diff --git a/prowler/CHANGELOG.md b/prowler/CHANGELOG.md index 5b535ef680..70a9d10b26 100644 --- a/prowler/CHANGELOG.md +++ b/prowler/CHANGELOG.md @@ -71,6 +71,7 @@ All notable changes to the **Prowler SDK** are documented in this file. - Update AWS CloudFront service metadata to new format [(#8829)](https://github.com/prowler-cloud/prowler/pull/8829) - Deprecate user authentication for M365 provider [(#8865)](https://github.com/prowler-cloud/prowler/pull/8865) - Update AWS EFS service metadata to new format [(#8889)](https://github.com/prowler-cloud/prowler/pull/8889) +- Update AWS FMS service metadata to new format [(#9005)](https://github.com/prowler-cloud/prowler/pull/9005) - Update AWS FSx service metadata to new format [(#9006)](https://github.com/prowler-cloud/prowler/pull/9006) - Update AWS Glacier service metadata to new format [(#9007)](https://github.com/prowler-cloud/prowler/pull/9007) diff --git a/prowler/providers/aws/services/fms/fms_policy_compliant/fms_policy_compliant.metadata.json b/prowler/providers/aws/services/fms/fms_policy_compliant/fms_policy_compliant.metadata.json index b8d67bf4ac..3472a777f4 100644 --- a/prowler/providers/aws/services/fms/fms_policy_compliant/fms_policy_compliant.metadata.json +++ b/prowler/providers/aws/services/fms/fms_policy_compliant/fms_policy_compliant.metadata.json @@ -1,29 +1,41 @@ { "Provider": "aws", "CheckID": "fms_policy_compliant", - "CheckTitle": "Ensure that all FMS policies inside an admin account are compliant", - "CheckType": [], + "CheckTitle": "All AWS FMS policies in the admin account are compliant for all accounts", + "CheckType": [ + "Software and Configuration Checks/AWS Security Best Practices/Network Reachability", + "Software and Configuration Checks/Industry and Regulatory Standards/AWS Foundational Security Best Practices" + ], "ServiceName": "fms", "SubServiceName": "", - "ResourceIdTemplate": "arn:aws:fms:region:account-id:policy/policy", + "ResourceIdTemplate": "", "Severity": "medium", "ResourceType": "Other", - "Description": "This check ensures all FMS policies inside an admin account are compliant", - "Risk": "If FMS policies are not compliant, means there are resources unprotected by the policies", - "RelatedUrl": "https://docs.aws.amazon.com/waf/latest/developerguide/getting-started-fms-intro.html", + "Description": "**Firewall Manager** policies in the administrator account are evaluated for organization-wide compliance. The assessment reviews each policy's account-level status and flags entries marked `NON_COMPLIANT` or unset. It also identifies when no effective policies exist within the administrator scope.", + "Risk": "Policy drift or absence leaves in-scope resources without enforced controls, degrading **confidentiality**, **integrity**, and **availability**. Missing WAF, Shield, security group, or network firewall baselines can enable DDoS exposure, unsafe routes, and open access, leading to unauthorized entry and data exfiltration.", + "RelatedUrl": "", + "AdditionalURLs": [ + "https://aws.amazon.com/firewall-manager/faqs/", + "https://docs.aws.amazon.com/waf/latest/developerguide/getting-started-fms-intro.html", + "https://www.amazonaws.cn/en/firewall-manager/faqs/", + "https://docs.aws.amazon.com/waf/latest/developerguide/fms-compliance.html" + ], "Remediation": { "Code": { - "CLI": "aws fms list-policies", + "CLI": "", "NativeIaC": "", - "Other": "", + "Other": "1. Sign in to the AWS console with the Firewall Manager administrator account\n2. Open Firewall Manager > Security policies\n3. If no policies exist: Click Create policy, choose the policy type you use, set scope to All accounts, enable Automatic remediation, and create the policy\n4. If policies exist with Noncompliant accounts: Open the policy > Edit > enable Automatic remediation and ensure scope includes All accounts > Save\n5. In AWS Config (organization management account): Settings > Organization settings > Enable recording for all accounts and all regions > Save\n6. Return to each Firewall Manager policy and verify Accounts within policy scope show Compliant", "Terraform": "" }, "Recommendation": { - "Text": "Ensure FMS is enabled and all the policies are compliant across your AWS accounts", - "Url": "https://docs.aws.amazon.com/waf/latest/developerguide/getting-started-fms-intro.html" + "Text": "Maintain centralized enforcement with **Firewall Manager**: define mandatory policies for all relevant accounts/resources, enable automatic remediation where appropriate, and continuously monitor compliance. Apply **least privilege** and **defense in depth** by standardizing web, network, and DNS protections and alerting on drift.", + "Url": "https://hub.prowler.com/check/fms_policy_compliant" } }, - "Categories": [], + "Categories": [ + "internet-exposed", + "trust-boundaries" + ], "DependsOn": [], "RelatedTo": [], "Notes": ""