This workflow template ensures compliance and data security by automating the process for handling AWS S3 buckets without encryption, as detected by Wiz. It identifies the bucket owner or notifies a designated Slack channel, recommends enabling AWS256 encryption, and either applies the changes upon approval or opens a follow-up ticket if the suggestion is rejected. It is essential for maintaining security standards and aligning with regulatory frameworks like CC6 and SOC2.
Trigger
Wiz
Use Cases
CSPM
Workflow Breakdown
Retrieve tags on the bucket
Reach out to the bucket owner or Slack channel, notify them about the issue
Suggest to remediate by enabling default AES256 encryption on the bucket
Apply changes if the user approves
If user or channel rejects, collect a reason and open a follow-up ticket
Update notes on the Wiz issue id that was provided
Vendors
AWS, Slack, Utils, Wiz, Jira Cloud
Workflow Output
Success/Failure - Jira Ticket and Slack messages
Tips
Setup integration names and Jira information on the first Workflow Context Step