High
GuardDuty
Regional
GuardDuty Runtime Monitoring should be enabled
FSBP
Description
Verifies that GuardDuty Runtime Monitoring is enabled across all accounts, providing OS-level, network, and file event analysis to detect threats in AWS workloads.
Remediation
To enable GuardDuty Runtime Monitoring, you need to configure the Runtime Monitoring settings in GuardDuty.
Steps
- Navigate to the Amazon GuardDuty console
- Go to 'Settings' in the left navigation
- Select 'Runtime Monitoring'
- Enable 'Runtime Monitoring'
- Configure security agents for your workloads
- Set up monitoring for EKS clusters and EC2 instances
- Save the configuration
- Verify that Runtime Monitoring is active
Compliance
FSBP