diff --git a/README.md b/README.md index 2fd03cb..78ce524 100644 --- a/README.md +++ b/README.md @@ -246,31 +246,33 @@ aws ce update-cost-allocation-tags-status --cost-allocation-tags-status \ ### Delegated security administration (Phase 3, no CloudFormation resource) -Account **seahaven-security (001520130573)** will be the org's delegated -administrator for the detective services. **STATUS: PENDING — delegation has -NOT been applied yet.** Flip this section to "applied" (with verification -output) only in the commit that accompanies actual execution. +Account **seahaven-security (001520130573)** is the org's delegated +administrator for the detective services. **STATUS: APPLIED 2026-07-14, +verified** (see evidence below). The hard preconditions were enforced before +the first delegation call (security review SEC-BASE-B/D — never delegate to an +account with unhardened root or before its baseline stack exists): -HARD PRECONDITIONS — do not run the first `enable-organization-admin-account` -call until ALL of these verify true (security review SEC-BASE-B/D: delegating -to an account with unhardened root and no SCPs hands the org's detection -nerve center to the weakest credential; delegating before the baseline deploy -wedges the stack CREATE on the auto-created detector/hub, and the retry -collides with the orphaned RETAIN fixed-name buckets): +- Baseline stack `UPDATE_COMPLETE`; root `AccountMFAEnabled: 1`; account + parent `ou-nbuj-v0s9630u` with SCPs deny-root-user + + protect-security-baseline + security-guardrails inherited. -```bash -# 1. Baseline deployed: -aws cloudformation describe-stacks --stack-name seahaven-security-baseline \ - --query 'Stacks[0].StackStatus' # expect CREATE_COMPLETE/UPDATE_COMPLETE (as 001520130573) -# 2. Root hardened (manual, Adam): MFA enabled, no root keys, alternate contacts set -aws iam get-account-summary --query 'SummaryMap.AccountMFAEnabled' # expect 1 (as 001520130573) -# 3. Account moved into the security OU (SCPs in effect): -aws organizations list-parents --child-id 001520130573 \ - --query 'Parents[0].Id' # expect ou-nbuj-v0s9630u -``` +Verification evidence (2026-07-14): -Delegation is then applied via CLI from the **management account** (all calls -idempotent): +- `organizations list-delegated-administrators` → `001520130573` (all five + service principals registered). +- GuardDuty: `AutoEnableOrganizationMembers: ALL`; members 328440206208 + + 396287094661 both `Enabled`. +- Security Hub: org auto-enable on; both members `Enabled`. +- Org Access Analyzer `seahaven-org-analyzer` created; Config org aggregator + `seahaven-org-aggregator` (AllAwsRegions) on the Config SLR; Inspector2 + auto-enable ec2/ecr/lambda + both members associated. +- **Findings flow verified end-to-end:** GuardDuty sample findings created in + member 396287094661 were listed and fully readable from the admin detector + in 001520130573 (`Recon:EC2/PortProbeUnprotectedPort`, AccountId + 396287094661, sample=true), then archived. + +The delegation runbook (all calls idempotent, run from the **management +account**): ```bash # GuardDuty: delegate + auto-enable all org members (adopts existing detectors)