AWS notifications: Clarify org notification recipients for AWS Health events
Summary
Rewords the AWS Organizations integration to apply specifically to AWS Health managed notifications and states that on a member-account event the management account, delegated administrator accounts, and the member account all receive the notification.
Security assessment
Describes notification delivery/visibility semantics across organization accounts (relevant to audit visibility) but documents no security feature, control, or fixed weakness.
Evidence
+When an event occurs in a member account, the management account, delegated administrator accounts, and the member account all receive an AWS Health managed notification.
Diff
diff --git a/notifications/latest/userguide/uno-orgs.md b/notifications/latest/userguide/uno-orgs.md index 6868da252..8483afd3b 100644 --- a//notifications/latest/userguide/uno-orgs.md +++ b//notifications/latest/userguide/uno-orgs.md @@ -46 +46 @@ Configuring notifications for organization accounts creates read-only notificati -User Notifications uses AWS Organizations in accounts that enable AWS managed notifications and aggregation and deduplication to: +For AWS Health managed notifications, User Notifications uses AWS Organizations to: @@ -57 +57 @@ For example, if management and member accounts within the same organization shar -If management and member accounts within the same organization both enable AWS managed notifications and an event occurs in a member account, both the management and member account receive a notification. However, if an event occurs in a member account and only the management account enabled AWS managed notifications, only the management account receives a notification. +When an event occurs in a member account, the management account, delegated administrator accounts, and the member account all receive an AWS Health managed notification.