TrustRadius: an HG Insights company

AWS Config

Score7 out of 10

29 Reviews and Ratings

What is AWS Config?

Amazon Web Services offers AWS Config, a service that provides monitoring and assessment of AWS resource configurations to support compliance auditing, change management and troubleshooting, with resource histories and comparison of historical configurations against planned configurations.

If you have AWS workload, definitely use AWS config for compliance monitoring

Pros

  • Great to track config changes and helpful for troubleshooting.
  • Great for compliance questions you might get.

Cons

  • It's only AWS, no third party.
  • Not the most intuitive interface, but with a little getting used to it is OK.

Most Important Features

  • Auditability
  • Troubleshooting: who did what when.

Return on Investment

  • Alerting on changes can be setup so issues can be solved quickly.

AWS Config - Enforce, Evaluate, Remediate

Pros

  • The ability to track changes in AWS is paramount, AWS config allows you to do this
  • Allows the auditing of an AWS account
  • Can view history of an account that has AWS config enabled

Cons

  • Vendor [lock-in] as this is only available on AWS
  • [The] interface is dated and is [in] need of updating by AWS
  • Graphing is [...] not the easiest to configure

Most Important Features

  • Rule enforcement
  • Auto remediation
  • Reporting

Return on Investment

  • Enforcing audit requirements
  • Easy to set up alerting when there are rule breaches
  • Auto remediation reduces the manual policing of such breaches

Other Software Used

Terraform, by HashiCorp, AWS CloudTrail, AWS CloudFormation

AWS Config is perfect for cloud governance

Pros

  • A detailed view of the resources associated within the account
  • How resources are configured
  • Enables us to assess, audit, and evaluate the configurations of our AWS resources

Cons

  • Sometime the app is slow
  • Cost is factor when there are multiple accounts associated

Most Important Features

  • Its easy to use and easy to see compliant and non-compliant resources
  • Rules and sending audit report

Return on Investment

  • Cost if there are multiple accounts

Other Software Used

Cloudera Distribution Hadoop (CDH), SAS Visual Analytics, Snowflake, Talend Cloud Integration, Amazon Elastic Compute Cloud (EC2)

AWS Config is the only one you need for your AWS infrastructure monitoring

Pros

  • Track many AWS server configuration
  • Faster and easier audit process of your AWS services configuration
  • Keeping history of changes means its easy to spot any issues that occur whenever any changes happened

Cons

  • The interface is not really user friendly and the configuration option is not easy to use either
  • Only available for resources within AWS
  • Some service can be quite costly, we need to prioritise which service that we would apply AWS config to and leave the less important service without AWS config monitoring

Return on Investment

  • A "Big Fish" company that is more concerned about the security of their data came aboard with us more easily since they trust us with the AWS config setup
  • Less time to debug or finding out issue on infrastructure whenever it happens
  • Easy and fast to roll back whenever changes that caused issues happen

Alternatives Considered

PaperTrail

Other Software Used

SolarWinds Papertrail

AWS Config for all governance and audit needs

Pros

  • It can help you define rules for provisioning and configuring of your AWS. We use it for this purpose.
  • It maintains configuration history. So you can use the AWS Management Console, API, or CLI to obtain details of past configurations
  • It gives you a configuration snapshot of all of your AWS resources and you can store it in AWS S3.
  • You can integrate it with AWS CloudTrail to correlate configuration changes to particular events in your account.

Cons

  • Dashboarding and graphs should be better and more configurable.
  • Some time the Config Rules are difficult to understand and configure. They could be made easy or have GUI to configure them. I know it is difficult to build but that would be a good win.

Return on Investment

  • A positive is that every organization using a Cloud like AWS needs a feature like AWS Config for managing governance and audit controls.
  • You can assess your overall compliance and risk status from a configuration perspective using pre-built rules. This is very useful for network and cloud management teams.

Other Software Used

AWS Lambda, AWS CodePipeline, Splunk Enterprise