# P12 AWS Config governance and remediation workbook

Use with AWS238. This is a no-create architecture and supplied-evidence exercise.

## 1. Governance outcome and ownership

- Control objective and business/regulatory mapping:
- Control owner and technical owner:
- Resource/application owner:
- Management/delegated administrator account:
- Aggregator account and Region:
- In-scope organization units/accounts/Regions:
- Explicit exclusions, owner, reason and expiry:
- Evidence retention and audit owner:
- Monthly Config, S3, SNS, Lambda and SSM budget:

## 2. Recording coverage matrix

| Account/OU | Region | Recorder type/status | Recording strategy/frequency | Required resource types | Global-resource home/duplicate decision | Delivery channel/status | Last CI UTC |
|---|---|---|---|---|---|---|---|
|  |  | customer/service-linked |  |  |  |  |  |

An aggregator does not enable a source recorder. A missing or stopped recorder can
produce a quiet dashboard rather than compliant resources.

## 3. Aggregation coverage

| Source account/organization | Source Regions | Individual authorization or Organizations role | Last updated | Failed/missing sources | Correction owner |
|---|---|---|---|---|---|
|  |  |  |  |  |  |

- All organization features/service access verified:
- Organization role/delegated admin valid:
- Aggregator is read-only; deployment path documented separately:
- Aggregation delay and freshness acceptance:
- Advanced-query limitation or direct-account evidence required:

## 4. Conformance pack design

| Control/rule | Managed/custom/process | Detective/proactive | Trigger | Scope | Parameters | Failure/NOT_APPLICABLE semantics | Owner |
|---|---|---|---|---|---|---|---|
| storage encryption |  |  |  |  |  |  |  |
| public access blocked |  |  |  |  |  |  |  |
| required tags |  |  |  |  |  |  |  |

- Template repository/version/hash:
- Rule identifier versus generated deployed rule name:
- Custom Lambda/Guard prerequisites and deployment order:
- Sample pack reviewed against actual legal/business requirements:
- Parameter defaults rejected or approved:
- Organization excluded-account behavior:
- Deployment status and failed-account evidence:

## 5. Compliance evidence

| Pack/rule | Resource | Result | Ordering timestamp | CI capture/status | Annotation | Score impact | Owner/action |
|---|---|---|---|---|---|---|---|
|  |  | COMPLIANT/NON_COMPLIANT/ERROR/NOT_APPLICABLE |  |  |  |  |  |

- Compliance score and `LastUpdatedTime`:
- Total compliant/possible rule-resource combinations:
- Rules/resources with `INSUFFICIENT_DATA`:
- Recorder and aggregator freshness proved:
- Direct source-account evidence sampled:
- Business compliance evidence beyond Config:

## 6. Remediation safety review

| Rule | Manual/auto | SSM document/version | Resource-ID parameter | Static parameters | AutomationAssumeRole | Max attempts/window | Concurrency/error % | Idempotency/precondition |
|---|---|---|---|---|---|---|---|---|
|  | manual first |  |  |  |  |  |  |  |

- Exact mutation and blast radius:
- Backup and rollback:
- Dry/manual execution in sandbox:
- Successful, no-op, stale-input, retry and rollback tests:
- Alarm/EventBridge/CloudTrail/SSM evidence:
- Canary accounts/Regions and observation period:
- Auto-remediation approval:
- Kill switch/change freeze:

Automatic remediation can run from a stale compliance snapshot. The Automation
must re-read current resource state and exit safely when already compliant.

## 7. Remediation exceptions

| Rule/resource | Created automatically or approved | Failure/reason | Expiration | Blocks auto-remediation | Owner | Clear/re-evaluate/retry evidence |
|---|---|---|---|---|---|---|
|  |  |  |  | yes |  |  |

Place planned exceptions only after the resource evaluates `NON_COMPLIANT` and
while remediation is manual. Service-linked remediation may not support exceptions.

## 8. Troubleshooting timeline

| UTC time | Account/Region | Recorder/CI | Evaluation | Remediation step | Error/event | Interpretation |
|---|---|---|---|---|---|---|
|  |  |  |  |  |  |  |

- First divergent layer:
- Root cause:
- Corrective change and rollback:
- Re-evaluation ID/time and new CI:
- Aggregated result/time:
- Remaining exception and risk:

## 9. Cost and no-create evidence

- Configuration items by recording frequency/resource churn:
- Standalone detective/proactive rule evaluations:
- Conformance-pack rule-resource evaluations:
- Lambda/Guard, SSM Automation, S3/SNS/KMS/log costs:
- Aggregator additional charge (currently none):
- Before/after recorder, pack, aggregator, rule and remediation inventories:
- Local artifact retained/removed:
