mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 05:43:17 +00:00
62 lines
2.8 KiB
Markdown
62 lines
2.8 KiB
Markdown
|
|
# seahaven-account-baseline
|
||
|
|
|
||
|
|
Account-level security and governance baseline for Sea Haven Industries
|
||
|
|
(AWS account **328440206208**, region **us-east-1**), managed as a single CDK
|
||
|
|
TypeScript app. This is where account-wide detective controls live, so they are
|
||
|
|
versioned, reviewed, and drift-checked like any other stack.
|
||
|
|
|
||
|
|
## What it deploys
|
||
|
|
|
||
|
|
### CloudTrail (audit finding C-1)
|
||
|
|
|
||
|
|
| Resource | Logical ID | Notes |
|
||
|
|
|---|---|---|
|
||
|
|
| Multi-region trail | `Trail` (`seahaven-org-trail`) | Management events read+write, global service events, **log-file validation on** |
|
||
|
|
| Log bucket | `TrailLogBucket` (`seahaven-cloudtrail-logs-328440206208`) | Private (Block Public Access all), SSE-KMS, versioned, **TLS-only**, **Object Lock GOVERNANCE 365d**, lifecycle (Glacier @90d, expire @365d), server access logging → `seahaven-s3-access-logs` |
|
||
|
|
| KMS CMK | `TrailKey` (`alias/cloudtrail-logs`) | Encrypts log files; **automatic rotation enabled** |
|
||
|
|
| CloudWatch Logs group | created by the L2 `Trail` | 365-day retention; this is the group the CIS Section 4 metric filters (H-1) attach to |
|
||
|
|
|
||
|
|
**Data flow:** API activity across all regions → CloudTrail → (a) KMS-encrypted,
|
||
|
|
Object-Locked S3 bucket for durable/tamper-resistant storage and (b) CloudWatch
|
||
|
|
Logs for real-time querying and metric-filter alarms.
|
||
|
|
|
||
|
|
**Compliance impact:** closes CIS 3.1 (multi-region trail), 3.2 (log-file
|
||
|
|
validation), 3.4 (CloudWatch Logs integration), 3.6 (bucket access logging),
|
||
|
|
3.7 (KMS CMK encryption), and 3.8 (CMK rotation). Unblocks CIS Section 4 /
|
||
|
|
finding H-1 (metric filters + alarms now have a log group to target).
|
||
|
|
|
||
|
|
### Design decisions
|
||
|
|
|
||
|
|
- **Management events only.** Object-level S3/Lambda data events (CIS 3.10/3.11)
|
||
|
|
are deferred to control cost; revisit with targeted S3 *write* data events on
|
||
|
|
sensitive buckets (payments / accounting / kb) if needed.
|
||
|
|
- **Object Lock GOVERNANCE, not COMPLIANCE.** Tamper-resistant but still
|
||
|
|
deletable by a principal holding `s3:BypassGovernanceRetention` — avoids the
|
||
|
|
irreversibility of COMPLIANCE mode. Revisit if a stricter posture is required.
|
||
|
|
- **RETAIN** on the bucket and KMS key so a stack teardown never destroys the
|
||
|
|
audit trail.
|
||
|
|
|
||
|
|
## Roadmap (same stack)
|
||
|
|
|
||
|
|
Account-level detective controls with no current home, to be added here:
|
||
|
|
AWS Config (H-2), GuardDuty (H-3), Security Hub (H-4), IAM Access Analyzer
|
||
|
|
(M-5), Inspector2 (M-6).
|
||
|
|
|
||
|
|
## Deploy
|
||
|
|
|
||
|
|
CI/CD via the org reusable workflows (`ci-typescript-cdk.yaml`,
|
||
|
|
`cd-cdk.yaml`); pushes to `main` deploy through the OIDC role in
|
||
|
|
`secrets.AWS_DEPLOY_ROLE_ARN`. Local: `npm ci && npm run build && npx cdk diff`.
|
||
|
|
|
||
|
|
```
|
||
|
|
npx cdk deploy seahaven-account-baseline
|
||
|
|
```
|
||
|
|
|
||
|
|
## Verify
|
||
|
|
|
||
|
|
```
|
||
|
|
aws cloudtrail get-trail-status --name seahaven-org-trail # IsLogging: true
|
||
|
|
aws cloudtrail describe-trails --trail-name-list seahaven-org-trail
|
||
|
|
aws cloudtrail validate-logs --trail-arn <arn> --start-time <t> # digest integrity
|
||
|
|
```
|