Skip to main content
compliance · aws

AWS Config rules that have never run a single evaluation

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight flags an AWS Config rule whose `FirstEvaluationStarted` flag from `config:DescribeConfigRuleEvaluationStatus` is false, meaning Config has never evaluated any resource against it. Rule evaluations bill at $0.001 each for the first 100,000, so an idle rule costs about nothing; the finding is a $0 compliance item because the control it represents is not actually running.

Signal and threshold

How ZopNight evaluates AWS Config rules that have never run a single evaluation.
Field Value
Rule IDsRC-199
Categorycompliance
Severitylow
Metricnone — pure configuration read
ThresholdFirstEvaluationStarted = false
SourceZopNight
Permissions usedconfig:DescribeConfigRules · config:DescribeConfigRuleEvaluationStatus

A rule that exists but checks nothing

A Config rule in the console looks like a control is in place. Whether it has ever done anything is a separate question, answered by FirstEvaluationStarted, which the CLI reference defines as whether Config has evaluated your resources against the rule at least once. A rule that never started is a silent gap: auditors see it listed, but no resource has ever been marked compliant or non-compliant by it.

Finding rules that never evaluated

Terminal window
aws configservice describe-config-rule-evaluation-status \
--query 'ConfigRulesEvaluationStatus[?FirstEvaluationStarted==`false`].[ConfigRuleName,FirstActivatedTime,LastErrorCode]' \
--output table

Then look at the rule’s scope to see what it is supposed to target:

Terminal window
aws configservice describe-config-rules --config-rule-names RULE_NAME \
--query 'ConfigRules[].[ConfigRuleName,ConfigRuleState,Scope]'

When a never-evaluated rule is reported

ZopNight combines the rule list with each rule’s evaluation status and marks a rule as unused when its first evaluation has not started. The finding appears only when that mark is present and true. If the evaluation status could not be read for a rule, it is left out.

When ZopNight does not report the rule

A rule that has evaluated at least once is never flagged here, even if it now reports zero resources. Rules whose evaluations fail with errors after a first run are also out of scope; check LastErrorCode and LastErrorMessage in the same output for those.

Why the finding is priced at $0

AWS Config pricing bills per rule evaluation, and its examples price the first 100,000 evaluations at $0.001 each. A rule with no evaluations has cost essentially nothing, so ZopNight does not present deletion as a saving. The finding is filed as compliance because a control that never runs is worse than no control: it gives false assurance.

Repairing or removing the rule

  1. Review the rule’s scope and resource type filter; a filter for a type or tag that no resource in this account and Region has is the usual cause.
  2. Confirm the configuration recorder is recording the resource types the rule targets. See AWS Config Recorder Not Enabled.
  3. Fix the scope and trigger an evaluation with aws configservice start-config-rules-evaluation --config-rule-names RULE_NAME.
  4. Delete the rule if the resource type is not used in this account.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·