Vulnerability and Compliance Management on AWS with Inspector and Patch Manager
_Category: Vulnerability Management_
Vulnerability management in the cloud is not simply a matter of running a security scanner on a schedule. New CVEs are disclosed every day, and in environments where hundreds of EC2 instances, container images, and Lambda functions are continuously deployed, you must be able to answer the question: "Is our workload safe right now, at this very moment?" This guide walks through the full vulnerability management lifecycle — detection, prioritization, patching, and evidence collection — anchored around Amazon Inspector and AWS Systems Manager Patch Manager.
---
A New Mindset for Cloud Vulnerability Management
Cloud environments operate on fundamentally different assumptions than on-premises infrastructure. Instances spin up on demand, container images are built dozens of times a day, and Lambda functions can be deployed at any moment. Quarterly scans simply cannot keep pace with this velocity.
Four critical shifts are required. First, move from periodic scanning to Continuous Scanning — the moment a new CVE is registered in the NVD, already-deployed workloads should be evaluated automatically. Second, shift the focus from discovery to prioritization — use a combination of CVSS score, exploitability, and business criticality to determine which patches to apply first. Third, replace manual patching with automated patching at scale — SSM Patch Manager works like a mass vaccination campaign, automatically applying verified patches to hundreds of instances. Fourth, go beyond patch completion to compliance evidence collection — Audit Manager automatically gathers evidence for regulatory frameworks such as PCI DSS, HIPAA, and SOC 2.
---
Amazon Inspector v2: Automated Scanning for EC2, ECR, and Lambda
Amazon Inspector is a continuous health-monitoring service for your workloads. Before diving into operations, it helps to understand the key differences between v1 and v2.
| Attribute | Inspector v1 | Inspector v2 | |-----------|-------------|-------------| | Scan mode | Manual Assessment Run | Continuous Scanning (automatic) | | Agent | Inspector-specific agent required | Reuses SSM Agent (no separate agent needed) | | Targets | EC2 only | EC2, ECR container images, Lambda functions | | New CVE handling | Requires a re-run | Automatic re-evaluation when new CVE is published | | Multi-account | Cumbersome | Centrally managed via AWS Organizations |
Continuous Scanning automatically triggers re-evaluation whenever a new software package is installed or a new CVE is published. EC2 instances are scanned via SSM Agent-based analysis, ECR images are scanned automatically on push, and Lambda functions are assessed for vulnerabilities in both function code and dependency libraries. When integrated with AWS Organizations, findings from all member accounts are centrally managed from a Delegated Administrator account.
---
CVE Prioritization and Operating Suppression Rules
Inspector provides an Inspector Score that combines the CVSS score, real-world exploitability, and network reachability to give you a holistic risk ranking. In practice, Critical findings with a score of 9.0 or above are treated as the highest priority, and vulnerabilities on internet-facing instances are escalated above those on internal-only hosts.
Suppression Rules let you intentionally suppress specific findings. Common use cases include suppressing a CVE that has been confirmed unexploitable in your environment, or acknowledging known issues on legacy instances that are mid-migration. Even suppressed findings are retained in audit history. To prevent abuse, it is strongly recommended to maintain an internal process that documents the approver, justification, and expiration date for every suppression.
Service role distinctions are a frequent exam topic.
| Service | Primary Role | Detection Approach | Key Keywords | |---------|-------------|--------------------|--------------| | Amazon Inspector | CVE vulnerability and CIS benchmark assessment | Static analysis against known vulnerability databases | CVE, software vulnerability, OS patch | | GuardDuty Malware Protection | Malware detection on EC2 and S3 | Behavior-based anomaly detection + file signatures | Malware, ransomware, C2 communication | | Security Hub | Aggregated security findings dashboard | Aggregates findings from Inspector, GuardDuty, and others | Central dashboard, multi-service integration |
Inspector is a static analysis tool that asks "does a known vulnerability exist here?" GuardDuty Malware Protection is a dynamic, behavior-based detection tool that asks "is malicious code running right now?" Inspector findings integrate with EventBridge, enabling workflows that automatically trigger Lambda, send SNS notifications, or create Jira tickets the moment a new Critical vulnerability is detected.
---
Core Components of AWS Systems Manager
In the context of vulnerability management, four SSM components are essential to understand.
Session Manager provides browser-based, secure shell access to EC2 instances without SSH or RDP. No inbound ports need to be opened, and every session is automatically logged to CloudTrail and S3 for audit purposes.
Run Command lets you execute shell commands or PowerShell scripts remotely across hundreds of instances simultaneously, without logging into each one. Results are consolidated in the SSM console.
State Manager continuously enforces a desired configuration state on your instances. Define an Association — for example, ensuring CloudWatch Agent is always installed — and State Manager periodically detects configuration drift and automatically remediates it.
Maintenance Window lets you define a scheduled time window (for example, every Sunday from 2 AM to 4 AM) during which management tasks are permitted to run. Combined with Patch Manager, this ensures patches are applied automatically during low-impact maintenance periods.
---
Automating OS Patching with Patch Manager
Patch Manager works like a large-scale, automated vaccination program for your fleet. A Patch Baseline defines which patches are approved, a Maintenance Window defines when they are applied, and Compliance State tracks the outcome in real time.
| Patch Baseline Type | Description | Typical Use Case | |--------------------|-------------|------------------| | AWS-managed Baseline | Default baselines provided by AWS per OS | Getting started without custom configuration | | Custom Baseline | Approval rules defined by your team | Excluding specific CVEs, or selectively applying patches | | Patch Group | Logical grouping of instances by tag | Applying different Baselines per environment (dev/staging/prod) |
Patch Group is a tag-based mechanism for organizing EC2 instances into logical groups. A common best practice is to auto-approve the latest patches in development environments and apply a 7-day delay before approval in production, reducing operational risk. Compliance State tracks each instance's Compliant or Non-Compliant status in real time, and these results are forwarded to Security Hub for visibility in the unified dashboard.
The division of labor between Inspector and Patch Manager is clear: Inspector detects what is vulnerable, and Patch Manager executes the remediation. Both services share SSM Agent as a common foundation.
---
Collecting Compliance Evidence with Audit Manager and Trusted Advisor
AWS Audit Manager automatically collects evidence for each control in regulatory frameworks such as PCI DSS, HIPAA, SOC 2, ISO 27001, and NIST. For a patch management policy control, it pulls Compliance reports from SSM Patch Manager. For access control requirements, it pulls IAM configuration data automatically. Evidence is organized into Assessments, which can be packaged into auditor-ready reports and enable Continuous Compliance monitoring.
AWS Trusted Advisor is an advisor that checks general best practices — things like MFA not enabled on the root account, overly permissive S3 bucket policies, and unused access keys. It is not the right tool for CVE vulnerability scanning (that is Inspector's domain) or for architecture resilience evaluation (that is Amazon Resilience Hub's domain).
ECR scan modes are also worth remembering. Basic scanning uses the Clair open-source engine and runs on push or manually. Enhanced scanning uses the Inspector v2 engine and supports Continuous Scanning. When integrated into a CI/CD pipeline, Enhanced scanning functions as a security gate that blocks vulnerable images from being promoted to production.
---
Tricky Vulnerability and Patching Scenarios on the Exam
Scenario 1: You want to assess CVE vulnerabilities and CIS benchmark compliance on EC2 instances using an agent-based approach and view results centrally. Answer: Amazon Inspector. It uses SSM Agent-based scanning and supports both CVE and CIS benchmark evaluation. Security Hub is an aggregation dashboard; GuardDuty handles threat detection — do not confuse their roles.
Scenario 2: You want to continuously detect CVEs on hundreds of EC2 instances and automatically apply patches. Answer: Amazon Inspector combined with Systems Manager Patch Manager. GuardDuty and Patch Manager is an incorrect pairing — GuardDuty does not perform CVE-list-based scanning.
Scenario 3: You want to assess the resilience of a workload against availability targets and RTO/RPO objectives, and receive improvement recommendations. Answer: Amazon Resilience Hub. This is the purpose-built tool for resilience evaluation, identifying single points of failure, missing backups, and missing multi-AZ configurations.
Inspector vs. GuardDuty Malware Protection — final comparison:
| Attribute | Amazon Inspector | GuardDuty Malware Protection | |-----------|-----------------|------------------------------| | Detection target | Known CVEs, CIS