Configures Security Hub with default standards enabled across all regions.

Terraform Template

resource "aws_securityhub_configuration_policy" "example" {

  configuration_policy {
    enabled_standard_arns = ["arn:aws:securityhub:us-east-1::standards/aws-foundational-security-best-practices/v/1.0.0", "arn:aws:securityhub:::ruleset/cis-aws-foundations-benchmark/v/1.2.0"]
    service_enabled = true
  }
  depends_on = ["aws_securityhub_organization_configuration.example"]
  description = "This is an example configuration policy"
  name = "Example"
}

resource "aws_securityhub_finding_aggregator" "example" {
  linking_mode = "ALL_REGIONS"
}

resource "aws_securityhub_organization_configuration" "example" {
  auto_enable = false
  auto_enable_standards = "NONE"
  depends_on = ["aws_securityhub_finding_aggregator.example"]

  organization_configuration {
    configuration_type = "CENTRAL"
  }
}