Automated Workflows
Automating Security Hub Workflows¶
Automating workflows in AWS Security Hub enables proactive enforcement of security policies, real-time response to threats, and consistent compliance across cloud environments. By integrating Security Hub with AWS services like CloudFormation (Infrastructure as Code) and Lambda (serverless functions), you can create self-healing architectures and automate remediation actions. This section demonstrates how to design and implement these workflows.
## Automating with CloudFormation¶
CloudFormation allows you to define and deploy infrastructure as code, ensuring Security Hub configurations are version-controlled and repeatable. You can use it to create Security Hub rules, custom actions, and integrations with other AWS services.
Example: CloudFormation Template for Security Hub Rule¶
# securityhub-rule.yaml
AWSTemplateFormatVersion: '2010-09-09'
Resources:
MySecurityHubRule:
Type: AWS::SecurityHub::Rule
Properties:
Name: "UnrestrictedS3Bucket"
Description: "Detects S3 buckets without encryption or public access."
Scope:
Resources:
- Type: "AWS::S3::Bucket"
Criteria:
Resource:
Type: "AWS
Configuration:
PublicAccessBlockConfiguration:
BlockPublicAcls: false
BlockPublicPolicyAcls: false
IgnorePublicAcls: false
RestrictPublicBuckets: false
Commands:
# Deploy the template
aws cloudformation create-stack \
--stack-name securityhub-rule-stack \
--template-body file://securityhub-rule.yaml \
--capabilities CAPABILITY_NAMED_IAM
This rule detects S3 buckets with public access and triggers alerts in Security Hub.
## Automating with Lambda¶
Lambda functions can automate responses to Security Hub findings, such as tagging resources, updating configurations, or triggering notifications. Pair Lambda with EventBridge to listen for Security Hub findings and execute actions in real time.
Example: Lambda Function for Finding Remediation¶
# remediate_finding.py
import json
import boto3
def lambda_handler(event, context):
client = boto3.client('ec2')
findings = json.loads(event['body'])['findings']
for finding in findings:
resource_arn = finding['resources'][0]['resourceId']
if 'ec2:SecurityGroup' in resource_arn:
# Example: Add a rule to a security group
client.authorize_security_group_ingress(
GroupId=resource_arn.split('/')[-1],
IpPermissions=[
{
'IpProtocol': '-1',
'IpRanges': [{'CidrIp': '0.0.0.0/0'}],
'UserIdGroupPairs': []
}
]
)
return {'statusCode': 200, 'body': 'Remediation completed'}
Commands:
# Create Lambda function
aws lambda create-function \
--function-name SecurityHubRemediation \
--runtime python3.9 \
--role arn:aws:iam::123456789012:role/lambda-role \
--handler remediate_finding.lambda_handler \
--zip-file fileb://remediate_finding.zip
Note: This example demonstrates a simplified remediation scenario. In production, ensure ingress rules are restricted to trusted IP ranges to avoid security risks.
## Integrating with EventBridge¶
Use EventBridge to route Security Hub findings to Lambda or other services. For example, create a rule that triggers a Lambda function when a new finding is published.
Example EventBridge Rule:
{
"name": "SecurityHubFindingsRule",
"source": "aws.securityhub",
"detail-type": ["Security Finding"],
"targets": [
{
"arn": "arn:aws:lambda:region:account-id:function:SecurityHubRemediation",
"id": "RemediationTarget"
}
]
}
## Diagram of Workflow¶
graph TD
A[Security Hub Findings] --> B[EventBridge]
B --> C[Lambda Function]
C --> D[Remediation Action (e.g., tagging, configuration update)]
C --> E[CloudFormation Stack Update]
This workflow demonstrates how Security Hub findings trigger automated remediation via Lambda and infrastructure updates via CloudFormation.
Key takeaways¶
- CloudFormation ensures Security Hub configurations are version-controlled and repeatable.
- Lambda enables real-time remediation of findings, such as updating security groups or tagging resources.
- EventBridge acts as the glue between Security Hub and automation services, enabling scalable, event-driven workflows.
- Combine these tools to enforce security policies consistently within AWS environments.