Manage compliance packages

Updated at:

A compliance package contains the rules that Cloud Config uses to check the compliance of your resources. You can perform the following operations on compliance packages:

Note

Member accounts in an account group view cannot modify, delete, or import compliance packages, and can copy a compliance package only to the current account.

Modify a compliance package

You can modify the basic information and effective scope of a compliance package, add or remove rules in the package, or change the parameters of its rules.

  • Log on to the Cloud Config console.

  • Optional. In the upper-left corner, select an account group.

    This operation is required only if you are using a management account of a resource directory. Otherwise, you do not need to perform the operation.

  • In the left-side navigation pane, choose Compliance & Audit > Compliance Package.

    1. Log on to the Cloud Config console.

    2. (Optional) In the upper-left corner, select an account group.

      This operation is required only if you are using a management account of Resource Directory.

    3. In the left-side navigation pane, choose Compliance & Audit > Compliance Package.

    4. On the Compliance Packages page, find the compliance package that you want to modify and click Modify in the Actions column.

      Note

      Modify is unavailable while the compliance package is in the Creating state. Member accounts in an account group view cannot modify compliance packages.

    5. On the Set Basic Properties page, modify the basic information and effective scope of the compliance package, and then click Next.

    6. On the Select Rules page, add or delete rules, and then click Next.

    7. On the Set Rule Parameters page, set parameters for the rules, and then click OK.

    Result

    After you submit the modification, the Compliance Package Status changes to Applying. You can view the detection results by rule, resource, and member. The Member Detection Results tab is displayed only in multi-account mode.

    Copy a compliance package

    In multi-account scenarios, the management account or the Cloud Config delegated administrator can copy a compliance package from one account group (account group A) to another account group (account group B).

    Prerequisites

    To copy a compliance package between account groups, make sure that the following requirements are met:

    1. Log on to the Cloud Config console.

    2. In the upper-left corner, select account group A, which contains the compliance package that you want to copy.

    3. In the left-side navigation pane, choose Compliance & Audit > Compliance Package.

    4. On the Compliance Package page, click the ID of the compliance package that you want to copy, or click the More icon icon in the Actions column and then select Copy.

      Note

      A member account in an account group view can copy a compliance package only to the current account.

    5. In the Copy Compliance Package dialog box, select account group B to which you want to copy the compliance package, and then click OK.

    6. View the copied compliance package in account group B.

      In the upper-left corner, select account group B. On the Compliance Packages page, you can view the compliance package copied from account group A and its evaluation results.

    Export and import compliance packages

    You can export a compliance package as a template file, and import a template file to create a compliance package. This allows you to reuse compliance package configurations across environments.

    Note

    Exporting a compliance package produces a reusable template file in .json format. To download the evaluation results of a compliance package as an Excel file, see Download the compliance evaluation report of a compliance package.

    Export a compliance package

  • Log on to the Cloud Config console.

  • Optional. In the upper-left corner, select an account group.

    This operation is required only if you are using a management account of a resource directory. Otherwise, you do not need to perform the operation.

  • In the left-side navigation pane, choose Compliance & Audit > Compliance Package.

    1. Log on to the Cloud Config console.

    2. (Optional) In the upper-left corner, select an account group.

      This operation is required only if you are using a management account of Resource Directory.

    3. In the left-side navigation pane, choose Compliance & Audit > Compliance Package.

    4. On the Compliance Packages page, find the compliance package that you want to export and click Export in the Actions column.

    Result

    The browser downloads the compliance package as a template file named CompliancePackageName.json.

    Import a compliance package

  • Log on to the Cloud Config console.

  • Optional. In the upper-left corner, select an account group.

    This operation is required only if you are using a management account of a resource directory. Otherwise, you do not need to perform the operation.

  • In the left-side navigation pane, choose Compliance & Audit > Compliance Package.

    1. Log on to the Cloud Config console.

    2. (Optional) In the upper-left corner, select an account group.

      This operation is required only if you are using a management account of Resource Directory.

    3. In the left-side navigation pane, choose Compliance & Audit > Compliance Package.

    4. On the Compliance Packages page, click Import Compliance Package.

      Note

      Import Compliance Package is unavailable to member accounts in an account group view.

    5. In the dialog box, click Upload File and select a text file whose name ends with .json or .txt and whose size is less than 1 MB. You can upload only one file at a time.

    Result

    After the import succeeds, the console automatically opens the details page of the new compliance package.

    Download the compliance evaluation report of a compliance package

    You can download the evaluation results of a compliance package to your computer to assign remediation tasks offline and track the modification of resource configurations.

  • Log on to the Cloud Config console.

  • Optional. In the upper-left corner, select an account group.

    This operation is required only if you are using a management account of a resource directory. Otherwise, you do not need to perform the operation.

  • In the left-side navigation pane, choose Compliance & Audit > Compliance Package.

    1. Log on to the Cloud Config console.

    2. (Optional) In the upper-left corner, select an account group.

      This operation is required only if you are using a management account of Resource Directory.

    3. In the left-side navigation pane, choose Compliance & Audit > Compliance Package.

    4. On the Compliance Package page, click the ID of the compliance package whose compliance evaluation report you want to download.

    5. In the upper-right corner, click Download Report.

      Note

      If the download feature is upgraded in your environment, the Download Feature Upgrade dialog box appears first. Click Continue Download to proceed with the download, or click Go to Compliance Reports to use the new compliance reports page in a new tab.

    6. In the Download Compliance Report dialog box, click OK.

    Result

    In single-account mode, you receive one evaluation report in Excel format. In multi-account mode, you receive the evaluation reports of all members in the account group. The Excel report of each member is named in the MemberID_MemberName format.

    Delete a compliance package

    If you no longer need a compliance package to check resources, you can delete it. After a compliance package is deleted, all rules in the package and their evaluation results are automatically deleted.

  • Log on to the Cloud Config console.

  • Optional. In the upper-left corner, select an account group.

    This operation is required only if you are using a management account of a resource directory. Otherwise, you do not need to perform the operation.

  • In the left-side navigation pane, choose Compliance & Audit > Compliance Package.

    1. Log on to the Cloud Config console.

    2. (Optional) In the upper-left corner, select an account group.

      This operation is required only if you are using a management account of Resource Directory.

    3. In the left-side navigation pane, choose Compliance & Audit > Compliance Package.

    4. On the Compliance Packages page, find the compliance package that you want to delete, click the More icon icon in the Actions column, and then select Delete.

      Note

      Member accounts in an account group view cannot delete compliance packages.

    5. In the Delete Compliance Package dialog box, click OK.

    6. View the compliance evaluation results.

      On the Compliance Package page, click the target compliance package's ID, or click Details in the Actions column for the package.

      • On the Rule Result tab, view the number of non-compliant resources by rule. You can also perform the following operations on the rules in the compliance package:

        • Click Edit or Delete in the Actions column for a rule to modify or delete it from the current compliance package and the Rules list.

        • Click Remove in the Actions column for a rule to remove it from the current compliance package.

      • On the Resource Result tab, view a list of non-compliant resources. You can also perform the following operations:

    Result

    The compliance package no longer appears on the Compliance Packages page.