Deploy and Configure Security Incident Response
-
Access Security Incident Response from the Management Account console
-
Choose Sign up
-
Select a security tooling account as Delegated Administrator from the Management Account.
-
Log into the delegated administrator account
-
Enter membership details and associate accounts
-
Enable proactive response
Note
Enabling proactive response creates a service-linked role allowing our CIRT to ingest GuardDuty findings and create proactive investigation cases.