Deprecation of the stax-audit-bus EventBridge rule
The stax-audit-bus EventBridge rule has been deprecated and will be removed from all Stax-managed AWS accounts on 31 March 2023. To understand the impact, read more.
The stax-audit-bus EventBridge rule has been deprecated and will be removed from all Stax-managed AWS accounts on 31 March 2023. To understand the impact, read more.
An update has been applied to the Stax Identity Service to improve its performance and reliability.
This update upgrades the Stax Identity Service Database's underlying software. This modernises and standardises the infrastructure in use across all of Stax's customers.
These changes have been applied automatically by Stax during the advertised maintenance window. There is no impact to service expected as a result of this upgrade. Should you experience any issues, please raise a support case.
To ensure you receive notice of upcoming changes to Stax, make sure you're subscribed to the status page.
As part of the release of Stax-managed Security Hub a new rule, Security Hub should be enabled for all regions in an account, has been added to the Stax Foundation Compliance Rule Bundle to help you follow recommended best practices.
This compliance score is displayed on the Accounts page. If you've noticed a drop in this score, this may indicate that AWS Security Hub is not configured in that account.
To easily remediate this, configure Stax-managed Security Hub to enable the service across all accounts and supported regions.
The Rules SQS queues have a dead letter queue, and SQS queues should have a dead-letter queue (DLQ), have been updated to ignore queues with a Redrive Access Policy. This change means that DLQs that have been configured with a Redrive Access Policy will be ignored and will no longer be evaluated as part of this rule.
To add this rule to your Organization Rule Bundle, head to the Rules Catalog page.
Stax has released Stax-managed Security Hub which gives you the ability to configure AWS Security Hub and its prepackaged standards for all accounts in your AWS Organization within all supported regions.
See Using Stax-managed Security Hub for details on how to enable it.
The Rule EC2 instances have IAM instance profiles in the EC2 Best Practice Rule Bundle (version 1.0) has been updated to ignore persisting recently terminated instances.
To add this rule to you Organization Rule Bundle, head to the Rules Catalog page.
A Stax-generated Event is created when an account is closed within Stax. The event schema can be found here. For more information about Stax-generated Events, please read the documentation.
The Rule RDS instances should not be in public subnets in the RDS Best Practice Rule Bundle (version 1.0) has been renamed to RDS instances in a subnet should not have internet access to improve usability and clarity.
To add this rule to your Organization Rule Bundle, head to the Rules Catalog page.
A fix has been applied to the UserAuthenticationEvent Stax generated event to conform to the schema.
The value has changed from "status": "Success" to "status": "SUCCESS".
For further information on Stax generated events, please see Stax Generated Events Schema.
The Stax Foundation Compliance Rule Bundle is a collection of AWS Well-Architected, CIS AWS Foundations Benchmark and Stax best-practice security controls, which helps you to track the safety and security of your accounts. It helps you to assess the compliance of your AWS accounts against enterprise-grade security controls that are applied to Stax-managed resources by default.
For organizations whose AWS accounts are Stax-managed, this Rule Bundle is already enabled. For organizations who are subscribed only to the Cost & Compliance module, head to the Rules Bundle page within the Stax Console to active the Stax Foundation Compliance Rule Bundle.