prowler-cloud/prowler

Environment-Specific Log Group Retention Policy Validation

開放

#6,240 建立於 2024年12月18日

 (1 則留言) (0 個反應) (0 位負責人)Python (1,322 個分叉)batch import
feature-requesthelp wanted

倉庫指標

星標
 (8,957 顆星)
PR 合併指標
 (PR 指標待抓取)

描述

New feature motivation

When scanning multiple accounts, we often have environment-specific log group retention policies:

Sandbox: 7 days Staging: 30 days Production: 365 days Currently, these policies may be flagged as non-compliant unless explicitly configured for each environment. For example, a Sandbox log group with a retention policy of exactly 7 days should pass the compliance check, while any configuration below 7 days should be flagged as non-compliant. Similarly, Staging and Production environments should align with their respective policies. Introduce functionality to allow environment-specific log group retention policies to be validated dynamically based on predefined rules.

Expected Behavior:

Ability to define retention policies per environment (e.g., Sandbox, Staging, Production). Ensure that compliance checks only flag log groups as non-compliant when their configuration deviates from the defined environment-specific rules. Support for handling multiple accounts and environments seamlessly.

Solution Proposed

Add a configuration file or parameter to specify retention rules for each environment. Update compliance logic to check against these rules during scans. Provide detailed output for any non-compliance based on environment-specific thresholds

Describe alternatives you've considered

This feature would be useful for organizations managing multiple cloud accounts with distinct compliance requirements for different environments. It ensures accurate reporting without false positives and better adherence to organizational policies.

Additional context

No response

貢獻者指南