Organization Services
Organization Services is the home for the AWS services that Prism manages across all your AWS accounts, so you configure them once from a central place instead of account by account. Three services are available.
CloudTrail
Create and manage AWS CloudTrail trails across every account with centralized logging configuration. From CloudTrail you can:
- Create and edit organization or per-account trails.
- Choose which management, data, insight, and network-activity events to record.
- Route logs to centralized storage for audit and investigation.
Open the CloudTrail guide | Quick start: create your first trail
Security Hub
Centralize cloud security posture management, threat detection, data security, vulnerability management, and security investigation across your organization, configured from one place rather than account by account. Security Hub brings together six capabilities:
- Security Hub CSPM: evaluate every enrolled account against AWS compliance standards, with per-standard scores and a control-level drill-down.
- GuardDuty: continuous threat detection with a severity-ranked threats dashboard and per-account findings.
- AWS Config: the recording foundation that Security Hub standards depend on, provisioned and managed for you.
- Amazon Macie: S3 data-security posture and sensitive-data findings, with a bucket-posture inventory and opt-in automated sensitive-data discovery.
- Amazon Inspector: software vulnerability scanning of EC2 instances, container images, Lambda functions, and code repositories, with estate-wide CVE prioritisation.
- Amazon Detective: behavior-graph investigation of the IAM users and roles involved in a security event, with accounts joining one administrator's behavior graph by invitation.
Most of these capabilities deploy from a delegated administrator account that aggregates results from enrolled members. Amazon Inspector instead enables each account independently, with no administrator account.
Open the Security Hub guide | Quick start: enable Security Hub
Security Hub and CloudFormation StackSets are beta capabilities that CloudKeeper enables together for your organization on request. Turning on the beta makes both services available; there is no separate switch for each one.
CloudFormation StackSets
Deploy a single CloudFormation template across the accounts and regions of your organization, driven from one administration account. From the StackSets service you can:
- Create StackSets that target organizational units, with one stack instance per account and region.
- Update templates, sync targets as accounts join or leave your OUs, and retry failed instances.
- Delete deployments while choosing whether the underlying stacks are retained or destroyed.
CloudFormation StackSets is part of the same beta as Security Hub. The single Organization Services beta that CloudKeeper enables for your organization unlocks both services at once.
Who can use it
Organization Services is available to Customer Admins and to Organization Services users who have been granted access, without giving them access to the Prism Admin Portal. See Access & Organization Services Users for how access is granted.