This guide configures delegation for the main AWS security services to create a dedicated security account. The security account aggregates all findings and alerts from the various services to allow for centralized monitoring and response.
The guide creates two CLI scripts to be applied in the organization Management Account and the member account designated as the central Security Account. The following services are included in this guide:
GuardDuty: Signature and anomaly-based security detection in the account to alert on suspicious activity
Security Hub: Aggregates findings from various security services and enables compliance monitoring according to standards such as CIS, PCI DSS, and AWS best practices
Access Analyzer: Identifies resources in the organization that are shared with external entities
Inspector: Software vulnerability scanning for EC2 instances and ECR repositories
Macie: Automates the discovery of sensitive data on Amazon S3 buckets
Important: This guide requires a recent scan of your organization management AWS account to ensure an up-to-date view of the AWS environment, configuration, and resources
A premium subscription is required for this content
Select the organization management account which is used to delegate management of security services to the dedicated security account.
Security Account
Enter the account id for the AWS account that will be designated as the central security account. This account will be delegated the permissions to manage security services on behalf of the organization and aggregate findings across all member accounts.
AWS Regions
AWS services operate independently in each region, and so it is required that you select each region you want to enable delegation for (It is recommended to enable this in all active regions in your organization).