Enable Security Hub

Overview

To enable Security Hub, AWS provides users with a graphical interface to interact with this service. In this step, we will enable Security Hub through this console interface.

Enable Security Hub through Console

To enable Security Hub in a Region, follow these steps:

  1. Log in to the Amazon Management Console. In the search bar, type and search for the Security Hub CSPM service.

Security Hub

  1. On the AWS Security Hub CSPM page, select Go to Security Hub CSPM.

Security Hub

  1. On the Welcome to AWS Security Hub page, select the Security standards such as AWS Foundational Security Best Practices, CIS AWS Foundations Benchmark, and PCI DSS.

Security Hub

  1. Select Enable Security Hub CSPM.

Security Hub

  1. After enabling, you will need to wait for some time for Security Hub to evaluate the Security Score of your current account against each security standard you configured.

Security Hub

  1. Select the Control section to view the Security Score

Security Hub

In some cases, you will encounter notifications related to AWS Config configuration. Please enable the AWS Config service in the corresponding Region. Most evaluation criteria are based on AWS Config service-level rules. When enabling AWS Config recording, select the option to record all resources in the corresponding Region and global resources.

Configure AWS Config

  1. On the console page, search for and select the AWS Config service

Security Hub

  1. Select Get started

Security Hub

  1. In the Override settings section, select All globally recorded IAM resource type and Exclude from recording

  2. In the Data governance section, select Create AWS Config service-linked role

Security Hub

  1. In the Delivery channel section, select Create a bucket, keep the default bucket name, select Next

Security Hub

  1. Continue to select Next

Security Hub

  1. Select Confirm

Security Hub

  1. Complete the AWS Config setup

Security Hub