High GuardDuty Regional

GuardDuty Runtime Monitoring should be enabled

FSBP

Description

Verifies that GuardDuty Runtime Monitoring is enabled across all accounts, providing OS-level, network, and file event analysis to detect threats in AWS workloads.


Remediation

To enable GuardDuty Runtime Monitoring, you need to configure the Runtime Monitoring settings in GuardDuty.

Steps

  1. Navigate to the Amazon GuardDuty console
  2. Go to 'Settings' in the left navigation
  3. Select 'Runtime Monitoring'
  4. Enable 'Runtime Monitoring'
  5. Configure security agents for your workloads
  6. Set up monitoring for EKS clusters and EC2 instances
  7. Save the configuration
  8. Verify that Runtime Monitoring is active

Compliance

FSBP