defsec
defsec copied to clipboard
check: Ensure a log metric filter and alarm exists for AWS Organizations changes
Provider
Severity
Short Code
Description Real-time monitoring of API calls can be achieved by directing CloudTrail Logs to CloudWatch Logs and establishing corresponding metric filters and alarms. It is recommended that a metric filter and alarm be established for AWS Organizations changes made in the master AWS Account.
Explanation Monitoring AWS Organizations changes can help you prevent any unwanted, accidental or intentional modifications that may lead to unauthorized access or other security breaches. This monitoring technique helps you to ensure that any unexpected changes performed within your AWS Organizations can be investigated and any unwanted changes can be rolled back.
Link https://docs.aws.amazon.com/organizations/latest/userguide/orgs_security_incident-response.html