mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 04:33:15 +00:00
Flip delegation runbook to applied with verification evidence (#48)
All five services delegated to seahaven-security 2026-07-14 after the hard preconditions verified (root MFA, OU placement, baseline live). Member adoption and central findings flow verified end-to-end with a sample finding; evidence recorded inline per SEC-BASE-A.
This commit is contained in:
parent
18f0f40e74
commit
2d3ba94140
1 changed files with 24 additions and 22 deletions
46
README.md
46
README.md
|
|
@ -246,31 +246,33 @@ aws ce update-cost-allocation-tags-status --cost-allocation-tags-status \
|
|||
|
||||
### Delegated security administration (Phase 3, no CloudFormation resource)
|
||||
|
||||
Account **seahaven-security (001520130573)** will be the org's delegated
|
||||
administrator for the detective services. **STATUS: PENDING — delegation has
|
||||
NOT been applied yet.** Flip this section to "applied" (with verification
|
||||
output) only in the commit that accompanies actual execution.
|
||||
Account **seahaven-security (001520130573)** is the org's delegated
|
||||
administrator for the detective services. **STATUS: APPLIED 2026-07-14,
|
||||
verified** (see evidence below). The hard preconditions were enforced before
|
||||
the first delegation call (security review SEC-BASE-B/D — never delegate to an
|
||||
account with unhardened root or before its baseline stack exists):
|
||||
|
||||
HARD PRECONDITIONS — do not run the first `enable-organization-admin-account`
|
||||
call until ALL of these verify true (security review SEC-BASE-B/D: delegating
|
||||
to an account with unhardened root and no SCPs hands the org's detection
|
||||
nerve center to the weakest credential; delegating before the baseline deploy
|
||||
wedges the stack CREATE on the auto-created detector/hub, and the retry
|
||||
collides with the orphaned RETAIN fixed-name buckets):
|
||||
- Baseline stack `UPDATE_COMPLETE`; root `AccountMFAEnabled: 1`; account
|
||||
parent `ou-nbuj-v0s9630u` with SCPs deny-root-user +
|
||||
protect-security-baseline + security-guardrails inherited.
|
||||
|
||||
```bash
|
||||
# 1. Baseline deployed:
|
||||
aws cloudformation describe-stacks --stack-name seahaven-security-baseline \
|
||||
--query 'Stacks[0].StackStatus' # expect CREATE_COMPLETE/UPDATE_COMPLETE (as 001520130573)
|
||||
# 2. Root hardened (manual, Adam): MFA enabled, no root keys, alternate contacts set
|
||||
aws iam get-account-summary --query 'SummaryMap.AccountMFAEnabled' # expect 1 (as 001520130573)
|
||||
# 3. Account moved into the security OU (SCPs in effect):
|
||||
aws organizations list-parents --child-id 001520130573 \
|
||||
--query 'Parents[0].Id' # expect ou-nbuj-v0s9630u
|
||||
```
|
||||
Verification evidence (2026-07-14):
|
||||
|
||||
Delegation is then applied via CLI from the **management account** (all calls
|
||||
idempotent):
|
||||
- `organizations list-delegated-administrators` → `001520130573` (all five
|
||||
service principals registered).
|
||||
- GuardDuty: `AutoEnableOrganizationMembers: ALL`; members 328440206208 +
|
||||
396287094661 both `Enabled`.
|
||||
- Security Hub: org auto-enable on; both members `Enabled`.
|
||||
- Org Access Analyzer `seahaven-org-analyzer` created; Config org aggregator
|
||||
`seahaven-org-aggregator` (AllAwsRegions) on the Config SLR; Inspector2
|
||||
auto-enable ec2/ecr/lambda + both members associated.
|
||||
- **Findings flow verified end-to-end:** GuardDuty sample findings created in
|
||||
member 396287094661 were listed and fully readable from the admin detector
|
||||
in 001520130573 (`Recon:EC2/PortProbeUnprotectedPort`, AccountId
|
||||
396287094661, sample=true), then archived.
|
||||
|
||||
The delegation runbook (all calls idempotent, run from the **management
|
||||
account**):
|
||||
|
||||
```bash
|
||||
# GuardDuty: delegate + auto-enable all org members (adopts existing detectors)
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue