Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Change Management is a part of CloudAware CMDB. Any object from your inventory added into CloudAware CMDB can be tracked in regard to changes.

...

Assigned To General AWS Security Queue

Assigned To Data Security Queue

  • CloudTail is disabled

  • Snapshot shared into another account or made public

  • KMS Key Created or Granted

  • KMS Key Policy Modified

Assigned To Network Security Queue

Assigned To Access Control Queue

  • EC2 Instance open to 0.0.0.0/0

  • RDS Instance open to 0.0.0.0/0

  • VPC Peering Request Accepted/Initiated

  • All VPC Network ACL Modifications

  • All VPC Routing modifications

  • New IAM Policy attached to user

  • New IAM Policy attached to group

  • Access Key Granted To User

  • User group membership is modified

  • New IAM Policy attached to role

  • S3 bucket policy modified

  • New SAML Provider is created

Creating an Approval Process

Log in to your Cloudaware account → Setup → start typing Approval in the Quick search bar → Approval Processes → think of:

  • Which object will be approved?

  • What is the entry criteria? (e.g. Cloudtrail status has to be disabled)

  • Who is the approver?

  • What happens when object is submitted for approval?

  • What happens after approval?

  • What happens after rejection?

...

Approval Status

Use Approval Processes functionality to get any new record to be automatically submitted for your approval. You may be notified by email of each submission. Review a record’s Approval Status to change and take an action. This field has a value ONLY if approval processes have been turned on. By default, approval processes are not turned on.

...

Track approval history directly in CloudAware CMDB:

...

More about working with Salesforce Approval Processes is available here.

Field History Tracking

The section ‘Changes 'Changes History' under the tab 'Change Management' on an instance provides a quick way to view the instance lifetime change log. It is not as detailed as Cloudtrail change log but is available on demand and does not require additional searching. For example, you can track any attribute of AWS EC2 instance (instance size change, a tag being applied, HIDS Status changed, etc).

...

Workflows