Changes to Stax Rule names
A number of Rule names have been updated to improve usability and standardize rule names across all Rule Bundles. To find out more, visit the Stax Compliance module guide.
A number of Rule names have been updated to improve usability and standardize rule names across all Rule Bundles. To find out more, visit the Stax Compliance module guide.
As announced on 04 September 2023, Stax has released a fix for an issue resulting in some out-of-date RI recommendations being collected from AWS member accounts.
Stax has released a change to only show RI recommendations that are less than 30 days old making the current recommendations and savings opportunities more accurate. Customers may notice a decrease in the Total Potential Yearly Saving and a reduction in the number of savings opportunities displayed.
This change does not impact RI recommendations generated by Stax within the AWS management account which are scoped to all accounts in the organization's consolidated billing family. These recommendations cover both the management account and member accounts and are refreshed daily.
Stax Notifications now supports the ability to create multiple of the same notification types for any delivery channel. This change provides greater flexibility and personalization and makes managing your Stax Cost & Compliance notifications much easier. See Manage Notifications for more details.
As of December 31st, AWS will no longer provide support for the Go 1.x runtime in AWS Lambda, as announced in this AWS blog post.
This change will be deployed to all affected Stax-managed Lambda functions before December 31, 2023. No customer action is required for this change and we will inform you when this change has been applied.
For any further questions, please raise a support case.
On 11 September 2023, Stax will be releasing a change to remediate an issue impacting Reserved Instance (RI) recommendations shown within the Reserved Instances tab on the Savings Plans & RIs page. This issue is resulting in some out-of-date RI recommendations being collected from AWS member accounts.
After the change, Stax will only show RI recommendations that are less than 30 days old making the current recommendations and savings opportunities more accurate. Customers may notice a decrease in the Total Potential Yearly Saving and a reduction in the number of savings opportunities displayed.
This change does not impact RI recommendations generated by Stax within the AWS management account which are scoped to all accounts in the organization's consolidated billing family. These recommendations cover both the management account and member accounts and are refreshed daily.
The NIST Cybersecurity Framework Rule Bundle is now available to all organizations. This Bundle is designed to help customers fortify their AWS environment against cyber threats and strengthen their security posture.
The new bundle currently includes 86 controls and over 16 new rules, with more to be added during the preview phase.
Add the Bundle to your Stax console to get started. Once added, Stax will perform an initial evaluation and populate the Rules page with new results. You can filter the page to show only results from the NIST Cybersecurity Framework bundle if preferred. Alternatively, to add any of the new rules to your Organization Rule Bundle, head to the Rules Catalog page.
As part of our ongoing maintenance and improvement of rules and rule bundles, we are updating rules related to AWS CloudTrail log metric filters. This change will offer a shift towards organization-level CloudTrail configurations, enabling enhanced security and manageability for your resources.
Please be aware that the existing rules will be deprecated in the following bundles:
The deprecated rules are as follows:
The newly introduced rules will take their place with the following rule names respectively:
Please note that the check history for the deprecated rules will not be kept.
If you have any questions about this change and what it means for you, please contact support.
OUs can now be managed from within Stax and SCPs can now be attached to OUs and individual accounts. For more information, see the documentation.
As part of the upcoming release to Manage AWS Organizational Units and Service Control Policies in Stax the following changes will be made to the Policies API Policy method's schema implementation. For a detailed outline of these changes, see the release plan here.
Attachableto
is no longer defined in the schemaMandatory
is no longer defined in the schemaPublic
is no longer defined in the schemaPolicy
is now defined as Content
in the schemaStatus
values are now; ACTIVE, CREATE_FAILED, CREATE_IN_PROGRESS, DELETED, DELETE_FAILED, DELETE_IN_PROGRESS, UPDATE_IN_PROGRESS. Previous values; ACTIVE, DELETED, FAILEDAwsId
is now defined in the schemaExternalResource
is now defined in the schemaOrganisationAttachment
is now defined in the schemaPolicyOwner
is now defined in the schemaPolicyType
is now defined in the schemaTags
is now defined in the schemaUserTaskId
is now defined in the schemaThe API documentation for the new Policies schema can be found here, with the release of this feature the Policyv2 schema will be renamed to replace Policy.
If you have questions or concerns regarding the changes, please reach out by raising a support case.
The Australian Cyber Security Centre Essential Eight Rule Bundle is now available to all organizations. This Bundle is designed to help customers fortify their AWS environment against cyber threats and strengthen their security posture.
The new Stax Compliance ACSC Essential Eight Rule Bundle includes 42 controls and 16 new rules.
Add the Bundle to Stax to get going. Once added, Stax will perform an initial evaluation and populate the Rules page with new results. You can filter the page to show only results from the Essential Eight bundle if preferred. Alternatively, to add any of the new rules to your Organization Rule Bundle, head to the Rules Catalog page.