Guard Duty with Security Hub

0

trying to understand relationship between security hub and guard duty in aws organisation sub account

If GuardDuty is enabled on organisation member account B and security hub is enabled on organisation master/delegated admin account A than will the master account A recieve findings from account B even if we don't enable guard duty in master account?

2개 답변
1
수락된 답변

If Security Hub and GuardDuty are enabled in the same account then Security Hub will receive the GD findings for that account and then send all findings to Security Hub in the delegated admin account for that region. Enabling GuardDuty on all accounts and in all regions is recommended best practice however - there is no cost if there are no workloads or activity in that account and if something WAS to happen then at least you would know about it. In addition it make it so much easier to manage and view all GD findings in a single account. Is there a reason for not enabling GD in your management/delegated admin account? (Note: we recommend making the delegated admin account the same for ALL security services like GD, SH, Inspector, Macie, Detective etc)

profile pictureAWS
답변함 2년 전
0

Yes, I have tried it in my environment.

You can receive findings from member account B without enabling GaurdDuty on management/delegated admin account A.

profile picture
hayao-k
답변함 2년 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인