Document history - AMS Accelerate Operations Plan

Document history

The following table describes the important changes to the documentation since the last release of the AMS Accelerate guide.

  • Latest documentation update: September 16, 2021

Change Description Date
New feature! Operations on Demand

Operations on Demand provides you with a curated catalog of operations activities.

See AWS Managed Services Operations On Demand.

September 16, 2021
Config Aggregator

As a part of the AMS Accelerate setup, the AMS team configures a config aggregator that aggregates the config compliance information in your account to an AMS-owned account where it is compiled into a report for you.

See Infrastructure security.

September 16, 2021
Patch Scheduling

When following step two in the procedure to set up a patching schedule, a note was added warning about initiating an immediate patch versus following the set schedule.

See Default patch cycle.

September 16, 2021
New monitoring alarm

Alert name and trigger condition: VPNTunnelDown, TunnelState > 0 for 1 min, 20 consecutive times. TunnelState is 0 when both tunnels are down, .5 when one tunnel is up and 1.0 when both tunnels are up.

See Alerts from baseline monitoring in AMS.

September 16, 2021
Bad JSON, backup

An example JSON block was missing a closing curly bracket, that was fixed.

See Associating AWS resources to the AMS Accelerate backup plan.

September 16, 2021
Bad JSON, patching

An example JSON block was not formatted correctly, that was fixed.

See Patch monitoring and failure remediation.

September 16, 2021
Bad JSON

An example JSON block was not formatted correctly, that was fixed.

See Patch monitoring and failure remediation.

September 16, 2021
Root account

New section on using the root credentials.

See How and when to use the root user account.

August 26, 2021
Change record

New and updated information on using the AMS Accelerate change tracking tool.

See Tracking changes in your AMS Accelerate accounts.

August 26, 2021
Compliance and conformance

Removed the ams-nist-cis-s3-bucket-policy-grantee-check Config rule.

See Compliance and conformance.

August 26, 2021
Getting started

Created a prerequisites section with the list of external dependencies for network configuration.

See Accelerate onboarding prerequisites.

August 12, 2021
Backup

Clarified wording for adding backup to an account.

See Adding AWS Backup to your AMS Accelerate accounts.

August 12, 2021
Account discovery tool

The Changelog zip has been updated.

See Account discovery.

August 12, 2021
Service description

Windows 2008 R2 is removed from the list of supported OSes.

See Supported configurations.

August 12, 2021
Service description

New RDS alert remediation feature.

See AMS automatic remediation of alerts.

July 29, 2021
Backup

Details on default backup plans.

See Backup management in AMS Accelerate.

July 29, 2021
Service description

Added NAT Gateway to the list of service supported by monitoring.

See Service description.

July 15, 2021
Support experience

Added missing AWS Support service codes

  • Service requests: service-ams-operations-service-request and for

  • Incidents: service-ams-operations-report-incident

See What is incident management?.

July 15, 2021
Backups

Clarified function of backup vaults.

See Backup management in AMS Accelerate.

July 15, 2021
Account dicovery

Clarified CloudSearch example: Don't change the "--domain-owner 354220221581" and " --region us-west-2", copy as-is.

Also, added access to the account discovery CLI CHANGELOG.

See Account discovery.

July 15, 2021
June 2021
New feature: Self-service reporting

AMS now offers self-service reporting through a new Reporting page in the AMS Console. See Self-service reporting.

June 17, 2021
Patching: Added patching recommendations and additional failure and remediation information to the Patching section. See Patching recommendations and Patch monitoring and failure remediation. June 17, 2021
Account discovery: Added an IAM policy to the Account Discovery section and updated the AWS account discovery with AWS CloudShell section with information about using AWS Regions. Also added notes recommending using the AWS CloudShell method for account discovery to all other methods. See Account discovery. June 17, 2021
Updates to Patch remediation in Accelerate: Support SSM maintenance window for patching with instance target, advance notice patch notification information, added missing patch counts in end patch notification. See Patch monitoring and failure remediation June 17, 2021
Updated the Alerts from baseline monitoring section with information on how to set up direct notifications. See Alerts from baseline monitoring in AMS. June 17, 2021
Added information abouit our SSM document policy. AWS Systems Manager in AMS Accelerate. June 17, 2021
Updated the AMS responsibility matrix (RACI). See Roles and responsibilities June 17, 2021
Updated the AWS Config reporting table. See Reporting in AMS. June 17, 2021
Renamed Remediation Category: Auto Remediation to Remediation Category: Automatic Remediation nad removed duplicate rule (ams-nist-cis-cloudtrail-enabled). See Compliance and conformance. June 17, 2021
Updated Macie links from 'findings' page to 'alerts' page; removed 'Average SwapUsage' from Alerts from baseline monitoring table. See Alerts from baseline monitoring in AMS. June 17, 2021
Added GuardDuty suppression rules. See Data protection. June 17, 2021
Removed the SALZ diagram from the How monitoring works page.

See How monitoring works.

May 13, 2021
Updated note to explain that the Instance Configuration Service is triggered through events and those events, as of now, are Instance tag events and Instance start events.

See Automated instance configuration setup.

May 13, 2021
Several minor updates, resulting from a full document review, to improve clarity and accuracy.

See What is AWS Managed Services?.

May 13, 2021
Improved accuracy in the Roles and responsibilities table by replacing relevant instances of "detective controls" with "Config Rules".

See Roles and responsibilities.

May 13, 2021
Added a new section: Granting permissions for AMS Accelerate administration. This new section provides a CloudFormation template that contains policies related to customer access within your Accelerate account.

See Granting permissions for AMS Accelerate administration.

May 13, 2021
Updated the "Remediation Category: Auto Remediation" in the "AMS Accelerate AWS Config Rules Inventory" table to include the three rules ams-nist-cis-cloudtrail-enabled, ams-nist-cis-guardduty-enabled-centralized, and ams-nist-cis-vpc-flow-logs-enabled

See Compliance and conformance.

May 13, 2021
Updated the description of how to use 'AwsAccountDiscoveryCli' for discovery on the Account discovery page.

See Account discovery.

May 13, 2021
Updated the Backup management section to remove outdated wording pertaining to existing backup plans and clarified language to distinguish between backup vaults and Accelerate accounts; formatted code blocks.

See Backup management in AMS Accelerate.

May 13, 2021
Clarified and elaborated on how AMS processes incidents and included a flowchart for added visual clarity.

See What is incident management?.

May 13, 2021
Many updates and new content for Monitoring tags and Tagging.

See Monitoring tags, Resource Tagger, and Tag-based Alarm Manager.

April 15, 2021
Added a link to monitoring information in the Supported Services section.

See Supported services.

April 15, 2021
Updated the AMS Accelerate service description page.

See Service description.

March 19, 2021
The Service Description was updated and the 'Getting Started' section of the 'What is Accelerate?' chapter was made into a separate chapter.

See Getting Started with AWS Managed Services.

March 19, 2021
This is the first release of this document.

See What is AWS Managed Services?.

March 16, 2021