defsec icon indicating copy to clipboard operation
defsec copied to clipboard

check: Ensure a log metric filter and alarm exists for AWS Organizations changes

Open owenrumney opened this issue 2 years ago • 0 comments

Provider

Severity

Short Code

Description Real-time monitoring of API calls can be achieved by directing CloudTrail Logs to CloudWatch Logs and establishing corresponding metric filters and alarms. It is recommended that a metric filter and alarm be established for AWS Organizations changes made in the master AWS Account.

Explanation Monitoring AWS Organizations changes can help you prevent any unwanted, accidental or intentional modifications that may lead to unauthorized access or other security breaches. This monitoring technique helps you to ensure that any unexpected changes performed within your AWS Organizations can be investigated and any unwanted changes can be rolled back.

Link https://docs.aws.amazon.com/organizations/latest/userguide/orgs_security_incident-response.html

owenrumney avatar Aug 17 '22 10:08 owenrumney