Property
Languagehcl
Severitymedium
CWECWE-778: Insufficient Logging
OWASPA09:2021 - Security Logging and Monitoring Failures
Confidence LevelHigh
Impact LevelMedium
Likelihood LevelLow

Description#

The AWS Config aggregator is set to collect configuration data from only specific regions instead of all regions. This leaves some AWS regions unmonitored, potentially missing important changes in those areas.

Impact#

If not all regions are included, unauthorized or accidental changes in unmonitored regions could go undetected, leading to blind spots in security monitoring. Attackers or misconfigurations in these regions might compromise resources without being logged or alerted.