mirror of
https://github.com/Sea-Haven-Industries/seahaven-account-baseline.git
synced 2026-08-04 16:56:14 +00:00
* Add seahaven-security member baseline (Phase 3) Account 001520130573 is the org's delegated security administrator. Same member-baseline construct set as external-dev; own CD job under its own OIDC role. Created at org root pending manual root hardening before the OU move (deny-root-user invariant). * Document delegated security administration runbook Delegation to seahaven-security has no CloudFormation types; the CLI sequence is the record, same pattern as the other account toggles. * Apply Phase-3 security-review findings Delegation runbook marked PENDING with hard preconditions (baseline deployed, root MFA verified, account inside the security OU) — it had read as applied before execution, the org's known claimed-done-but-NOT failure mode (SEC-BASE-A/B). New security-guardrails SCP on the security OU: region lock, IAM user/key lockout, privileged-role protection, delegated-admin membership protection (SEC-BASE-C, cross-reviewed APPROVE). deploy-security gains stack-name pre-flight (SEC-BASE-D). Default VPC in 001520130573 deleted; empty flow-log list and aws@ alert routing documented as deliberate (SEC-BASE-F/H). |
||
|---|---|---|
| .. | ||
| scp | ||
| account-baseline-stack.ts | ||
| backup-offsite-stack.ts | ||
| backup-stack.ts | ||
| bedrock-logging-regional.ts | ||
| bedrock-logging.ts | ||
| cis-monitoring.ts | ||
| detective-controls.ts | ||
| dynamodb-cmk-stack.ts | ||
| flow-logs.ts | ||
| governance-toggles.ts | ||
| logs-key.ts | ||
| member-baseline-stack.ts | ||
| org-governance-stack.ts | ||
| regional-baseline-stack.ts | ||
| ses-monitoring.ts | ||
| web-acl.ts | ||