compliance.tf

Preventive vs detective controls

Preventive controls block a non-compliant change before it is made, and detective controls expose a non-compliant state after it appears. In infrastructure as code, prevention runs before apply, while detection relies on scans and runtime monitoring.

Comparison

PreventiveDetective
When it actsPrior to planning or applying resourcesOnce code exists or resources are live
Terraform examplesModule defaults and input validation; a policy that refuses a planCheckov or Trivy scans; AWS Config rules; Security Hub findings
Result of a violationThe proposed change is blockedA finding someone has to triage and fix
What it can seeOnly the path it protectsAnything the scanner or monitor can read, including drift and console edits
Typical audit evidenceModule source, plan outputScan reports, configuration history

Why teams need both

On the path it protects, a preventive control takes away the opportunity for a misconfiguration, so there is less to fix and account for; the audit evidence guide shows how each type appears during an audit. That protection stops at the path boundary. A resource made through the console, or one built from a module outside the catalog, never crosses it, and importing an existing resource does not prove it was compliant before import. Detective tooling supplies an independent check and catches those cases.

How compliance.tf applies it

compliance.tf modules act as preventive controls. The module carries the control as defaults and input validation, so a non-compliant value fails at terraform plan:

│ Error: Invalid value for variable
│
│ s3_bucket_logging_enabled: logging.target_bucket must be set
│ to enable S3 bucket access logging.
│
│ Frameworks requiring this control:
│   SOC 2, CIS AWS v1.4.0 (3.6), PCI DSS v4.0 (10.2.1)

compliance.tf does not detect drift and works only while infrastructure as code is being authored. Run a scanner in CI and keep runtime monitoring in AWS, so each layer verifies the other.

Sources

On this page

Ask AI about this

Help improve this page