Managing your environment with AWS Config
Moving through the Incident Response Domain, you have now come to the next critical service that you need to know about, one that will help show you what has changed after an incident has occurred—AWS Config.
AWS Config and its configuration recorder can help you take a real-time inventory of most of the resources in a single account running in a single region or can be configured to collate data across multiple regions and even multiple accounts.
The service provides an even greater functionality when it comes to security. For organizations that need to maintain a compliance security standard, AWS Config can evaluate your resources instantly or on a fixed schedule and, with the help of Config Rules, determine if they are in or out of compliance. If they are found out of compliance, you can use a combination of Lambda and System Manager to automate remediations to either destroy items that do not meet the compliance standards...