Monitoring Amazon AWS

Overview

Add AWS accounts to TOS as devices to monitor and manage your AWS environment. TOS tracks configuration and policy changes across your AWS accounts, giving you ongoing visibility into topology, accurate path analysis, and reliable change automation — along with continuous compliance monitoring.

AWS onboarding models

TOS supports different models to onboard AWS devices:

  • Single-account onboarding: Add one AWS account at a time using access keys for an IAM user in that account.

  • Cross-account onboarding:  Add multiple AWS accounts using a management account and a single IAM user who assumes a role in each target account.

  • AWS Organizations onboarding: Add member accounts in AWS Organizations through automatic discovery, using a management account, and an IAM user in the management account who assumes an identically-named role in each member account.

    SecureTrack cannot discover AWS opt-in Regions when you monitor AWS accounts through a Cloud Organization. You must manually add accounts in this case. For more information, see Opt-in Regions limitation for cloud organizations.
AWS and TOS configuration

All onboarding models require configuration in both AWS and TOS:

  • AWS platform configuration: Create the IAM identity and required permissions and required permissions on AWS for the onboarding model you choose.

  • TOS device configuration: Add the AWS account as a device, and provide the required credentials.

    For AWS Organization-based onboarding only, first define and configure the cloud organization in TOS to manage organization-level access.

To see which TOS features are supported for your device, review the SecureTrack Features by Vendor.