Manage findings in Security Hub - AWS Prescriptive Guidance

Manage findings in Security Hub

You can build a cloud-based notification system for Security Hub findings by using Amazon EventBridge rules and Amazon Simple Notification Service (Amazon SNS) topics. This system notifies the appropriate team about a finding when it is created. For this approach, the multi-account strategy described in Develop an AWS account structure is critical because applications are separated into dedicated accounts. This helps you notify the correct teams for each finding.

Security or cloud teams might choose to receive events from all AWS accounts. In this case, build an EventBridge rule within the Security Hub delegated administrator account and subscribe an Amazon SNS topic that notifies these teams. For application teams, configure an EventBridge rule and SNS topic within their respective application accounts. When a Security Hub finding occurs within an application account, the responsible team is notified about the finding.

Security Hub already automatically sends all new findings and all updates to existing findings to EventBridge as Security Hub Findings - Imported events. Each Security Hub Findings - Imported event contains a single finding. You can apply filters on EventBridge rules so that a finding initiates the rule only if the finding matches the filters. For instructions, see Configuring an EventBridge rule for automatically sent findings. For more information about creating and subscribing Amazon SNS topics, see Configuring Amazon SNS.

Consider the following when using this approach:

  • For application teams, create EventBridge rules within each AWS account and AWS Region where the application is hosted.

  • For security and cloud teams, create EventBridge rules in the Security Hub delegated administrator account. This notifies teams about all findings in the member accounts.

  • Amazon SNS sends a notification each day if the status of the security finding is NEW. If you want to turn off the daily notifications, you can create a custom AWS Lambda function that changes the status of the finding from NEW to NOTIFIED after the Amazon SNS subscriber receives the notification.