Missing alarm for AWS Organizations changes

Without a CloudWatch filter and alarm for AWS Organizations changes, changes to organizational permissions may go unnoticed for longer.

Description

AWS Organizations supports sensitive administrative actions such as inviting accounts, attaching policies, creating organizational units and moving accounts. Without connecting relevant CloudTrail events to CloudWatch alarms, changes to the organization or its permissions can be discovered late.

In an environment with multiple accounts and organizational units, these changes can affect permission boundaries. Monitor the required events and notify the responsible team.

Potential impact

  • Important changes to organizational policies or account placement can be discovered late.
  • Assessing the effects of account structure changes can take longer.
  • Initial responses to permission misuse or configuration mistakes can be delayed.

Remediation

  • Deliver the required Organizations events from CloudTrail to CloudWatch Logs and configure a log metric filter.
  • Connect the emitted metric name and namespace to an alarm, and set its evaluation period and threshold. Configure an operational notification channel such as SNS and its recipient subscriptions.
  • Use test events that satisfy the alarm conditions to verify metric creation and notification delivery. Log delivery and alarm evaluation can introduce delays.

Examples

Configure the referenced log group and SNS topic, CloudTrail delivery permissions and notification subscriptions separately. The filter below includes selected Organizations events; extend it to meet the organization's monitoring requirements.

Before

hcl
resource "aws_cloudwatch_log_metric_filter" "organizations_changes" {
  name           = "organizations-changes"
  log_group_name = aws_cloudwatch_log_group.cloudtrail.name
  pattern        = "{ ($.eventSource = \"ec2.amazonaws.com\") }"

  metric_transformation {
    name      = "organizations-changes"
    namespace = "Security"
    value     = "1"
  }
}

After

hcl
resource "aws_cloudwatch_log_metric_filter" "organizations_changes" {
  name           = "organizations-changes"
  log_group_name = aws_cloudwatch_log_group.cloudtrail.name
  pattern        = "{ ($.eventSource = \"organizations.amazonaws.com\") && (($.eventName = AcceptHandshake) || ($.eventName = AttachPolicy) || ($.eventName = CreateAccount) || ($.eventName = MoveAccount) || ($.eventName = RemoveAccountFromOrganization)) }"

  metric_transformation {
    name      = "organizations-changes"
    namespace = "Security"
    value     = "1"
  }
}

resource "aws_cloudwatch_metric_alarm" "organizations_changes" {
  alarm_name          = "organizations-changes"
  comparison_operator = "GreaterThanOrEqualToThreshold"
  evaluation_periods  = 1
  metric_name         = "organizations-changes"
  namespace           = "Security"
  period              = 300
  statistic           = "Sum"
  threshold           = 1
  alarm_actions       = [aws_sns_topic.security_alerts.arn]
}

Explanation:

  • Before: The filter selects EC2 events and has no associated Organizations alarm.
  • After: Selected Organizations events produce a metric, with an alarm configured for a five-minute sum of at least one. Actual notifications depend on log delivery, alarm state and the SNS delivery path.

References