chore(aws): enhance metadata for fms service (#9005)

Co-authored-by: Sergio Garcia <hello@mistercloudsec.com>
This commit is contained in:
Rubén De la Torre Vico
2025-10-29 19:15:00 +01:00
committed by GitHub
parent f2f1e6bce6
commit 2a9c2b926d
2 changed files with 24 additions and 11 deletions
+1
View File
@@ -71,6 +71,7 @@ All notable changes to the **Prowler SDK** are documented in this file.
- Update AWS CloudFront service metadata to new format [(#8829)](https://github.com/prowler-cloud/prowler/pull/8829)
- Deprecate user authentication for M365 provider [(#8865)](https://github.com/prowler-cloud/prowler/pull/8865)
- Update AWS EFS service metadata to new format [(#8889)](https://github.com/prowler-cloud/prowler/pull/8889)
- Update AWS FMS service metadata to new format [(#9005)](https://github.com/prowler-cloud/prowler/pull/9005)
- Update AWS FSx service metadata to new format [(#9006)](https://github.com/prowler-cloud/prowler/pull/9006)
- Update AWS Glacier service metadata to new format [(#9007)](https://github.com/prowler-cloud/prowler/pull/9007)
@@ -1,29 +1,41 @@
{
"Provider": "aws",
"CheckID": "fms_policy_compliant",
"CheckTitle": "Ensure that all FMS policies inside an admin account are compliant",
"CheckType": [],
"CheckTitle": "All AWS FMS policies in the admin account are compliant for all accounts",
"CheckType": [
"Software and Configuration Checks/AWS Security Best Practices/Network Reachability",
"Software and Configuration Checks/Industry and Regulatory Standards/AWS Foundational Security Best Practices"
],
"ServiceName": "fms",
"SubServiceName": "",
"ResourceIdTemplate": "arn:aws:fms:region:account-id:policy/policy",
"ResourceIdTemplate": "",
"Severity": "medium",
"ResourceType": "Other",
"Description": "This check ensures all FMS policies inside an admin account are compliant",
"Risk": "If FMS policies are not compliant, means there are resources unprotected by the policies",
"RelatedUrl": "https://docs.aws.amazon.com/waf/latest/developerguide/getting-started-fms-intro.html",
"Description": "**Firewall Manager** policies in the administrator account are evaluated for organization-wide compliance. The assessment reviews each policy's account-level status and flags entries marked `NON_COMPLIANT` or unset. It also identifies when no effective policies exist within the administrator scope.",
"Risk": "Policy drift or absence leaves in-scope resources without enforced controls, degrading **confidentiality**, **integrity**, and **availability**. Missing WAF, Shield, security group, or network firewall baselines can enable DDoS exposure, unsafe routes, and open access, leading to unauthorized entry and data exfiltration.",
"RelatedUrl": "",
"AdditionalURLs": [
"https://aws.amazon.com/firewall-manager/faqs/",
"https://docs.aws.amazon.com/waf/latest/developerguide/getting-started-fms-intro.html",
"https://www.amazonaws.cn/en/firewall-manager/faqs/",
"https://docs.aws.amazon.com/waf/latest/developerguide/fms-compliance.html"
],
"Remediation": {
"Code": {
"CLI": "aws fms list-policies",
"CLI": "",
"NativeIaC": "",
"Other": "",
"Other": "1. Sign in to the AWS console with the Firewall Manager administrator account\n2. Open Firewall Manager > Security policies\n3. If no policies exist: Click Create policy, choose the policy type you use, set scope to All accounts, enable Automatic remediation, and create the policy\n4. If policies exist with Noncompliant accounts: Open the policy > Edit > enable Automatic remediation and ensure scope includes All accounts > Save\n5. In AWS Config (organization management account): Settings > Organization settings > Enable recording for all accounts and all regions > Save\n6. Return to each Firewall Manager policy and verify Accounts within policy scope show Compliant",
"Terraform": ""
},
"Recommendation": {
"Text": "Ensure FMS is enabled and all the policies are compliant across your AWS accounts",
"Url": "https://docs.aws.amazon.com/waf/latest/developerguide/getting-started-fms-intro.html"
"Text": "Maintain centralized enforcement with **Firewall Manager**: define mandatory policies for all relevant accounts/resources, enable automatic remediation where appropriate, and continuously monitor compliance. Apply **least privilege** and **defense in depth** by standardizing web, network, and DNS protections and alerting on drift.",
"Url": "https://hub.prowler.com/check/fms_policy_compliant"
}
},
"Categories": [],
"Categories": [
"internet-exposed",
"trust-boundaries"
],
"DependsOn": [],
"RelatedTo": [],
"Notes": ""