Managing administrator and member accounts - Amazon Security Hub
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

Managing administrator and member accounts

If your Amazon environment has multiple accounts, you can treat the accounts that use Amazon Security Hub as member accounts and associate them with a single administrator account. The administrator can monitor your overall security posture and take allowed actions on member accounts. The administrator can also perform various account management and administration tasks at scale, such as monitoring estimated usage costs and assessing account quotas.

You can associate member accounts with an administrator in two ways, by integrating Security Hub with Amazon Organizations or by manually sending and accepting membership invitations in Security Hub.

Managing accounts with Amazon Organizations

Amazon Organizations is a global account management service that lets Amazon administrators to consolidate and manage multiple Amazon Web Services accounts. It provides account management and consolidated billing features that are designed to support budgetary, security, and compliance needs. It's offered at no additional charge, and it integrates with multiple Amazon Web Services, including Amazon Security Hub, Amazon Macie, and Amazon GuardDuty. For more information, see the Amazon Organizations User Guide.

When you integrate Security Hub and Amazon Organizations, the Organizations management account designates a Security Hub delegated administrator. Security Hub is automatically enabled in the delegated administrator account in the Amazon Web Services Region in which it was designated.

After designating a delegated administrator, we recommend managing accounts in Security Hub with central configuration. This is the most efficient way to customize Security Hub and ensure adequate security coverage for your organization.

Central configuration lets the delegated administrator customize Security Hub across multiple organization accounts and Regions rather than configuring Region-by-Region. You can create a configuration policy for your entire organization, or create different configuration policies for different accounts and OUs. The policies specify whether Security Hub is enabled or disabled in associated accounts and which security standards and controls are enabled.

The delegated administrator can designate accounts as centrally managed or self-managed. Centrally managed accounts are configurable only by the delegated administrator. Self-managed accounts can specify their own settings.

If you don't opt in to central configuration, the delegated administrator has a more limited ability to configure Security Hub, called local configuration. Under local configuration, the delegated administrator can automatically enable Security Hub and default security standards in new organization accounts in the current Region. However, existing accounts don't use these settings, so configuration drift can occur after an account joins the organization.

Aside from these new account settings, local configuration is account-specific and Region-specific. Each organization account must configure the Security Hub service, standards, and controls separately in each Region. Local configuration also doesn't support the use of configuration policies.

Managing accounts manually by invitation

You must manually manage member accounts by invitation in Security Hub if you have a standalone account or if you don't integrate with Organizations. A standalone account can't integrate with Organizations, so it's necessary to manage it manually. We recommend integrating with Amazon Organizations and using central configuration if you add additional accounts in the future.

When you use manual account management, you designate an account to be the Security Hub administrator. The administrator account can view data in member accounts and take certain actions on member account findings. The Security Hub administrator invites other accounts to be member accounts, and the administrator-member relationship is established when a prospective member account accepts the invitation.

Manual account management doesn't support the use of configuration policies. Without configuration policies, the administrator can't centrally customize Security Hub by configuring variable settings for different accounts. Instead, each organization account must enable and configure Security Hub for itself separately in each Region. This can make it more difficult and time consuming to ensure adequate security coverage across all of the accounts and Regions in which you use Security Hub. It can also cause configuration drift as member accounts can specify their own settings without input from the administrator.

To manage accounts by invitation, see Managing accounts by invitation.