mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 06:53:17 +00:00
* Add seahaven-dev member baseline with org-managed detection Account 710827005802 (internal dev/staging) is the first account born after delegation: GuardDuty/Security Hub enroll it via the org admin, so DetectiveControls gains a localDetectiveServices flag (default true — zero diff on the three deployed consumers, verified) and the dev instance sets orgManagedDetection to skip the colliding local detector/hub/analyzer. Default VPC kept and flow-logged (dev runs real workloads). Enrollment verified Enabled in both services before this commit. * Fix Phase-4 review findings: standards + analyzer stay CFN-owned SH-DEV-001: org AutoEnableStandards DEFAULT gave dev legacy CIS v1.2.0 and nothing owned CIS v3.0 — org config set to NONE, standards are now unconditional in DetectiveControls (attach fine to an org-enabled hub), legacy ruleset disabled in dev. SH-DEVBASE-002: the ORGANIZATION analyzer treats the whole org as trusted so it cannot flag intra-org exposure — account analyzer restored unconditionally (coexistence verified live). Enrollment comments corrected: manual create-members, the automatic sweep is still unexercised. Zero diff re-verified on all three deployed baseline stacks. |
||
|---|---|---|
| .. | ||
| scp | ||
| account-baseline-stack.ts | ||
| backup-offsite-stack.ts | ||
| backup-stack.ts | ||
| bedrock-logging-regional.ts | ||
| bedrock-logging.ts | ||
| cis-monitoring.ts | ||
| detective-controls.ts | ||
| dynamodb-cmk-stack.ts | ||
| flow-logs.ts | ||
| governance-toggles.ts | ||
| logs-key.ts | ||
| member-baseline-stack.ts | ||
| org-governance-stack.ts | ||
| regional-baseline-stack.ts | ||
| ses-monitoring.ts | ||
| web-acl.ts | ||