Amazon Audit Manager Configuration
Designated administrator account name for accelerator security services. AWS organizations designate a member account as a delegated administrator for the organization users and roles from that account can perform administrative actions for security services like Macie, GuardDuty, Detective and SecurityHub. Without designated administrator account administrative tasks for security services are performed only by users or roles in the organization's management account. This helps you to separate management of the organization from management of these security services. Accelerator use Audit account as designated administrator account.
Amazon Detective Configuration
AWS Elastic Block Store default encryption configuration
Accelerator use this parameter to configure EBS default encryption. Accelerator will create KMS key for every AWS environment (account and region), which will be used as default EBS encryption key.
To enable EBS default encryption in every region accelerator implemented, you need to provide below value for this parameter.
Amazon GuardDuty Configuration
Amazon Macie Configuration
Accelerator use this parameter to define AWS Macie configuration.
To enable Macie in every region accelerator implemented and set fifteen minutes of frequency to publish updates to policy findings for the account with publishing sensitive data findings to Security Hub. you need to provide below value for this parameter.
AWS S3 public access block configuration
Accelerator use this parameter to block AWS S3 public access
To enable S3 public access blocking in every region accelerator implemented, you need to provide below value for this parameter.
AWS SecurityHub configuration
Accelerator use this parameter to define AWS SecurityHub configuration.
To enable AWS SecurityHub for all regions and enable "AWS Foundational Security Best Practices v1.0.0" security standard for IAM.1 & EC2.10 controls you need provide below value for this parameter.
AWS SNS subscription configuration
Accelerator use this parameter to define AWS SNS notification configuration.
To enable high, medium and low SNS notifications, you need to provide below value for this parameter.
AWS Systems Manager Document configuration
Accelerator use this parameter to define AWS Systems Manager documents configuration. SSM documents are created in designated administrator account for security services, i.e. Audit account.
To create a SSM document named as "SSM-ELB-Enable-Logging" in every region accelerator implemented and share this document with Root organizational unit(OU), you need to provide below value for this parameter. To share document to specific account uncomment accounts list. A valid SSM document template file ssm-documents/ssm-elb-enable-logging.yaml must be present in Accelerator config repository. Accelerator will use this template file to create the document.
Generated using TypeDoc
AWS Accelerator central security services configuration