{"repo":"awslabs/security-hub-compliance-analyzer","free":true,"listed":false,"github":"https://github.com/awslabs/security-hub-compliance-analyzer","clone":"git clone https://github.com/awslabs/security-hub-compliance-analyzer.git","description":"A compliance analysis tool which enables organizations to more quickly articulate their compliance posture and also generate supporting evidence artifacts","language":"Python","stars":60,"topics":["analysis","automation","aws","compliance","config","nist800-53","securityhub"],"license":"Apache-2.0","category":"workflow-automation","readme_excerpt":"Security Hub Compliance Analyzer CDK (Python) Project Description Security Hub Compliance Analyzer (SHCA) generates artifacts in support of Department of Defense Risk Management Framework (RMF) Information System accreditation. Utilizing Amazon Web Services provided documentation, mapping NIST800-53-Rev-5 Controls to AWS Security Hub Security Control IDs, SHCA requests the current environment compliance from Security Hub and generates a zip file stored in Amazon S3 containing discrete artifacts in CSV, JSON, OCSF providing SecOps with artifacts to import into the RMF tool. Requirements Security Hub with and the NIST Special Publication 800-53 Revision 5 Security Standard and running for at least 24 hours to produce results For more information on enabling this standard visit Enabling and disabling security standards ) Security Hub Compliance Analyzer Diagram AWS Step Functions, State Machine Graph 1-config-rules-scrape (AWS Security Hub Findings Extraction) All findings within Security Hub are extracted and saved in JSON. 2-parse-nist-controls (AWS Security Hub Findings Condense and Convert) The most recent finding from each control/resource id in the JSON is written to a CSV file for better analysis and readability. The CSV includes a reason code column extracted from the ASFF Compliance.StatusReasons[0].ReasonCode field, which is used downstream to identify services with no applicable resources ( CONFIG EVALUATIONS EMPTY ). 3-create-summary (AWS Security Hub Summary) A summ","default_branch":null,"files":null,"tree":[],"storefront":"/r/awslabs","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/awslabs/security-hub-compliance-analyzer/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}