Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Monitor root user activity in MP accounts #7825

Closed
3 of 4 tasks
richgreen-moj opened this issue Sep 2, 2024 · 3 comments
Closed
3 of 4 tasks

Monitor root user activity in MP accounts #7825

richgreen-moj opened this issue Sep 2, 2024 · 3 comments
Assignees

Comments

@richgreen-moj
Copy link
Contributor

richgreen-moj commented Sep 2, 2024

User Story

As a MP engineer
I want to be alerted to when the AWS account root user is being used
So that I know that it is only used for genuine purposes (and there are no security breaches)

Value / Purpose

This is a follow-on from #7437 which looked at alerting for admin role usage and more generally the NCSC recommendations on mitigating the risk of an attacker gaining unauthorised access to code and production environments.

It may need to be looked at after this more general ticket that investigates how we will be looking after the root account/codebase... #7824

Useful Contacts

No response

Additional Information

No response

Definition of Done

  • Identify best solution for alerting and where to alert
  • Deploy solution
  • Update documentation
  • Reviewed by another team member
@SimonPPledger
Copy link
Contributor

#7824 is now complete

@richgreen-moj
Copy link
Contributor Author

PR #8654 has enabled monitoring/alerting for root account usage across all MP accounts. The PR explains in detail what has been enabled including links to examples of root account usage alerts being triggered.

I don't think there is any need to update any particular documentation for this change.

Over time we should review the amount of traffic being sent to the low priority alarms channel from member accounts and look to act on any issues or see if we need to tweak the alarm configuration etc.

@richgreen-moj richgreen-moj moved this from In Progress to For Review in Modernisation Platform Dec 4, 2024
@Kudzai-moj
Copy link
Contributor

everything looks good to me. Moving to done

@Kudzai-moj Kudzai-moj moved this from For Review to Done in Modernisation Platform Dec 5, 2024
@Kudzai-moj Kudzai-moj closed this as completed by moving to Done in Modernisation Platform Dec 5, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: Done
Development

No branches or pull requests

4 participants