Medium Macie Regional

Amazon Macie should be enabled

NIST 800-53

Description

This control checks whether Amazon Macie is enabled for an account. The control fails if Macie isn't enabled for the account. Amazon Macie discovers sensitive data using machine learning and pattern matching, provides visibility into data security risks, and enables automated protection against those risks. Macie automatically and continually evaluates your Amazon Simple Storage Service (Amazon S3) buckets for security and access control, and generates findings to notify you of potential issues with the security or privacy of your Amazon S3 data. Macie also automates discovery and reporting of sensitive data, such as personally identifiable information (PII), to provide you with a better understanding of the data that you store in Amazon S3.


Remediation

To remediate this issue, you need to enable Amazon Macie for your account.

Steps

  1. Navigate to the Amazon Macie console
  2. Select the appropriate AWS region
  3. Click 'Get started' or 'Enable Macie'
  4. Choose your data discovery preferences
  5. Select the S3 buckets to monitor
  6. Configure findings and notifications
  7. Review and confirm the configuration
  8. Enable Macie for your account
  9. Verify Macie is active and monitoring
  10. Set up automated responses to findings

Compliance

NIST 800-53