Building blocks
Design goal
Give security teams one place to detect, investigate, and govern risk across the AWS Organization while keeping workload accounts independently owned.
Architecture
A dedicated security account receives delegated administration and aggregated findings while CloudTrail and configuration/audit data are centralized according to the organization security model.
Architecture decisions
Use dedicated security ownership
WhySeparate security administration from workload administration.
Trade-offA dedicated security function improves separation of duties but adds delegated-administration, access-review, and operating-process overhead.
Centralize findings, not every workload action
WhyAggregate posture and threat signals centrally while keeping account-level boundaries intact.
Trade-offCentral visibility preserves account autonomy, but incident response still depends on clear ownership and coordinated action in workload accounts.
Security
Protect the control and data paths deliberately. Use least-privilege delegated administrator roles, organization policies, protected log archives, encryption, and restricted write access to security data.
Availability
Design for the failure domain that must be survived. Use regional aggregation and operational alerting based on the services and regions in scope.
Disaster recovery
Treat regional recovery as a separate operating state. Ensure critical audit logs and security findings are retained independently of compromised workload accounts; document regional service dependencies.
Cost drivers
- Security Hub controls
- GuardDuty analyzed events/data
- CloudTrail data events
- Config items
- S3 log retention
Design assumptions
- AWS Organizations is available
- Security and log archive accounts are defined
Implementation plan
- Define dedicated security and log-archive responsibilities before delegating any organization-wide security service.
- Enable supported security services across the intended Organizational Units and delegate administration to the security account.
- Route audit logs and security findings to destinations that workload accounts cannot modify or delete.
- Define triage ownership, notification paths, and the boundary between central security actions and workload-team remediation.
- Onboard a pilot member account and verify that findings, logs, permissions, and response workflows behave as designed.
Validate the design
- Generate a representative member-account finding and confirm it appears in the central security account.
- Verify workload administrators cannot alter or delete protected audit data.
- Test notification and triage routing from detection through assignment to the expected owner.
- Onboard a new member account and confirm required detectors, standards, and logging are applied automatically.