Amazon

AWS

Dashboard and Browsers

Change Tracking
Policy Analysis
Risk
Dashboard
Violations
Cleanup

Change Management

Change Management
Graphical Policy
Real-time Monitoring
Create SecureChange ticket from Policy Browser for:
Rule Decommission
Rule Recertification

Policy Analysis

Policy Analysis
Object Lookup

Auditing and Reporting

Auditing and Reporting

Topology

Static Topology
VPC Peering
Transit Gateway

Notes for Amazon devices:

  • Real-time monitoring uses device polling.

    • PCI results do not include these tests: 1.1.5, 1.1.7, 1.3.4, 2.2.4.
      To pass PCI DSS tests that require rule comments or ticket IDs, add the comments and ticket IDs in Policy Browser (formerly Rule Documentation).

    • Dashboard support does not include Risk and Cleanup.

    • Auditing support does not include Compliance Policies and Unified Security Policy.

    • Topology path calculation simulates traffic if there is no more than one dynamic connection, but as many static connections as necessary.
      Supported configurations are internal VPC connectivity and connectivity between VPC and the data center.

    • In Compare, nested SGs of peered VPCs are shown as empty groups in rule source and destination. Also, no calculations are made for those rules.
      Users may look at the SG origin VPC for more details.