shiichan

Security Hub CSPM's New AI Security Best Practices Standard Catches AI Misconfigs Automatically!

Hey everyone, it's Shiichan! Today I've got a handy update that keeps an eye on your AI security all in one place.

AWS What's New aws.amazon.com

What was announced?

According to AWS What's New, AWS Security Hub CSPM now has a new standard called AI Security Best Practices. It bundles 31 automated controls that detect when your deployed AI resources drift away from security best practices. It covers Amazon Bedrock, Amazon Bedrock AgentCore, and Amazon SageMaker workloads, and it was built by AWS security experts.

The story so far

Until now, checking whether your AI workloads were configured safely meant running manual assessments or authoring your own custom rules. With AI services multiplying, eyeballing every Bedrock and SageMaker setting by hand was a real chore.

What changes

Just turn the standard on, and the 31 controls automatically evaluate your resources and generate findings for anything that strays from best practices. No more manual assessments or custom rule authoring, so security teams can spot and fix misconfigurations fast.

Dive Deep

The covered domains span the security essentials: network isolation, encryption at rest and in transit, VPC placement, KMS key usage, private container registry requirements, and authorization controls.

The resources it inspects are broad too, from Bedrock AgentCore runtimes, gateways, memory stores, and custom browsers to SageMaker notebook instances, endpoints, models, monitoring jobs, and feature groups. Each control is assigned a security category, and a finding is generated whenever a resource deviates from best practices.

The standard identifier is:

standards/ai-security-best-practices/v/1.0.0

It's available in all Regions where Security Hub CSPM is available, including AWS GovCloud (US) and the China Regions. For the details, check the AWS Security Hub CSPM User Guide. On pricing, you can try Security Hub CSPM at no cost for 30 days with the AWS Free Tier.

Wrap-up

  • AWS Security Hub CSPM adds an AI Security Best Practices standard with 31 automated controls
  • Covers Amazon Bedrock, Bedrock AgentCore, and SageMaker workloads
  • Auto-checks network isolation, encryption, VPC placement, KMS, authorization, and more, with no manual work or custom rules
  • Available in every Region where Security Hub CSPM runs (including GovCloud (US) and China Regions), free for 30 days

If your team is shipping AI on Bedrock or SageMaker, or you want one place to watch all your AI security settings, this one's for you!