Template update records

Updated at:

This topic records metadata changes to Cloud Config managed rules and compliance packages, including new managed rules, adjusted managed rules, and compliance package updates. This topic is continuously updated and retains only the changes from the last month.

2026-08-12

Type

Identifier

Description

Adjusted managed rule

rds-instance-sql-collector-retention

The compliance evaluation for the retention period is relaxed. Previously, a SQL audit log retention period less than or equal to the specified minimum was evaluated as non-compliant. Now, only a retention period less than the specified minimum is evaluated as non-compliant. This means that a retention period that equals the minimum (180 days by default) is considered compliant.

Adjusted managed rule

redis-instance-audit-log-retention

The audit log retention period is now uniformly retrieved from Database Autonomy Service (DAS) for evaluation, because the Redis audit log feature is upgraded to a new version. The previous multi-path evaluation logic is simplified accordingly. Instances of versions that do not support audit logs are evaluated as not applicable.

Adjusted managed rule

use-ddos-instance-for-security-protection

The rule name and description are changed from "Use DDoS protection" to "Use Anti-DDoS Pro or Premium instances" to more accurately indicate that the rule checks whether an account has enabled Anti-DDoS Pro or Premium instances to defend against attacks.

2026-08-06

Type

Identifier

Description

New managed rule

root-ak-check-v2

An Alibaba Cloud account is considered compliant if it has no unused AccessKey pairs, no AccessKey pairs that were not used recently, and no AccessKey pairs that were used recently. The account is considered non-compliant if any of the preceding AccessKey pair risks exist. If the RAM governance report cannot be obtained, the evaluation result is insufficient data.

New managed rule

sae-application-enabled-security-protection

A running SAE application is considered compliant if all its instances are connected to Security Center and the protection clients are online. The application is considered non-compliant if it is not connected to Security Center or the protection client of any instance is offline. Applications that are not in the running state and applications whose instance specification is 0.5 vCPU or less are evaluated as not applicable.

Adjusted managed rule

apig-consumer-apikey-kms-reference

The remediation guide link of the rule is updated to point to a more relevant official topic.

Adjusted managed rule

apig-consumer-idle-check

The remediation guide link of the rule is updated to point to a more relevant official topic.

Adjusted managed rule

apig-domain-force-https-enabled

The remediation guide link of the rule is updated to point to a more relevant official topic.

Adjusted managed rule

apig-domain-https-enabled

The remediation guide link of the rule is updated to point to a more relevant official topic.

Adjusted managed rule

apig-gateway-ip-acl-enabled

The remediation guide link of the rule is updated to point to a more relevant official topic.

Adjusted managed rule

apig-gateway-waf-enabled

The remediation guide link of the rule is updated to point to a more relevant official topic.

2026-08-03

Type

Identifier

Description

New managed rule

apig-gateway-custom-domain-enabled

An AI gateway instance is considered compliant if at least one custom domain name is associated with it, and non-compliant if no custom domain name is associated. Instances that are not AI gateway instances are evaluated as not applicable.

New managed rule

apig-gateway-ip-acl-not-allow-all

An AI gateway instance is considered compliant if an IP access control policy is configured for it and the policy does not contain 0.0.0.0/0. The instance is considered non-compliant if no IP access control policy is configured or the policy contains 0.0.0.0/0. Instances that are not AI gateway instances are evaluated as not applicable.

2026-07-27

Type

Identifier

Description

New managed rule

ecs-snapshot-idle-check

A snapshot is considered compliant if its source disk still exists, and non-compliant if the source disk has been released or the snapshot is not associated with a source disk.

New managed rule

hbr-vault-backup-job-status-check

A Cloud Backup vault is considered compliant if it has no backup jobs in the "Partially Completed" or "Failed" state, and non-compliant if such jobs exist.

Compliance package update

ct-484cff4e06a300621b62

The following rule is added to the compliance package: idle disk snapshot detection (ecs-snapshot-idle-check).

Compliance package update

ct-484cff4e06a300621b9d

The following rule is added to the compliance package: idle disk snapshot detection (ecs-snapshot-idle-check).

2026-07-23

Type

Identifier

Description

New managed rule

sas-log-analysis-enabled

The configuration is considered compliant if the log analysis feature is enabled for any log type in Security Center.

2026-07-17

Type

Identifier

Description

Adjusted managed rule

ack-cluster-supported-version

The list of supported Kubernetes versions is updated. Versions 1.28, 1.30, 1.31, 1.32, and 1.33 are added to prevent new versions from being flagged as non-compliant by mistake.

New managed rule

apig-consumer-apikey-kms-reference

A consumer is considered compliant if its API key uses the KMS key reference mode, which supports periodic automatic rotation, and non-compliant if the API key is system-generated.

New managed rule

apig-consumer-idle-check

A consumer is considered compliant if it is granted access to at least one API, and non-compliant if it is not granted access to any API.

New managed rule

apig-domain-force-https-enabled

A domain is considered compliant if HTTPS redirect is enabled, and non-compliant if it is not enabled.

New managed rule

apig-domain-https-enabled

A domain is considered compliant if the HTTPS protocol (transport encryption) is configured, and non-compliant if it is not configured.

2026-07-16

Type

Identifier

Description

Adjusted managed rule

ecs-instance-image-type-check

The image source parameter is changed from single-value exact match to multi-value support. For example, both system and self can be allowed at the same time, separated by commas (,).

Adjusted managed rule

resources-tags-not-casesensitive-whitespace

Message Queue for Apache AMQP instances are added to the applicable resource types to expand the coverage of tag compliance checks.

2026-07-13

Type

Identifier

Description

Adjusted managed rule

redis-instance-tls-version-check

A "Not applicable" determination is added: single-replica instances and disk-based instances are not applicable to this check, which avoids false positives for instance types that do not support TLS.

2026-07-09

Type

Identifier

Description

Adjusted managed rule

mse-cluster-stable-version-check

The detection logic is changed from comparison against a fixed version threshold to referencing the version risk items in the MSE health check result (engine version too low, client version risk, or engine version at risk). This check applies only to Professional Edition instances.