Lunker - Gone Fishing!

blog.lukach.io

Amazon Cloud

GitHub Profile

December 16, 2025

ClickOps #10 - Use Security Hub CSPM as Event Bus

by John Lukach

I like to use Security Hub CSPM as a security event bus to centralize alerts from multiple accounts and regions to a single location.

enable security hub

First, delegate administration to a new Security Hub account before enabling it in the management account.

initial security hub

Security Hub is notorious for automatically enabling security standards that I prefer to be disabled by default. AWS Config is a dependency for security standards evaluations.

delegated administrator

I also shut off the auto-enablement of new security controls.

security hub configureation

Start Centralized Configuration

security hub configureation

security hub configureation

security hub configureation

security hub configureation

security hub configureation

security hub configureation

If you receive any errors, you will likely need to remove the centralized configuration policy and the delegated administrator before re-applying.

security hub error

security hub error

tags: aws - security - hub - alerts