mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 06:53:17 +00:00
- H-1: 15 CIS Section 4 metric filters (4.1-4.15) on the CloudTrail log group, each alarming to a new SSE SNS topic seahaven-cis-alarms (email to adam). ALARM-only actions per Sea Haven preference. 4.16 = Security Hub (Day 1). - H-14: VPC flow logs (ALL traffic) on all 5 VPCs → hardened S3 bucket. Delivery bucket policy cross-reviewed; kept the AWS-required s3:x-amz-acl condition + logs:*:* source-ARN (cross-reviewer wrongly flagged these; verified against AWS flow-logs-s3-permissions docs), dropped the unneeded s3:ListBucket. - M-13: SES configuration set seahaven-email-events capturing bounce/complaint/ reject to CloudWatch for reputation visibility. L-4 (log retention) and L-5 (alarm action) applied via CLI, documented in README. |
||
|---|---|---|
| .. | ||
| account-baseline-stack.ts | ||
| backup-offsite-stack.ts | ||
| backup-stack.ts | ||
| cis-monitoring.ts | ||
| detective-controls.ts | ||
| flow-logs.ts | ||
| governance-toggles.ts | ||
| ses-monitoring.ts | ||