2362-4ee4-8360-49420ef1bbbd_994x849.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><strong>Configure the applicable bucket public access policy settings.</strong></figcaption></figure></div><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5A_R!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8598a007-9a41-4a62-9212-e0fbfc5c4698_998x825.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5A_R!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8598a007-9a41-4a62-9212-e0fbfc5c4698_998x825.png 424w, https://substackcdn.com/image/fetch/$s_!5A_R!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8598a007-9a41-4a62-9212-e0fbfc5c4698_998x825.png 848w, https://substackcdn.com/image/fetch/$s_!5A_R!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8598a007-9a41-4a62-9212-e0fbfc5c4698_998x825.png 1272w, https://substackcdn.com/image/fetch/$s_!5A_R!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8598a007-9a41-4a62-9212-e0fbfc5c4698_998x825.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5A_R!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8598a007-9a41-4a62-9212-e0fbfc5c4698_998x825.png" width="998" height="825" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/8598a007-9a41-4a62-9212-e0fbfc5c4698_998x825.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:825,&quot;width&quot;:998,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:64504,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5A_R!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8598a007-9a41-4a62-9212-e0fbfc5c4698_998x825.png 424w, https://substackcdn.com/image/fetch/$s_!5A_R!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8598a007-9a41-4a62-9212-e0fbfc5c4698_998x825.png 848w, https://substackcdn.com/image/fetch/$s_!5A_R!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8598a007-9a41-4a62-9212-e0fbfc5c4698_998x825.png 1272w, https://substackcdn.com/image/fetch/$s_!5A_R!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8598a007-9a41-4a62-9212-e0fbfc5c4698_998x825.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><strong>Set the policy to take corrective action at the bucket level.</strong></figcaption></figure></div><p></p><p>Setting the configuration via Turbot&#8217;s Terraform provider is just as easy:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!g-Uo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4a03e0d0-19ff-4811-b1df-7f7d983ced90_1686x1680.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!g-Uo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4a03e0d0-19ff-4811-b1df-7f7d983ced90_1686x1680.png 424w, https://substackcdn.com/image/fetch/$s_!g-Uo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4a03e0d0-19ff-4811-b1df-7f7d983ced90_1686x1680.png 848w, https://substackcdn.com/image/fetch/$s_!g-Uo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4a03e0d0-19ff-4811-b1df-7f7d983ced90_1686x1680.png 1272w, https://substackcdn.com/image/fetch/$s_!g-Uo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4a03e0d0-19ff-4811-b1df-7f7d983ced90_1686x1680.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!g-Uo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4a03e0d0-19ff-4811-b1df-7f7d983ced90_1686x1680.png" width="1456" height="1451" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/4a03e0d0-19ff-4811-b1df-7f7d983ced90_1686x1680.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1451,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:308921,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!g-Uo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4a03e0d0-19ff-4811-b1df-7f7d983ced90_1686x1680.png 424w, https://substackcdn.com/image/fetch/$s_!g-Uo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4a03e0d0-19ff-4811-b1df-7f7d983ced90_1686x1680.png 848w, https://substackcdn.com/image/fetch/$s_!g-Uo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4a03e0d0-19ff-4811-b1df-7f7d983ced90_1686x1680.png 1272w, https://substackcdn.com/image/fetch/$s_!g-Uo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4a03e0d0-19ff-4811-b1df-7f7d983ced90_1686x1680.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>After setting these policies, Turbot will identify all AWS accounts and S3 buckets that are not enabled for public access block settings, and then handle remediation (i.e. set the configurations).</p><p>If you are not yet ready to enforce remediation, you can still assess the impact of this in your environment by setting the value to 'Check: Per `Public Access Block&nbsp; &gt; Settings` at the Turbot level.&nbsp; In &#8216;Check&#8217; mode Turbot will alarm on accounts and buckets that do not have public blocks in place. After review of the alarms, selectively apply the enforcement settings or create exceptions as desired.&nbsp;</p><p>Given that denying public access may not be applicable for all accounts and buckets, make use of Turbot&#8217;s <a href="https://turbot.com/v5/docs/guides/managing-policies#creating-an-exception">policy exceptions</a> and <a href="https://turbot.com/v5/docs/concepts/policies/values-settings#expiration">time-based expiration</a> settings features to mark exceptions to the rule or automatically reset a configuration when the exception expires.</p><p></p><h2><strong>Make it happen</strong></h2><p>See for yourself how easy it is to manage your public access block settings. A <strong>ready-to-run</strong> Terraform template is available to enable this configuration from the open source <a href="https://github.com/turbot/tdk/tree/master/control_objectives/aws_s3_public_access_block">Turbot Development Kit (TDK)</a>. If you need any assistance getting with these policies please reach out to <a href="mailto:support@turbot.com">Turbot Support</a>, and keep an eye on your inbox for another Turbot tip next week!</p><p>Cheers,</p><p>Bob</p>]]></content:encoded></item><item><title><![CDATA[[Turbot On] GCP Firewall Rule Logging]]></title><description><![CDATA[Automatically enable GCP Firewall Logging for one or more firewall rules.]]></description><link>https://on.turbot.com/p/gcp-firewall-rule-logging</link><guid isPermaLink="false">https://on.turbot.com/p/gcp-firewall-rule-logging</guid><dc:creator><![CDATA[Bob Tordella]]></dc:creator><pubDate>Mon, 03 May 2021 15:55:09 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!heOA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F45b93a15-c232-4d9d-aa64-9ebf00b1c323_3200x1800.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!heOA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F45b93a15-c232-4d9d-aa64-9ebf00b1c323_3200x1800.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!heOA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F45b93a15-c232-4d9d-aa64-9ebf00b1c323_3200x1800.jpeg 424w, https://substackcdn.com/image/fetch/$s_!heOA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F45b93a15-c232-4d9d-aa64-9ebf00b1c323_3200x1800.jpeg 848w, https://substackcdn.com/image/fetch/$s_!heOA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F45b93a15-c232-4d9d-aa64-9ebf00b1c323_3200x1800.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!heOA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F45b93a15-c232-4d9d-aa64-9ebf00b1c323_3200x1800.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!heOA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F45b93a15-c232-4d9d-aa64-9ebf00b1c323_3200x1800.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/45b93a15-c232-4d9d-aa64-9ebf00b1c323_3200x1800.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2406790,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!heOA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F45b93a15-c232-4d9d-aa64-9ebf00b1c323_3200x1800.jpeg 424w, https://substackcdn.com/image/fetch/$s_!heOA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F45b93a15-c232-4d9d-aa64-9ebf00b1c323_3200x1800.jpeg 848w, https://substackcdn.com/image/fetch/$s_!heOA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F45b93a15-c232-4d9d-aa64-9ebf00b1c323_3200x1800.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!heOA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F45b93a15-c232-4d9d-aa64-9ebf00b1c323_3200x1800.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Firewall Rule Logging in Google Cloud (GCP) allows for audit, verification, and analysis of the configuration of firewall rules. With logging enabled it&#8217;s possible to determine if a firewall rule is functioning as intended, and how many connections are affected by any given rule. </p><p>Each log record record contains the source and destination IP addresses, the protocol and ports used, the date and time, and a reference to the firewall rule that applied to the traffic.&nbsp; This information can assist in identifying potential operational and security risks in your environment.</p><p></p><h3>This week we will look at how Turbot can automate the task of enabling GCP Firewall Rule logging on a single rule or across all rules in many GCP projects.</h3><p></p><h2><strong>Traditional Workflow</strong></h2><p>The GCP console or APIs can be used to enable and disable firewall rule logging. When you enable this feature, the GCP Firewall service makes the logs available in Logs Explorer and in Firewall Insights. While it is simple to configure for a few firewall rules, ensuring that this logging is always enabled for all rules across dozens (or hundreds) of GCP projects would require development of automation scripts.</p><h2><strong>Get it done with Turbot</strong></h2><p>In Turbot, GCP Firewall Logging guardrails are readily available to control your cloud resource configurations.&nbsp; We can enable this automation by setting the `<strong>GCP &gt; Network &gt; Firewall &gt; Logging</strong>` policy with just a few clicks in the Turbot GUI:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4SO0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9d858513-433a-4692-8b38-5ea4905c31b4_991x882.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4SO0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9d858513-433a-4692-8b38-5ea4905c31b4_991x882.png 424w, https://substackcdn.com/image/fetch/$s_!4SO0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9d858513-433a-4692-8b38-5ea4905c31b4_991x882.png 848w, https://substackcdn.com/image/fetch/$s_!4SO0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9d858513-433a-4692-8b38-5ea4905c31b4_991x882.png 1272w, https://substackcdn.com/image/fetch/$s_!4SO0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9d858513-433a-4692-8b38-5ea4905c31b4_991x882.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4SO0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9d858513-433a-4692-8b38-5ea4905c31b4_991x882.png" width="991" height="882" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/9d858513-433a-4692-8b38-5ea4905c31b4_991x882.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:882,&quot;width&quot;:991,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:51072,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4SO0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9d858513-433a-4692-8b38-5ea4905c31b4_991x882.png 424w, https://substackcdn.com/image/fetch/$s_!4SO0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9d858513-433a-4692-8b38-5ea4905c31b4_991x882.png 848w, https://substackcdn.com/image/fetch/$s_!4SO0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9d858513-433a-4692-8b38-5ea4905c31b4_991x882.png 1272w, https://substackcdn.com/image/fetch/$s_!4SO0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9d858513-433a-4692-8b38-5ea4905c31b4_991x882.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><strong>Set a policy to take corrective action for enabling firewall rule logging.</strong></figcaption></figure></div><p></p><p>Setting the configuration via Turbot&#8217;s Terraform provider is just as easy:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8kw3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Facbd84a6-3046-462d-92b0-d0539d3774d6_3344x2292.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8kw3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Facbd84a6-3046-462d-92b0-d0539d3774d6_3344x2292.png 424w, https://substackcdn.com/image/fetch/$s_!8kw3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Facbd84a6-3046-462d-92b0-d0539d3774d6_3344x2292.png 848w, https://substackcdn.com/image/fetch/$s_!8kw3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Facbd84a6-3046-462d-92b0-d0539d3774d6_3344x2292.png 1272w, https://substackcdn.com/image/fetch/$s_!8kw3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Facbd84a6-3046-462d-92b0-d0539d3774d6_3344x2292.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8kw3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Facbd84a6-3046-462d-92b0-d0539d3774d6_3344x2292.png" width="1456" height="998" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/acbd84a6-3046-462d-92b0-d0539d3774d6_3344x2292.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:998,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:334062,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8kw3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Facbd84a6-3046-462d-92b0-d0539d3774d6_3344x2292.png 424w, https://substackcdn.com/image/fetch/$s_!8kw3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Facbd84a6-3046-462d-92b0-d0539d3774d6_3344x2292.png 848w, https://substackcdn.com/image/fetch/$s_!8kw3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Facbd84a6-3046-462d-92b0-d0539d3774d6_3344x2292.png 1272w, https://substackcdn.com/image/fetch/$s_!8kw3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Facbd84a6-3046-462d-92b0-d0539d3774d6_3344x2292.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Terraform template to set the <strong>GCP &gt; Network &gt; Firewall &gt; Logging policy.</strong></figcaption></figure></div><p></p><p>After setting this policy, Turbot will identify all firewall rules that are not enabled for firewall rule logging, and then handle their remediation (i.e. enable the logging configuration).</p><p>If you are not yet ready to enforce remediation, you can still assess what rules do not have logging enabled by setting the value to `<strong>Check: Enabled</strong>` at the Turbot level.&nbsp; </p><p>Turning on firewall logging can generate a large number of logs which can increase GCP Stackdriver costs.&nbsp; To prevent costs from running out of control, use Turbot&#8217;s time-based policy expiration feature to automatically reset the configuration after a given time period has elapsed, or when you no longer need logging enabled.</p><p></p><h2><strong>Make it happen</strong></h2><p>See for yourself how easy it is to manage your logging configuration across your GCP firewalls. A <strong>ready-to-run</strong> Terraform template is available to enable this configuration from the <a href="https://github.com/turbot/tdk/tree/master/control_objectives/gcp_network_firewall_logging">Turbot Development Kit (TDK)</a>. If you need any assistance please reach out to <a href="mailto:support@turbot.com">Turbot Support</a>, and keep an eye on your inbox for another Turbot tip next week!</p><p>Cheers,</p><p>Bob</p>]]></content:encoded></item></channel></rss>