More Info:

Amazon Organizations changes should be monitored using AWS CloudWatch alarms.

Risk Level

Low

Address

Security

Compliance Standards

HIPAA, HITRUST, CISAWS, CBP

Triage and Remediation

Remediation

The AWS Organizations Changes Alarm is triggered when there is a change in the AWS Organizations structure, such as adding or removing accounts, or changing the root email address. To remediate this misconfiguration, you can follow these steps:

  1. Log in to your AWS Management Console.

  2. Navigate to the CloudWatch service.

  3. Click on “Alarms” in the left-hand menu.

  4. Find the “AWS Organizations Changes Alarm” in the list of alarms.

  5. Click on the alarm to view its details.

  6. Click on the “Actions” dropdown menu and select “Disable Alarm Actions”.

  7. Click “Save” to disable the alarm.

This will stop the alarm from being triggered when there is a change in the AWS Organizations structure. However, it is important to regularly review and update your AWS Organizations structure to ensure that it is properly configured and secure.

Additional Reading: