To configure Amazon Inspector, we need to create a number of components within the Amazon Inspector service, starting with the assessment target. An assessment target is a grouping of AWS EC2 instances that you want to run an assessment against. This grouping is defined and managed by the tags associated with your EC2 instances within your environment:
- From within the AWS Management Console, select the Amazon Inspector service found in the Security, Identity, & Compliance category.
- Select Assessment targets in the left menu:
- Select the blue Create button, and this will display the following options:
From here, you create the assessment targets:
-
- Enter a name for your assessment target.
- If you want to include all of your EC2 instances in your AWS account and your current region, then you can tick the appropriate box to do so.
- Using the drop-down lists for the Key and Value options, select the tags that you have configured for your EC2 instances...