What you are evaluating
Treat Security Hub, Security Hub CSPM, Inspector and GuardDuty as separately scoped services. Regional enablement, AWS Config dependencies, workload support and paid feature activation affect what is collected and how much the deployment costs.
A useful evaluation context
An AWS-centered team can evaluate native findings and workload signals within its existing account, Region and incident-management structure.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- Security Hub CSPM runs documented configuration checks and collects security findings across supported AWS resources.
- Unified Security Hub correlates supported signals from services such as Inspector and GuardDuty; its ingestion boundary differs from CSPM partner findings.
- Inspector vulnerability assessment and GuardDuty runtime monitoring require their own supported workloads, enablement and operational configuration.
Where it fits in the work
- Inventory a sandbox account and its Regions, then choose only the services needed for an approved, cost-bounded evaluation.
- Verify the required configuration recording and service integrations before interpreting a missing finding as a clean result.
- Assign findings to a resource owner, correct one synthetic issue and verify the underlying resource and subsequent finding state.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
In an isolated account, introduce a harmless configuration deviation in a synthetic resource, then restore the approved setting.
Evidence to look for
The expected service reports the deviation, identifies the correct account and Region, and reflects the correction after its documented processing delay.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- Which checks require AWS Config recording or another explicitly enabled service?
- Does a finding belong to Security Hub CSPM or the unified correlation path, and which integrations consume it?
- Which Regions, workload types and runtime features are absent from the proposed configuration?