HashiCorp Sentinel policy library for AWS
This topic describes how to run Sentinel policies created and maintained by HashiCorp. For instructions about how to create your own custom Sentinel policies, refer to Define custom Sentinel policies.
Overview
Pre-written Sentinel policy libraries streamline your compliance processes and enhance security across your infrastructure. HashiCorp's ready-to-use policies can help you enforce best practices and security standards across your AWS environment.
Complete the following steps to implement pre-written Sentinel policies in your workspaces:
- Obtain the policies you want to implement. Download policies directly into your repository or create a fork of the HashiCorp repositories.
- Connect policies to your workspace. After you download policies or fork policy repositories, you must connect them to your HCP Terraform or Terraform Enterprise workspaces.
Refer to the Sentinel documentation for information about the Sentinel language.
Requirements
You must use one of the following Terraform applications:
- HCP Terraform
- Terraform Enterprise v202406-1 or newer
Permissions
To create new policy sets and policies, your HCP Terraform or Terraform Enterprise user account must either be a member of the owners team or have the Manage Policies organization-level permissions enabled. Refer to the following topics for additional information:
Version control system
You must have a GitHub account connected to HCP Terraform or Terraform Enterprise to manually connect policy sets to your workspaces. Refer to Connecting VCS Providers for instructions.
Available AWS policies
HashiCorp publishes pre-written policies for the following AWS standards.
- Center for Internet Security (CIS)
- Foundational Security Best Practices (FSBP)
- ISO/IEC 27001:2013 Annex A
- PCI DSS
- NIST SP 800-53 Revision 5
Center for Internet Security (CIS)
The Center for Internet Security (CIS) is a non-profit organization that publishes prescriptive guidance for configuring secure cloud services. Refer to the CIS website for additional information.
CIS refers to their standards as benchmarks. HashiCorp publishes pre-written policies that support the following CIS benchmarks for AWS:
- Amazon Web Services Foundations version 1.2. Refer to the AWS documentation for additional information about this version.
- Amazon Web Services Foundations version 1.4. Refer to the AWS documentation for additional information about this version.
- Amazon Web Services Foundations version 3.0. Refer to the AWS documentation for additional information about this version.
Refer to the CIS policy set for AWS GitHub repository for details about these policies.
Foundational Security Best Practices (FSBP)
The Foundational Security Best Practices (FSBP) standard enforces security best practices on AWS resources. HashiCorp publishes pre-written policies that support the following AWS FSBP standards:
- AWS Foundational Security Best Practices v1.0.0. Refer to the AWS documentation for additional information.
Refer to the AWS FSBP policy set repository for details about these policies.
ISO/IEC 27001:2013 Annex A
International Electrotechnical Commission (IEC) and International Organization for Standardization (ISO) are independent, non-governmental, not-for-profit organizations that develop and publish international software standards.
The ISO/IEC 27001:2013 standard defines guidelines on how to establish, implement, maintain, and continually improve an information security management system. Annex A describes a set of information security controls, including cloud services governance, for mitigating risks identified in an information security management system. Refer to the AWS ISO/IEC 27001:2013 Annex A user guide for more information about the standard.
Refer to the 27001:2013 Annex A policy set repository for details about the policies HashiCorp publishes and maintains to support ISO/IEC 27001:2013 Annex A.
PCI DSS
The Payment Card Industry Data Security Standard (PCI DSS) is set of rules for protecting payment data throughout the data's lifecycle. Compliance with PCI DSS is mandatory for organizations that handle credit card information. Refer to the PCI DSS website for more information about the standard.
Refer to the PCI DSS policy set reposity for details about the policies HashiCorp publishes and maintains.
NIST SP 800-53 Revision 5
NIST Special Publication 800-53 Revision 5 (NIST SP 800-53 Rev. 5) framework provides a catalog of security and privacy requirements for protecting the confidentiality, integrity, and availability of information systems and critical resources. Refer to the AWS NIST SP 800-53 documentation information about the AWS implementation.
Refer to Pre-written Sentinel Policies for AWS NIST Foundations Benchmarking repository for details about these policies.
Get policies
Use one of the following methods to get pre-written policies:
- Download policies from the registry: Use this method if you want to assemble custom policy sets without customizing policies.
- Fork the HashiCorp policy GitHub repository: Use this method if you intend to customize the policies.
Complete the following steps to download policies from the registry and apply them directly to your workspaces.
- Browse the policy libraries available in the Terraform registry.
- Click on a policy library and click Choose policies.
- Select the policies you want to implement. The registry generates code in the USAGE INSTRUCTIONS box.
- Click Copy Code Snippet to copy the code to your clipboard.
- Create a GitHub repository to store the policies and the policy set configuration file.
- Create a file called
sentinel.hclin the repository. - Paste the code from your clipboard into
sentinel.hcland commit your changes. - Complete the instructions for connecting the policies to your workspace.
Connect policies to your workspace
- Sign in to HCP Terraform or Terraform Enterprise and navigate to the organization with workspaces you want to connect policies to.
- Choose Settings from the sidebar.
- Click Policy Sets and click Connect a new policy set.
- Click the Version control provider (VCS) tile.
- Enable the Sentinel option as the policy framework.
- Specify a name and description for the set.
- Configure any additional options for the policy set and click Next.
- Choose the GitHub connection type, then choose the repository you created in Set up a repository for the policies.
- If the
sentinel.hclpolicy set file is stored in a subfolder, specify the path to the file in the Policies path field. The default is the root directory. - If you want to apply updated policy sets to the workspace from a specific branch, specify the name in the VCS branch field. The default is the default branch configured for the repository.
- Click Next and specify any additional parameters you want to pass to the Sentinel runtime and click Connect policy set to finish applying the policies to the workspace.
Run a plan in the workspace to trigger the connected policies. Refer to Start a Terraform run for additional information.
Next steps
- Group your policies into sets and apply them to your workspaces. Refer to Create policy sets for additional information.
- View results and address Terraform runs that do not comply with your policies. Refer to View results for additional information.
- You can also view Sentinel policy results in JSON format. Refer to View Sentinel JSON results for additional information.