Low GuardDuty Regional

GuardDuty IPSets should be tagged

Description

Flags Amazon GuardDuty IPSets that have no user-defined tags. Tags help associate IPSets with their owning team and threat intelligence feed lineage; untagged IPSets are operationally opaque.


Remediation

Apply at least one user-defined tag to every GuardDuty IPSet.

Steps

  1. Open the Amazon GuardDuty console and choose Lists, then Trusted IP lists / Threat lists.
  2. Select the affected IPSet and choose Tags.
  3. Add at least one tag with a non-aws: prefixed key.
  4. Save the changes.