Skip to main content
resource · aws

AWS Config Rule

live rule families
1
schedulable
no
category
governance-services

Does ZopNight manage AWS Config Rule?

AWS Config rules bill per evaluation: every time a resource in scope changes, every rule watching it charges again. Large rule sets over large estates multiply that arithmetic continuously. ZopNight discovers rules on the 6-hour cycle, attributes evaluation cost from Cost Explorer or CUR 2.0, and flags rules nobody consumes.

At a glance

AWS Config Rule coverage facts.
Field Value
Scheduling notesdiscovery, cost tracking, and recommendations only.

An AWS Config rule evaluates resources against compliance conditions, billed per rule evaluation. Large rule sets over large estates multiply evaluation charges every time resources change.

Evaluations as the unit of spend

A Config rule bills each time it evaluates a resource, with the per-evaluation rate tiering down at volume. Total cost is rules times resources times change frequency, three multiplicands that grow independently. Adding a conformance pack drops dozens of rules onto the estate at once; the estate itself grows; and deployment cadence raises change frequency. The result is a charge that compounds quietly, because each individual evaluation costs a fraction of a cent and nobody ever sees the multiplication written out.

Separating enforced rules from ornamental ones

Rules are discovered via a dedicated provider on the 6-hour cycle, with evaluation cost attributed from Cost Explorer or CUR 2.0. The unused-rule recommendation asks the consumption question: which rules feed a remediation action, a compliance dashboard someone reads, or an audit requirement, and which merely evaluate thousands of resources daily for findings that accumulate unread. Rules in the second group are paying compliance prices for no compliance outcome, and either deserve an owner or deserve deletion.

Rule sets that outgrow their purpose

Conformance packs applied wholesale are the main source: an operational-best-practices pack contains rules for services the account does not run, each still evaluating whatever falls in scope. Duplicate coverage accumulates when Security Hub standards and hand-added Config rules check the same conditions in parallel, billing twice for one answer. And custom Lambda-backed rules add a second meter (the Lambda invocations) while being the most likely to be orphaned when their authoring team dissolves.

Auditing the rule inventory

The Config console’s Rules view lists every rule with its compliance summary and trigger type. For each, two questions settle its fate: does anything consume its findings, and does something else already check the same condition. The console’s per-rule evaluation counts, joined with the CUR’s evaluation charges, turn the multiplication into per-rule dollars.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

417 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

417 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·