• Evaluate configuration settings of AWS resources using AWS Config
  • Can be re-evaluated on demand
  • Remediate actions are done via SSM documents
  • Config is integrated with cloudtrail and SNS notifications can be configured from there
  • Sends notification only when compliance status changes

SNS Topic can be selected here.