Managing Your Environment with AWS Config
Moving through the incident response domain, you have now come to the next critical service that you need to know about, one that helps to show you what has changed after an incident has occurred—AWS Config.
AWS Config and its configuration recorder can help you take a real-time inventory of most of the resources in a single account running in a single Region or can be configured to collate data across multiple Regions and even multiple accounts.
The service provides an even greater functionality when it comes to security. For organizations that need to maintain a compliance security standard, AWS Config can evaluate your resources instantly or on a fixed schedule and, with the help of Config rules, determine whether they are in or out of compliance. If they are found to be out of compliance, you can use a combination of Lambda and System Manager to automate remediations to either destroy items that do not meet the compliance standards...