AWS Security Hub monitors your environment using automated security checks based on AWS best practices and industry standards, so that you can take corrective action on findings. AWS Audit Manager imports Security Hub findings for supported compliance standards, such as the CIS Foundations Benchmark and PCI. AWS Audit Manager automatically performs additional analysis and adds annotations to the collected Security Hub findings to generate evidence for the AWS services that are monitored by AWS Security Hub
AWS CloudTrail allows you to log, continuously monitor, and retain account activity related to actions across your AWS infrastructure. Audit Manager collect log data from CloudTrail directly and performs additional analysis. Audit Manager annotates the data to generate evidence automatically for over 175 AWS services that feed logs into AWS CloudTrail.
AWS Config continuously monitors and records your AWS resource configurations and allows you to automate the evaluation of recorded configurations against desired configurations. AWS Audit Manager collects log data from AWS Config and performs additional analysis. Audit Manager annotates that data to generate evidence automatically for the AWS services that are monitored by AWS Config.
AWS Control Tower provides the easiest way to set up and govern a new, secure, multi-account AWS environment based on best practices established through AWS’ experience working with thousands of enterprises as they move to the cloud. AWS Audit Manager imports guardrail logs from Control Tower, and performs additional analysis. Audit Manager annotates that data to generate evidence automatically for the AWS services that are tracked by Control Tower guardrail logs.
Amazon EventBridge is a serverless service that uses events to connect application components together, making it easier for you to build scalable event-driven applications. You can use EventBridge rules to detect and react to Audit Manager events such as state change notifications whenever an assessment is created, edited, or deleted. You can also use EventBridge rules to detect changes to any delegation workflow or assessment control review status.
Amazon Bedrock is a fully managed service that makes foundation models (FMs) from Amazon and other leading AI companies available through an API, enabling you to privately tune existing large language models (LLMs) with your organization data. AWS Audit Manager provides a generative AI best practices framework for Amazon Bedrock customers. You can deploy this best practices framework via AWS Audit Manager in the accounts where you are running your generative AI models and applications, to collect evidence that will help monitor compliance with intended policies.