Medium
GuardDuty
Regional
GuardDuty EC2 Runtime Monitoring should be enabled
FSBP
Description
Ensures the GuardDuty automated security agent is enabled for EC2 runtime monitoring in all accounts. GuardDuty Runtime Monitoring observes OS-level, networking, and file events to detect threats in EC2 workloads.
Remediation
To enable GuardDuty EC2 Runtime Monitoring, you need to configure the EC2 Runtime Monitoring settings in GuardDuty.
Steps
- Navigate to the Amazon GuardDuty console
- Go to 'Settings' in the left navigation
- Select 'Runtime Monitoring'
- Enable 'EC2 Runtime Monitoring'
- Configure security agents for EC2 instances
- Set up monitoring for EC2 workloads
- Save the configuration
- Verify that EC2 Runtime Monitoring is active
Compliance
FSBP