Implementing continuous compliance

Okay; as we have understood what is possible, let's see it all in action and create our own custom Config rule. Our example organization has an internal policy that states that every production server must be backed up daily. Being awesome AWS engineers, we are using the AWS Backups service and have created a backup plan that takes a daily snapshot of Elastic Block Store (EBS) volumes that have been assigned to the plan. The backup plan looks for a resource tag called Backup with the value of Daily and automatically adds those to the plan:

AWS Config triggering remediation action on non-compliant resource ...

Get Learn AWS Serverless Computing now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.