Multi-region CloudTrail with log-file validation, a rotating KMS CMK, an Object-Lock'd S3 log bucket, and CloudWatch Logs delivery. First resident of the account-level security baseline; AWS Backup / 3-2-1 (C-7) lands alongside. IAM/KMS/S3 policies cross-reviewed; review caught a missing CloudTrail KMS grant, now added (SourceArn + encryption-context scoped). |
||
|---|---|---|
| .github | ||
| bin | ||
| lib | ||
| .gitignore | ||
| cdk.json | ||
| package-lock.json | ||
| package.json | ||
| README.md | ||
| tsconfig.json | ||
seahaven-account-baseline
Account-level security and governance baseline for Sea Haven Industries (AWS account 328440206208, region us-east-1), managed as a single CDK TypeScript app. This is where account-wide detective controls live, so they are versioned, reviewed, and drift-checked like any other stack.
What it deploys
CloudTrail (audit finding C-1)
| Resource | Logical ID | Notes |
|---|---|---|
| Multi-region trail | Trail (seahaven-org-trail) |
Management events read+write, global service events, log-file validation on |
| Log bucket | TrailLogBucket (seahaven-cloudtrail-logs-328440206208) |
Private (Block Public Access all), SSE-KMS, versioned, TLS-only, Object Lock GOVERNANCE 365d, lifecycle (Glacier @90d, expire @365d), server access logging → seahaven-s3-access-logs |
| KMS CMK | TrailKey (alias/cloudtrail-logs) |
Encrypts log files; automatic rotation enabled |
| CloudWatch Logs group | created by the L2 Trail |
365-day retention; this is the group the CIS Section 4 metric filters (H-1) attach to |
Data flow: API activity across all regions → CloudTrail → (a) KMS-encrypted, Object-Locked S3 bucket for durable/tamper-resistant storage and (b) CloudWatch Logs for real-time querying and metric-filter alarms.
Compliance impact: closes CIS 3.1 (multi-region trail), 3.2 (log-file validation), 3.4 (CloudWatch Logs integration), 3.6 (bucket access logging), 3.7 (KMS CMK encryption), and 3.8 (CMK rotation). Unblocks CIS Section 4 / finding H-1 (metric filters + alarms now have a log group to target).
Design decisions
- Management events only. Object-level S3/Lambda data events (CIS 3.10/3.11) are deferred to control cost; revisit with targeted S3 write data events on sensitive buckets (payments / accounting / kb) if needed.
- Object Lock GOVERNANCE, not COMPLIANCE. Tamper-resistant but still
deletable by a principal holding
s3:BypassGovernanceRetention— avoids the irreversibility of COMPLIANCE mode. Revisit if a stricter posture is required. - RETAIN on the bucket and KMS key so a stack teardown never destroys the audit trail.
Roadmap (same stack)
Account-level detective controls with no current home, to be added here: AWS Config (H-2), GuardDuty (H-3), Security Hub (H-4), IAM Access Analyzer (M-5), Inspector2 (M-6).
Deploy
CI/CD via the org reusable workflows (ci-typescript-cdk.yaml,
cd-cdk.yaml); pushes to main deploy through the OIDC role in
secrets.AWS_DEPLOY_ROLE_ARN. Local: npm ci && npm run build && npx cdk diff.
npx cdk deploy seahaven-account-baseline
Verify
aws cloudtrail get-trail-status --name seahaven-org-trail # IsLogging: true
aws cloudtrail describe-trails --trail-name-list seahaven-org-trail
aws cloudtrail validate-logs --trail-arn <arn> --start-time <t> # digest integrity