Template update records
This topic records metadata changes to Cloud Config managed rules and compliance packages, including new managed rules, adjusted managed rules, and compliance package updates. This topic is continuously updated and retains only the changes from the last month.
2026-08-12
|
Type |
Identifier |
Description |
|
Adjusted managed rule |
|
The compliance evaluation for the retention period is relaxed. Previously, a SQL audit log retention period less than or equal to the specified minimum was evaluated as non-compliant. Now, only a retention period less than the specified minimum is evaluated as non-compliant. This means that a retention period that equals the minimum (180 days by default) is considered compliant. |
|
Adjusted managed rule |
|
The audit log retention period is now uniformly retrieved from Database Autonomy Service (DAS) for evaluation, because the Redis audit log feature is upgraded to a new version. The previous multi-path evaluation logic is simplified accordingly. Instances of versions that do not support audit logs are evaluated as not applicable. |
|
Adjusted managed rule |
|
The rule name and description are changed from "Use DDoS protection" to "Use Anti-DDoS Pro or Premium instances" to more accurately indicate that the rule checks whether an account has enabled Anti-DDoS Pro or Premium instances to defend against attacks. |
2026-08-06
|
Type |
Identifier |
Description |
|
New managed rule |
|
An Alibaba Cloud account is considered compliant if it has no unused AccessKey pairs, no AccessKey pairs that were not used recently, and no AccessKey pairs that were used recently. The account is considered non-compliant if any of the preceding AccessKey pair risks exist. If the RAM governance report cannot be obtained, the evaluation result is insufficient data. |
|
New managed rule |
|
A running SAE application is considered compliant if all its instances are connected to Security Center and the protection clients are online. The application is considered non-compliant if it is not connected to Security Center or the protection client of any instance is offline. Applications that are not in the running state and applications whose instance specification is 0.5 vCPU or less are evaluated as not applicable. |
|
Adjusted managed rule |
|
The remediation guide link of the rule is updated to point to a more relevant official topic. |
|
Adjusted managed rule |
|
The remediation guide link of the rule is updated to point to a more relevant official topic. |
|
Adjusted managed rule |
|
The remediation guide link of the rule is updated to point to a more relevant official topic. |
|
Adjusted managed rule |
|
The remediation guide link of the rule is updated to point to a more relevant official topic. |
|
Adjusted managed rule |
|
The remediation guide link of the rule is updated to point to a more relevant official topic. |
|
Adjusted managed rule |
|
The remediation guide link of the rule is updated to point to a more relevant official topic. |
2026-08-03
|
Type |
Identifier |
Description |
|
New managed rule |
|
An AI gateway instance is considered compliant if at least one custom domain name is associated with it, and non-compliant if no custom domain name is associated. Instances that are not AI gateway instances are evaluated as not applicable. |
|
New managed rule |
|
An AI gateway instance is considered compliant if an IP access control policy is configured for it and the policy does not contain 0.0.0.0/0. The instance is considered non-compliant if no IP access control policy is configured or the policy contains 0.0.0.0/0. Instances that are not AI gateway instances are evaluated as not applicable. |
2026-07-27
|
Type |
Identifier |
Description |
|
New managed rule |
|
A snapshot is considered compliant if its source disk still exists, and non-compliant if the source disk has been released or the snapshot is not associated with a source disk. |
|
New managed rule |
|
A Cloud Backup vault is considered compliant if it has no backup jobs in the "Partially Completed" or "Failed" state, and non-compliant if such jobs exist. |
|
Compliance package update |
|
The following rule is added to the compliance package: idle disk snapshot detection ( |
|
Compliance package update |
|
The following rule is added to the compliance package: idle disk snapshot detection ( |
2026-07-23
|
Type |
Identifier |
Description |
|
New managed rule |
|
The configuration is considered compliant if the log analysis feature is enabled for any log type in Security Center. |
2026-07-17
|
Type |
Identifier |
Description |
|
Adjusted managed rule |
|
The list of supported Kubernetes versions is updated. Versions 1.28, 1.30, 1.31, 1.32, and 1.33 are added to prevent new versions from being flagged as non-compliant by mistake. |
|
New managed rule |
|
A consumer is considered compliant if its API key uses the KMS key reference mode, which supports periodic automatic rotation, and non-compliant if the API key is system-generated. |
|
New managed rule |
|
A consumer is considered compliant if it is granted access to at least one API, and non-compliant if it is not granted access to any API. |
|
New managed rule |
|
A domain is considered compliant if HTTPS redirect is enabled, and non-compliant if it is not enabled. |
|
New managed rule |
|
A domain is considered compliant if the HTTPS protocol (transport encryption) is configured, and non-compliant if it is not configured. |
2026-07-16
|
Type |
Identifier |
Description |
|
Adjusted managed rule |
|
The image source parameter is changed from single-value exact match to multi-value support. For example, both system and self can be allowed at the same time, separated by commas (,). |
|
Adjusted managed rule |
|
Message Queue for Apache AMQP instances are added to the applicable resource types to expand the coverage of tag compliance checks. |
2026-07-13
|
Type |
Identifier |
Description |
|
Adjusted managed rule |
|
A "Not applicable" determination is added: single-replica instances and disk-based instances are not applicable to this check, which avoids false positives for instance types that do not support TLS. |
2026-07-09
|
Type |
Identifier |
Description |
|
Adjusted managed rule |
|
The detection logic is changed from comparison against a fixed version threshold to referencing the version risk items in the MSE health check result (engine version too low, client version risk, or engine version at risk). This check applies only to Professional Edition instances. |