Asterrr's Handbook

Central security and logging

Collecting audit logs, findings and compliance data from every account and Region into dedicated security accounts, and making the logs tamper-proof.

Exam tasks: 1.2 (prescribe security controls, centralized logging and auditing), 1.4 (design a multi-account environment)

The decision: where do logs and findings from hundreds of accounts land, who administers the security services, and how do you prove nobody changed the evidence?

The target architecture

Two accounts in a Security OU do the work. Neither runs workloads.

  • Log archive account: owns the S3 buckets that receive CloudTrail, Config and other logs. Almost nobody can sign in, and nothing can delete.
  • Security tooling (audit) account: the delegated administrator for GuardDuty, Security Hub, Config, Inspector, Access Analyzer, Macie and Security Lake. The security team works here, not in the management account.

Which service answers which question

QuestionServiceOrganization-wide setup
Who called which API, when, from where?CloudTrailOrganization trail from the management account or a CloudTrail delegated admin
Is anything behaving maliciously right now?GuardDutyDelegated admin, auto-enable for new accounts, per Region
What did this resource look like last Tuesday, and is it compliant?AWS ConfigOrganization rules and conformance packs, plus an aggregator
Are we following FSBP, CIS or PCI DSS?Security Hub CSPMDelegated admin with central configuration policies
Which workloads have known CVEs?Amazon InspectorDelegated admin, auto-enable EC2, ECR and Lambda scanning
Who outside the organization can reach this resource?IAM Access AnalyzerAnalyzer with the organization as the zone of trust
Where's the sensitive data in S3?Amazon MacieDelegated admin, automated discovery
Can we query years of security logs in one place?Security LakeDelegated admin, rollup Region, OCSF in S3

Detective vs compliance vs threat

Config records state and compliance ("is encryption on?"). GuardDuty detects threats ("an instance is talking to a crypto-mining pool"). CloudTrail records actions ("who turned encryption off?"). Match the verb in the question to the service.

CloudTrail organization trail

  • Create it once in the management account, or in a delegated administrator account for CloudTrail. It applies to every current and future member account.
  • Member accounts can see the trail but can't stop, modify or delete it.
  • Make it a multi-Region trail so a new Region or an attacker's favourite unused Region is still logged.
  • Deliver to a bucket in the log archive account. The bucket policy lets cloudtrail.amazonaws.com write, scoped with aws:SourceArn to the trail. Encrypt with a KMS key whose policy allows CloudTrail to use it.
  • Turn on log file integrity validation. CloudTrail writes signed digest files every hour so you can prove a log file wasn't changed or deleted after delivery.
  • Management events are logged by default. Data events (S3 object reads, Lambda invokes, DynamoDB items) must be selected explicitly and cost extra.
  • CloudTrail Lake stores events in an organization event data store you query with SQL, as an alternative to building Athena tables over the bucket.
90 days
Event history for management events, per account and Region, with no trail at all.
1 hour
Interval at which integrity digest files are delivered.
Per Region
GuardDuty, Security Hub CSPM, Config and Inspector are Regional. Enable them in every Region you use, or deny unused Regions with an SCP.
Compliance mode
The only S3 Object Lock mode that even the root user can't bypass.

Integrity validation isn't immutability

Digest files detect tampering. They don't prevent someone with bucket permissions from deleting logs. To prevent deletion, you need S3 Object Lock, a restrictive bucket policy and an SCP that stops anyone from changing either.

Making logs immutable

ControlWhat it stops
S3 Object Lock, compliance modeAny delete or overwrite of a locked object version before the retention date, by anyone, root included
S3 Object Lock, governance modeDeletes by most users. Principals with s3:BypassGovernanceRetention can still remove objects
Legal holdDeletion with no expiry date, until the hold is removed
Bucket policy denying s3:DeleteObject and policy changesAccidental or casual deletes by admins in the log archive account
SCP on the Security OUAnyone disabling CloudTrail, GuardDuty or Config, or editing the log bucket's policy
Separate accountA compromised workload account reaching its own audit trail
  • Object Lock needs versioning. You can enable it on new buckets and on existing ones.
  • Pair it with lifecycle rules that move old logs to S3 Glacier storage classes. Retention still applies after the transition.

Security Hub and GuardDuty at scale

  • Delegated administrator. Designate the security tooling account from the management account. It then enables the service for members and sees all their findings.
  • Auto-enable new accounts that join the organization, so coverage doesn't depend on someone remembering.
  • Cross-Region aggregation. Security Hub links Regions to one home Region, so analysts see every Region's findings in one console and one EventBridge stream.
  • Central configuration policies in Security Hub CSPM decide which standards and controls are on for each OU.
  • Security Hub CSPM controls depend on AWS Config recording in each account and Region.
  • GuardDuty reads CloudTrail, VPC Flow Logs and DNS query logs directly. You don't need to turn those logs on for GuardDuty. Add protection plans (S3, EKS, Runtime Monitoring, Malware Protection, RDS, Lambda) as needed.

Security Hub naming in 2026

The original posture-checking service is now called AWS Security Hub CSPM and uses ASFF findings. The newer AWS Security Hub correlates signals from Security Hub CSPM, GuardDuty, Inspector and Macie into prioritized exposures, using OCSF. Exam questions mostly describe the aggregation behaviour, which both share.

AWS Config across the organization

  • Organization Config rules and organization conformance packs are deployed from the management account or a delegated admin, and members can't delete them.
  • A conformance pack is a bundle of rules and remediations, such as the operational best practices for PCI DSS, deployed as one unit.
  • Remediation uses Systems Manager Automation documents, run automatically or on demand.
  • An aggregator gives a read-only, multi-account, multi-Region view of configuration and compliance. Advanced queries run SQL-like queries against it ("every unencrypted EBS volume in the org").

Aggregators don't enforce

An aggregator only collects. It doesn't deploy rules, record resources or fix anything. If a question asks to apply a rule everywhere, the answer is organization rules or conformance packs, not an aggregator.

Other org-wide detectors

  • IAM Access Analyzer: with the organization as the zone of trust, it flags S3 buckets, KMS keys, IAM roles, queues, secrets and other resources that are shared outside the org. Unused access analyzers find stale roles, keys and permissions. Policy validation and policy generation from CloudTrail help write least-privilege policies.
  • Amazon Inspector: continuous vulnerability scanning of EC2 instances (through the SSM agent or agentless snapshots), ECR container images and Lambda functions. Findings flow into Security Hub.
  • Amazon Security Lake: normalizes CloudTrail, VPC Flow Logs, Route 53 Resolver logs, Security Hub findings, EKS audit logs, WAF logs and custom sources into OCSF in Apache Parquet in S3. Contributing Regions roll up into a rollup Region. Subscribers get either data access (S3 plus notifications) or query access (through Lake Formation and Athena).

Exam signal

"Security team wants a single place to query logs from all accounts with a standard schema, and to share it with a third-party SIEM" points to Security Lake. "Just store CloudTrail centrally" is an organization trail.

Central notifications with EventBridge

GuardDuty, Security Hub, Config and Inspector publish findings as events to the default event bus of the account and Region where they're generated. Two patterns route them centrally:

  1. Use the aggregation you already have. The delegated admin account's Security Hub home Region receives all findings, so one EventBridge rule there covers the organization.
  2. Cross-account event bus. Member accounts have a rule whose target is a custom bus in the security account. The bus's resource policy allows events:PutEvents from the organization with an aws:PrincipalOrgID condition, so new accounts work without editing the policy.

From the central bus, fan out to SNS, a chat channel, a ticketing system or a Lambda function that isolates the resource. See auto-remediation for response patterns and observability for application logs and CloudWatch cross-account views.

Scenarios

Scenario
Lumen Freight has 140 AWS accounts in AWS Organizations. Auditors require that API activity from every account is retained for 7 years, that no one, including administrators in any account, can delete or alter the logs during that time, and that new accounts are covered automatically. Which solution meets these requirements?
Scenario · choose 2
A security team wants one place to see GuardDuty and Security Hub findings from 60 accounts across 6 Regions, and wants a Lambda function to open a ticket for every HIGH severity finding. The team must not use the management account for daily work. Which TWO actions should the architect take?
Scenario
A company must ensure that every account in its Workloads OU has encrypted EBS volumes, that noncompliant volumes are reported, and that members can't remove the check. Which approach requires the LEAST ongoing effort?

Further reading

On this page