Low
GuardDuty
Regional
GuardDuty detectors should be tagged
Description
Flags Amazon GuardDuty detectors that have no user-defined tags. Tags help associate detectors with their owning team and account-organisation lineage; untagged detectors are operationally opaque.
Remediation
Apply at least one user-defined tag to every GuardDuty detector.
Steps
- Open the Amazon GuardDuty console.
- Choose Settings, then select Tags.
- Add at least one tag with a non-aws: prefixed key.
- Save the changes.