Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Enable AWS Organisations integration to link root account with Cortex XSIAM #7897

Closed
6 tasks done
richgreen-moj opened this issue Sep 11, 2024 · 6 comments
Closed
6 tasks done
Assignees
Labels

Comments

@richgreen-moj
Copy link
Contributor

richgreen-moj commented Sep 11, 2024

User Story

As a SOC engineer
I want to enrich the information in security alerts in Cortex XSIAM
So that I have more detailed information e.g. can identify which application/owner is affected

Value / Purpose

Following some engagement with the SOC in #7605 it was decided that we should explore using the AWS Organisations Integration to link the root account (MOJ Master) with Cortex XSIAM as the SOC feel this would better enrich the info in the alerts they are getting for AWS accounts.

Useful Contacts

@ashwinmoj @richgreen-moj @davidkelliott

Additional Information

For more context contact Ashwin John ashwinmoj

This will also require input from the root account team #aws-root-account in slack

Definition of Done

  • Review docs and best way to enable the integration
  • Decide on appropriate permissions to be given
  • Create relevant infra in the root account (user/roles etc.)
  • Work with SOC/Ashwin to enable the integration in Cortex Xsiam (handover credentials)
  • Verify that the SOC are able to query the API through the integration
  • Update any documentation as required
@richgreen-moj richgreen-moj changed the title Enable AWS Organisations integration to link root account with Cortex Xsiam Enable AWS Organisations integration to link root account with Cortex XSIAM Sep 11, 2024
@ashwinmoj
Copy link

I will be on annual leave for two weeks starting from next week and will return on September 30th. During my absence, @YasJustice/ yaasseen.aumeer@justice.gov.uk from the MIP team will be available for any assistance or inquiries related to these tickets.

@richgreen-moj richgreen-moj self-assigned this Sep 16, 2024
@richgreen-moj
Copy link
Contributor Author

Documentation has been reviewed. The guide says:
"When self hosted outside the AWS environment in a remote network, the AWS Integrations should use: Access Key and Secret Key authentication option."
As Cortex XSIAM is hosted outside of AWS we will need to follow this strategy.

@richgreen-moj
Copy link
Contributor Author

I raised Add Cortex XSOAR Integration User ministryofjustice/aws-root-account#993 to create a user with read/list only permissions to the organizations account.

I am reaching out to yaasseen.aumeer@justice.gov.uk to discuss exchanging some access keys and creating the integration in the Cortex XSOAR app.

@richgreen-moj
Copy link
Contributor Author

richgreen-moj commented Sep 19, 2024

Having created a user with relevant permissions in the moj-master account, @ewastempel generated a set of keys so that I could share them with Yaasseen.

We set up the integration over a teams call and Yaasseen tested it by querying the org. He was able to retrieve a list of all the AWS accounts in the organisation and their respective tags etc. directly in the XSIAM app 👍

I'll raise a follow-on ticket for looking at how we approach the long-term management of identities shared with the XSIAM app going forward.

@richgreen-moj
Copy link
Contributor Author

richgreen-moj commented Sep 20, 2024

Follow-on issue raised to look at long-term management of credentials https://github.com/ministryofjustice/modernisation-platform-security/issues/24

@Khatraf
Copy link
Contributor

Khatraf commented Sep 23, 2024

Reviewed – All criteria in the definition of done have been met, and user have confirmed that everything works as intended. I have verified that their access keys were used today and that they have been assigned read-only permissions to AWS Org so I'm happy to close this.

@Khatraf Khatraf closed this as completed Sep 23, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
Status: Done
Development

No branches or pull requests

4 participants