mirror of
https://github.com/Sea-Haven-Industries/seahaven-account-baseline.git
synced 2026-08-04 16:56:14 +00:00
Document delegated security administration runbook
Delegation to seahaven-security has no CloudFormation types; the CLI sequence is the record, same pattern as the other account toggles.
This commit is contained in:
parent
69dd0d87b5
commit
11f6e30a42
1 changed files with 36 additions and 0 deletions
36
README.md
36
README.md
|
|
@ -244,6 +244,42 @@ aws ce update-cost-allocation-tags-status --cost-allocation-tags-status \
|
|||
'TagKey=Project,Status=Active' 'TagKey=Owner,Status=Active' 'TagKey=Environment,Status=Active'
|
||||
```
|
||||
|
||||
### Delegated security administration (Phase 3, no CloudFormation resource)
|
||||
|
||||
Account **seahaven-security (001520130573)** is the org's delegated
|
||||
administrator for the detective services. Delegation has no CFN types and is
|
||||
applied via CLI from the **management account** (applied 2026-07-14; recorded
|
||||
here as the runbook — safe to re-run, all calls are idempotent):
|
||||
|
||||
```bash
|
||||
# GuardDuty: delegate + auto-enable all org members (adopts existing detectors)
|
||||
aws guardduty enable-organization-admin-account --admin-account-id 001520130573
|
||||
# then AS 001520130573: update-organization-configuration --auto-enable-organization-members ALL
|
||||
# + create-members for pre-existing accounts (mgmt, external-dev)
|
||||
|
||||
# Security Hub: delegate + auto-enable new members
|
||||
aws securityhub enable-organization-admin-account --admin-account-id 001520130573
|
||||
# then AS 001520130573: update-organization-configuration --auto-enable
|
||||
|
||||
# IAM Access Analyzer: delegate + ORGANIZATION-scoped analyzer
|
||||
aws organizations register-delegated-administrator \
|
||||
--account-id 001520130573 --service-principal access-analyzer.amazonaws.com
|
||||
# then AS 001520130573: create-analyzer --type ORGANIZATION
|
||||
|
||||
# Config: delegate the aggregator (recorders stay per-account in the baselines;
|
||||
# the aggregator's recorder-status view is the drift detector)
|
||||
aws organizations register-delegated-administrator \
|
||||
--account-id 001520130573 --service-principal config.amazonaws.com
|
||||
# then AS 001520130573: put-configuration-aggregator --organization-aggregation-source
|
||||
|
||||
# Inspector2: delegate + associate members
|
||||
aws inspector2 enable-delegated-admin-account --delegated-admin-account-id 001520130573
|
||||
```
|
||||
|
||||
New member accounts are detected/enrolled automatically after this — do NOT
|
||||
add per-account GuardDuty/SecurityHub resources to future member baselines
|
||||
(slimming the existing member stacks is a separate, verification-gated change).
|
||||
|
||||
**L-8 (billing-metrics preference) is OUTSTANDING — console only.** Enabling the
|
||||
CloudWatch `EstimatedCharges` metric in us-east-1 requires turning on *Receive
|
||||
Billing Alerts* under Billing → Billing preferences; there is no public API/CLI.
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue