Skip to main content
compliance · aws

AWS accounts where the AWS Config configuration recorder is not recording

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

ZopNight flags an AWS account when its probe finds the AWS Config configuration recorder is not enabled, which you can confirm with `config:DescribeConfigurationRecorderStatus`. Without the recorder, AWS Config keeps no resource change history and Config rules have nothing to evaluate. The check probes `us-east-1` only, so treat a clean result as covering that Region, not every Region you use.

Signal and threshold

How ZopNight evaluates AWS accounts where the AWS Config configuration recorder is not recording.
Field Value
Rule IDsRC-1520
Categorycompliance
Severitymedium
Metricnone — pure configuration read
Thresholdrecorder not recording
SourceZopNight
Permissions usedconfig:DescribeConfigurationRecorders · config:DescribeConfigurationRecorderStatus

What you lose when the recorder is off

AWS Config only knows about resources it records. The configuration recorder captures a configuration item each time a resource or one of its relationships changes, and that history is what audits, incident reviews and every Config rule rely on. When the recorder is stopped or was never set up, questions like “who opened this security group and when” have no answer in Config. AWS Config pricing charges per configuration item delivered per account per Region, and the page’s examples use $0.003 per item, so enabling it does add cost; this rule is about coverage, not savings.

Checking recorder status per Region

recording is the field that matters; lastStatus shows whether the last delivery succeeded:

Terminal window
for r in $(aws ec2 describe-regions --query 'Regions[].RegionName' --output text); do
echo "$r: $(aws configservice describe-configuration-recorder-status --region "$r" \
--query 'ConfigurationRecordersStatus[].[name,recording,lastStatus]' --output text)"
done

An empty result for a Region means no recorder exists there at all.

How ZopNight reaches its verdict

ZopNight keeps one record per account for this check, holding a single yes-or-no answer to “is a recorder enabled”. The rule fires only when that answer is present and says no. If ZopNight cannot list the account’s recorders, no record is written and no finding is raised. If it can list them but cannot read their recording status, for example because config:DescribeConfigurationRecorderStatus is not granted, it treats the recorder as not recording and the finding does fire.

The single-Region limitation

The probe runs against us-east-1 only. An account that records in us-east-1 but not in eu-west-1 will look compliant to this rule, and one that records everywhere except us-east-1 will be flagged. Use the loop above for the full picture across every Region you operate in.

Cost of enabling, value of the record

The finding carries a $0 estimate. Turning the recorder on adds per-item charges that scale with how often your resources change, so noisy Regions cost more to record. Recording only the resource types you need is a reasonable way to limit that.

Turning the recorder on

  1. In the AWS Config console, open Settings and set up the configuration recorder, or call aws configservice put-configuration-recorder with a recording group (allSupported records every supported type).
  2. Create a delivery channel pointing to an S3 bucket for snapshots and history (aws configservice put-delivery-channel); AWS requires one before the recorder can start.
  3. Start recording: aws configservice start-configuration-recorder --configuration-recorder-name default.
  4. Add conformance packs or Config rules for the controls your audits need.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·