Guard Duty with Security Hub

0

trying to understand relationship between security hub and guard duty in aws organisation sub account

If GuardDuty is enabled on organisation member account B and security hub is enabled on organisation master/delegated admin account A than will the master account A recieve findings from account B even if we don't enable guard duty in master account?

2 個答案
1
已接受的答案

If Security Hub and GuardDuty are enabled in the same account then Security Hub will receive the GD findings for that account and then send all findings to Security Hub in the delegated admin account for that region. Enabling GuardDuty on all accounts and in all regions is recommended best practice however - there is no cost if there are no workloads or activity in that account and if something WAS to happen then at least you would know about it. In addition it make it so much easier to manage and view all GD findings in a single account. Is there a reason for not enabling GD in your management/delegated admin account? (Note: we recommend making the delegated admin account the same for ALL security services like GD, SH, Inspector, Macie, Detective etc)

profile pictureAWS
已回答 2 年前
0

Yes, I have tried it in my environment.

You can receive findings from member account B without enabling GaurdDuty on management/delegated admin account A.

profile picture
hayao-k
已回答 2 年前

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南