View a markdown version of this page

V1.4.0 and later - Automated Security Response on AWS

V1.4.0 and later

Stack deployment

  1. Remove the automated-security-response-member.template from each member account.

  2. Remove the automated-security-response-admin.template from the admin account.

StackSet deployment

For each StackSet, remove stacks, then remove the StackSet in the reverse order of deployment.

Note that IAM roles from the automated-security-response-member-roles.template are retained even if the template is removed. This is so that remediations using these roles continue to function. These SO0111-* roles can be manually removed after verifying that they are no longer in use by active remediations, such as CloudTrail to CloudWatch logging, or RDS Enhanced Monitoring.