diff --git a/README.md b/README.md index 5e7742a..c0c011d 100644 --- a/README.md +++ b/README.md @@ -244,6 +244,42 @@ aws ce update-cost-allocation-tags-status --cost-allocation-tags-status \ 'TagKey=Project,Status=Active' 'TagKey=Owner,Status=Active' 'TagKey=Environment,Status=Active' ``` +### Delegated security administration (Phase 3, no CloudFormation resource) + +Account **seahaven-security (001520130573)** is the org's delegated +administrator for the detective services. Delegation has no CFN types and is +applied via CLI from the **management account** (applied 2026-07-14; recorded +here as the runbook — safe to re-run, all calls are idempotent): + +```bash +# GuardDuty: delegate + auto-enable all org members (adopts existing detectors) +aws guardduty enable-organization-admin-account --admin-account-id 001520130573 +# then AS 001520130573: update-organization-configuration --auto-enable-organization-members ALL +# + create-members for pre-existing accounts (mgmt, external-dev) + +# Security Hub: delegate + auto-enable new members +aws securityhub enable-organization-admin-account --admin-account-id 001520130573 +# then AS 001520130573: update-organization-configuration --auto-enable + +# IAM Access Analyzer: delegate + ORGANIZATION-scoped analyzer +aws organizations register-delegated-administrator \ + --account-id 001520130573 --service-principal access-analyzer.amazonaws.com +# then AS 001520130573: create-analyzer --type ORGANIZATION + +# Config: delegate the aggregator (recorders stay per-account in the baselines; +# the aggregator's recorder-status view is the drift detector) +aws organizations register-delegated-administrator \ + --account-id 001520130573 --service-principal config.amazonaws.com +# then AS 001520130573: put-configuration-aggregator --organization-aggregation-source + +# Inspector2: delegate + associate members +aws inspector2 enable-delegated-admin-account --delegated-admin-account-id 001520130573 +``` + +New member accounts are detected/enrolled automatically after this — do NOT +add per-account GuardDuty/SecurityHub resources to future member baselines +(slimming the existing member stacks is a separate, verification-gated change). + **L-8 (billing-metrics preference) is OUTSTANDING — console only.** Enabling the CloudWatch `EstimatedCharges` metric in us-east-1 requires turning on *Receive Billing Alerts* under Billing → Billing preferences; there is no public API/CLI.