AWS Config vs. AWS Security Hub

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
AWS Config
Score 7.0 out of 10
N/A
Amazon Web Services offers AWS Config, a service that provides monitoring and assessment of AWS resource configurations to support compliance auditing, change management and troubleshooting, with resource histories and comparison of historical configurations against planned configurations.N/A
AWS Security Hub
Score 9.0 out of 10
N/A
AWS Security Hub gives users a comprehensive view of your high-priority security alerts and security posture across AWS accounts. With Security Hub, users have a single place that aggregates, organizes, and prioritizes security alerts, or findings, from multiple AWS services, such as Amazon GuardDuty, Amazon Inspector, Amazon Macie, AWS Identity and Access Management (IAM) Access Analyzer, and AWS Firewall Manager, as well as from AWS Partner solutions.N/A
Pricing
AWS ConfigAWS Security Hub
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
AWS ConfigAWS Security Hub
Free Trial
NoNo
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
YesNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional DetailsWith AWS Config, you are charged based on the number of configuration items recorded, the number of active AWS Config rule evaluations and the number of conformance pack evaluations in your account. A configuration item is a record of the configuration state of a resource in your AWS account. An AWS Config rule evaluation is a compliance state evaluation of a resource by an AWS Config rule in your AWS account, and a conformance pack evaluation is the evaluation of a resource by an AWS Config rule within the conformance pack.
More Pricing Information
Community Pulse
AWS ConfigAWS Security Hub
Best Alternatives
AWS ConfigAWS Security Hub
Small Businesses
HashiCorp Vagrant
HashiCorp Vagrant
Score 10.0 out of 10

No answers on this topic

Medium-sized Companies
Ansible
Ansible
Score 9.2 out of 10
Palo Alto Networks Prisma Cloud
Palo Alto Networks Prisma Cloud
Score 8.3 out of 10
Enterprises
Ansible
Ansible
Score 9.2 out of 10
AWS Config
AWS Config
Score 7.0 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
AWS ConfigAWS Security Hub
Likelihood to Recommend
8.8
(6 ratings)
9.0
(6 ratings)
Usability
-
(0 ratings)
8.1
(2 ratings)
Performance
9.6
(2 ratings)
-
(0 ratings)
Ease of integration
6.2
(2 ratings)
-
(0 ratings)
User Testimonials
AWS ConfigAWS Security Hub
Likelihood to Recommend
Amazon AWS
It's really good if your infrastructure services is all in AWS, that means everything could be audited and monitored using AWS config. You also can create alarms to notify you or your team about any changes on your AWS resources which is very useful to prevent abuse if you have a fairly large team. It's also very useful whenever some third party wants to audit your AWS resources, if you have a fairly comprehensive AWS config configured, the auditing process will be easy since they only need to look at your AWS config setup.
Read full review
Amazon AWS
I don't think there's yet a perfect tool in this category of security and incident aggregators, but AWS Security Hub is an excellent tool for having visibility into our overall security posture. It is a great aggregator for many AWS services but also for third party security tools with which it integrates really well.
Read full review
Pros
Amazon AWS
  • The ability to track changes in AWS is paramount, AWS config allows you to do this
  • Allows the auditing of an AWS account
  • Can view history of an account that has AWS config enabled
Read full review
Amazon AWS
  • Brings together the security related AWS tools in one dashboard
  • Allows to pick and chose which AWS security tools to use
  • Clean UI
Read full review
Cons
Amazon AWS
  • It's only AWS, no third party.
  • Not the most intuitive interface, but with a little getting used to it is OK.
Read full review
Amazon AWS
  • Not easy to read past data, especially once it moves into Glacier deep storage
  • performance is somewhat sluggish ... other systems are much faster to analyze data
  • Doesn't always provide a remediation solution or suggested fix like other 3rd party tools like Qualys.
  • It's hard to get the initial configuration and enrollment completed as there's a lot of manual intervention for every configured rule that needs to be enabled
  • alerts are often times delayed
Read full review
Usability
Amazon AWS
No answers on this topic
Amazon AWS
AWS always good with usability and same here for AWS Security Hub. A lot of good documentation is available to read and configure your own. We also started with looking at the videos and documentation to configure automation for our compliance checks. And to configure there are very less steps to be followed which is a very good thing for faster configuration.
Read full review
Performance
Amazon AWS
Would rate lower for other workloads but for AWS workloads its simple to set up, cost effective and customisable. Primary use case is compliance from a governance perspective.
Read full review
Amazon AWS
No answers on this topic
Alternatives Considered
Amazon AWS
I do not know or have used any other product in AWS cloud space that matches what AWS Config provides. We have some custom built monitoring and governance, however that is there because AWS Config does not provide it currently.
Read full review
Amazon AWS
AWS Security Hub is it's own unique program that I have used. I haven't used anything similar to it and it was worth it to try out. However, for those that want to keep for long, it will be very heavy in term of budget and resource that they have to provide.
Read full review
Return on Investment
Amazon AWS
  • Enforcing audit requirements
  • Easy to set up alerting when there are rule breaches
  • Auto remediation reduces the manual policing of such breaches
Read full review
Amazon AWS
  • The automated compliance test helped us a lot to get PCIDSS certified so it was a very good return for our investments.
  • Some third party tools we were using were not available for AWS Security Hub automated testing.
  • Easy to configure for faster security automations but if we need detailed reports we should add more tools.
Read full review
ScreenShots