Labels and Tags in AWS VPC

When you onboard an AWS VPC to Security Cloud Control, Security Cloud Control reads all AWS VPC tags as part of the configuration. That is, they are copied from AWS and stored in Security Cloud Control's database. These tags are represented as Security Cloud Control labels, which can be viewed on the Security Devices page, just like labels on any other device type. If you delete the existing labels or create new labels from Security Cloud Control, these changes are not synchronized to the AWS VPC. You must manually make the same changes using the AWS console. VPC Tags that are created or modified in the AWS console after the AWS VPC has been onboarded will not be stored in Security Cloud Control's copy of the configuration or detected as an out-of-band change.