Misconfigurations
The Misconfigurations page (/security) shows configuration checks for your AWS infrastructure. Every misconfiguration represents a specific resource that is failing a security control.
What Is a Misconfiguration?
A misconfiguration is a resource setting that fails a security control. Examples include:
- An S3 bucket with public access enabled
- An EC2 security group allowing unrestricted inbound access on port 22 (SSH)
- An IAM user with no MFA enabled
- An RDS instance without encryption at rest
Misconfigurations describe cloud configuration weaknesses. For CVE-based software issues in packages and workloads, see Vulnerabilities.
Misconfiguration Attributes
Each misconfiguration displayed on the Misconfigurations page includes:
| Attribute | Description |
|---|---|
| Severity | CRITICAL, HIGH, MEDIUM, or LOW — indicates the risk level of the misconfiguration |
| Resource Type | The AWS resource type affected (e.g., S3 Bucket, EC2 Instance, IAM User) |
| Affected Resource | The specific resource name or ID with the issue |
| Title / Rule | The name of the security control that was violated |
| Description | An explanation of what the control checks and why it matters |
| Impact | What risk the misconfiguration introduces |
| Remediation | Step-by-step guidance for fixing the issue |
Viewing Misconfiguration Details
Click any misconfiguration in the list to open its detail panel on the right side of the screen. The panel is organized into the following sections:
Identity
- Resource ID — the unique identifier of the affected AWS resource
- Resource Type — the AWS resource type
Details
- Region — the AWS region where the resource is deployed
- AWS Account — the connected account that owns the resource
- First Detected — when Byrsa first identified this misconfiguration
- Last Updated — the last time the misconfiguration record was updated
Rule
- The name of the security control or rule being violated
Impact
- A description of the security risk and potential consequences of leaving this misconfiguration in place
Recommendation
- Actionable remediation steps to resolve the misconfiguration
Panel Footer
The footer of the detail panel provides two actions:
- View Full Details — opens the full resource detail view
- Create Task — creates a security task to track the remediation of this misconfiguration
Creating a Task from a Misconfiguration
You can turn any misconfiguration into a trackable task by clicking Create Task in the detail panel footer. A task creation form will appear where you can:
- Set a title and description for the task
- Choose a priority (Low, Medium, High, Critical)
- Optionally toggle Create Jira ticket if your Jira integration is configured
Byrsa enforces a one-task-per-misconfiguration rule. If a task already exists for a misconfiguration, you will not be able to create another one. This prevents duplicate tracking of the same issue.
Once created, the task will appear on the Tasks page, where you can update its status and manage your remediation backlog.