diff --git a/lib/org-governance-stack.ts b/lib/org-governance-stack.ts index 262a2eb..4990e20 100644 --- a/lib/org-governance-stack.ts +++ b/lib/org-governance-stack.ts @@ -33,6 +33,22 @@ import { Construct } from "constructs"; * Rollout discipline (Phase 2 canary): new SCPs attach to the NEW (empty) OUs * only. Extending any of them to the external-dev OU is a separate, gated * targetIds change made only after live access verification in 396287094661. + * + * Cross-review dispositions (GPT-4.1, 2026-07-14): + * - deny-root-user blocks root MFA enrollment (iam:EnableMFADevice as root). + * OPERATIONAL REQUIREMENT: create new accounts at the org ROOT, complete + * root hardening (MFA, contacts), THEN move-account into the target OU. + * - Delegated-admin ops (Phase 3) are unaffected by protect-security-baseline: + * org-managed GuardDuty/SecurityHub act on members via service-linked + * roles, which SCPs do not evaluate. If a legitimate admin action is ever + * denied, exemptions change only through the mandatory gates. + * - `arn:aws:iam::*:role/cdk-hnb659fds-*` exemption is ACCEPTED RISK (same + * decision as the external-dev guardrails): it is the only generic + * cross-account expression for CDK exec roles; member baselines protect + * those roles from takeover (ProtectPrivilegedRoles pattern). + * - Region-lock NotAction list deliberately matches battle-tested + * p-i59g24mz; regional services (s3, kms, logs, ssm...) stay region-locked + * BY DESIGN — do not add them to NotAction (that would exempt them). */ export class OrgGovernanceStack extends cdk.Stack { constructor(scope: Construct, id: string, props?: cdk.StackProps) {