cisagov / crossfeed

External monitoring for organization assets
https://docs.crossfeed.cyber.dhs.gov
Creative Commons Zero v1.0 Universal
372 stars 54 forks source link

Create log metric filter and alarm for root user access. #2321

Closed Matthew-Grayson closed 1 year ago

Matthew-Grayson commented 1 year ago

πŸ—£ Description

Create log metric filter for CloudWatch.1 to monitor use of AWS root account. Create alarm for CloudWatch.1 with action set as SNS topic. Create SNS topic to aggregate all CloudWatch control alarms.

πŸ’­ Motivation and context

Address 1 of 14 AWS CloudWatch controls CloudWatch.1 flagged by AWS security hub.

πŸ§ͺ Testing

βœ… Pre-approval checklist

βœ… Pre-merge checklist

βœ… Post-merge checklist