Low
GuardDuty
Regional
GuardDuty IPSets should be tagged
Description
Flags Amazon GuardDuty IPSets that have no user-defined tags. Tags help associate IPSets with their owning team and threat intelligence feed lineage; untagged IPSets are operationally opaque.
Remediation
Apply at least one user-defined tag to every GuardDuty IPSet.
Steps
- Open the Amazon GuardDuty console and choose Lists, then Trusted IP lists / Threat lists.
- Select the affected IPSet and choose Tags.
- Add at least one tag with a non-aws: prefixed key.
- Save the changes.