EC2 instances managed by SSM should have a compliant patch status

This page is not yet available in Spanish. We are working on its translation.
If you have any questions or feedback about our current translation project, feel free to reach out to us!

Description

This control verifies the status of Systems Manager patch compliance, ensuring that patch installations on EC2 instances are successful. If there are any patch compliance events with a status of NON_COMPLIANT, the control will fail. This check applies only to EC2 instances managed by Systems Manager Patch Manager.

Keeping your EC2 instances patched according to organizational requirements helps to minimize the attack surface within your AWS accounts.

Remediation

For guidance on configuring and troubleshooting Patch Manager, refer to the AWS Systems Manager Patch Manager section of the AWS Systems Manager User Guide.