Flip delegation runbook to applied with verification evidence (#48)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run

All five services delegated to seahaven-security 2026-07-14 after the
hard preconditions verified (root MFA, OU placement, baseline live).
Member adoption and central findings flow verified end-to-end with a
sample finding; evidence recorded inline per SEC-BASE-A.
This commit is contained in:
Adam Moussa 2026-07-14 15:53:42 -04:00 • committed by GitHub
parent 18f0f40e74
commit 2d3ba94140
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -246,31 +246,33 @@ aws ce update-cost-allocation-tags-status --cost-allocation-tags-status \
### Delegated security administration (Phase 3, no CloudFormation resource)
Account **seahaven-security (001520130573)** will be the org's delegated
administrator for the detective services. **STATUS: PENDING — delegation has
NOT been applied yet.** Flip this section to "applied" (with verification
output) only in the commit that accompanies actual execution.
Account **seahaven-security (001520130573)** is the org's delegated
administrator for the detective services. **STATUS: APPLIED 2026-07-14,
verified** (see evidence below). The hard preconditions were enforced before
the first delegation call (security review SEC-BASE-B/D — never delegate to an
account with unhardened root or before its baseline stack exists):
HARD PRECONDITIONS — do not run the first `enable-organization-admin-account`
call until ALL of these verify true (security review SEC-BASE-B/D: delegating
to an account with unhardened root and no SCPs hands the org's detection
nerve center to the weakest credential; delegating before the baseline deploy
wedges the stack CREATE on the auto-created detector/hub, and the retry
collides with the orphaned RETAIN fixed-name buckets):
- Baseline stack `UPDATE_COMPLETE`; root `AccountMFAEnabled: 1`; account
parent `ou-nbuj-v0s9630u` with SCPs deny-root-user +
protect-security-baseline + security-guardrails inherited.
```bash
# 1. Baseline deployed:
aws cloudformation describe-stacks --stack-name seahaven-security-baseline \
--query 'Stacks[0].StackStatus' # expect CREATE_COMPLETE/UPDATE_COMPLETE (as 001520130573)
# 2. Root hardened (manual, Adam): MFA enabled, no root keys, alternate contacts set
aws iam get-account-summary --query 'SummaryMap.AccountMFAEnabled' # expect 1 (as 001520130573)
# 3. Account moved into the security OU (SCPs in effect):
aws organizations list-parents --child-id 001520130573 \
--query 'Parents[0].Id' # expect ou-nbuj-v0s9630u
```
Verification evidence (2026-07-14):
Delegation is then applied via CLI from the **management account** (all calls
idempotent):
- `organizations list-delegated-administrators` → `001520130573` (all five
service principals registered).
- GuardDuty: `AutoEnableOrganizationMembers: ALL`; members 328440206208 +
396287094661 both `Enabled`.
- Security Hub: org auto-enable on; both members `Enabled`.
- Org Access Analyzer `seahaven-org-analyzer` created; Config org aggregator
`seahaven-org-aggregator` (AllAwsRegions) on the Config SLR; Inspector2
auto-enable ec2/ecr/lambda + both members associated.
- **Findings flow verified end-to-end:** GuardDuty sample findings created in
member 396287094661 were listed and fully readable from the admin detector
in 001520130573 (`Recon:EC2/PortProbeUnprotectedPort`, AccountId
396287094661, sample=true), then archived.
The delegation runbook (all calls idempotent, run from the **management
account**):
```bash
# GuardDuty: delegate + auto-enable all org members (adopts existing detectors)