High GuardDuty Regional

GuardDuty Lambda Protection should be enabled

PCI DSS v4.0.1PCI DSS v11.5.1

Description

Verifies that GuardDuty Lambda Protection is enabled across all accounts. Lambda Protection monitors network activity logs for Lambda invocations to identify potential security threats.


Remediation

To enable GuardDuty Lambda Protection, you need to configure the Lambda protection settings in GuardDuty.

Steps

  1. Navigate to the Amazon GuardDuty console
  2. Go to 'Settings' in the left navigation
  3. Select 'Lambda Protection'
  4. Enable 'Lambda Protection'
  5. Configure the protection settings as needed
  6. Save the configuration
  7. Verify that Lambda protection is active

Compliance

PCI DSS v4.0.1PCI DSS v11.5.1