Guide · AWS Security Hub · Setup

AWS Security Hub for MCP Servers — Finding Aggregation, Standards, Integrations

AWS Security Hub is a regional service that collects security findings from GuardDuty, Inspector, Macie, IAM Access Analyzer, Firewall Manager, and third-party tools, normalizes them into the AWS Security Finding Format (ASFF), and presents a unified view with compliance scoring against CIS, PCI DSS, and AWS best-practice standards. For MCP server operators the critical setup detail is to pass --no-enable-default-standards when enabling Security Hub — the default behavior automatically enables CIS AWS Foundations Benchmark v1.2, which generates hundreds of Config rule evaluations and charges per evaluation. Decide which standards you actually need before enabling. A second common mistake is enabling Security Hub without first enabling GuardDuty — Security Hub can aggregate GuardDuty findings, but only if GuardDuty is already running; enabling Hub does not retroactively pull historical GuardDuty findings from before the integration was activated.

TL;DR

Enable Security Hub with --no-enable-default-standards, then deliberately choose which compliance standards to run. Wire GuardDuty, Inspector, and IAM Access Analyzer integrations. Enable cross-region aggregation if your MCP infrastructure spans multiple AWS regions. See the findings API guide for ASFF format and BatchImportFindings, the compliance standards guide for CIS/PCI/FSBP control details, the automation rules guide for automated finding triage, and the cross-account guide for Organizations-based multi-account setup.

Enable Security Hub

Security Hub is enabled per-account per-region. There is no single global switch. If your MCP servers run in three AWS regions, you must enable Security Hub in each region to get findings from that region's services.

# Enable Security Hub WITHOUT default standards (recommended)
# Default behavior auto-enables CIS v1.2 (200+ Config rules) — skip it unless you want that
aws securityhub enable-security-hub \
  --no-enable-default-standards \
  --tags "Environment=production,Service=mcp-platform"

# Verify Hub is enabled and check configuration
aws securityhub describe-hub
# Output includes:
#   HubArn: arn:aws:securityhub:us-east-1:123456789012:hub/default
#   SubscribedAt: 2026-10-08T10:00:00Z
#   AutoEnableControls: true (controls auto-enabled when new ones added to subscribed standards)
#   ControlFindingGenerator: SECURITY_CONTROL (recommended — deduplicates findings across standards)

# Set ControlFindingGenerator to SECURITY_CONTROL if not already set
# This generates one finding per control per resource instead of one per standard per resource
# Critical for accounts subscribed to multiple overlapping standards
aws securityhub update-security-hub-configuration \
  --control-finding-generator SECURITY_CONTROL

The ControlFindingGenerator setting is the most important configuration decision after enabling. With SECURITY_CONTROL mode, if a single EC2 misconfiguration is flagged by both FSBP and CIS, you receive one finding (the control finding) rather than two separate standard-specific findings. This reduces finding volume by 30–60% in accounts subscribed to multiple standards. The only reason to use the legacy STANDARD_CONTROL mode is if you have automation that depends on the old finding IDs — new deployments should always use SECURITY_CONTROL.

# Check current Security Hub configuration
aws securityhub describe-hub \
  --query '{HubArn:HubArn,AutoEnableControls:AutoEnableControls,ControlFindingGenerator:ControlFindingGenerator}'

# List all Security Hub subscriptions in this region
aws securityhub list-enabled-standards

# Disable Security Hub if needed (deletes all findings — irreversible per region)
# This is a destructive operation — all findings are permanently deleted
# aws securityhub disable-security-hub

Integrations: enabling finding sources

Security Hub supports native AWS integrations and third-party partner integrations. Native AWS integrations (GuardDuty, Inspector, Macie, IAM Access Analyzer, Firewall Manager) are enabled separately from Security Hub itself — enabling Security Hub does not automatically start receiving their findings.

# List all available product integrations (native AWS + partner)
aws securityhub describe-products \
  --query 'Products[?CompanyName==`Amazon`].{Name:ProductName,Arn:ProductArn}'

# Key native AWS integration ARNs (us-east-1):
# GuardDuty:          arn:aws:securityhub:us-east-1::product/aws/guardduty
# Inspector v2:       arn:aws:securityhub:us-east-1::product/aws/inspector
# Macie:              arn:aws:securityhub:us-east-1::product/aws/macie
# IAM Access Analyzer: arn:aws:securityhub:us-east-1::product/aws/access-analyzer
# Firewall Manager:   arn:aws:securityhub:us-east-1::product/aws/firewall-manager
# Security Lake:      arn:aws:securityhub:us-east-1::product/aws/security-lake

# Enable GuardDuty integration (most critical for MCP server threat detection)
aws securityhub enable-import-findings-for-product \
  --product-subscription-arn "arn:aws:securityhub:us-east-1::product/aws/guardduty"

# Enable Inspector v2 (vulnerability scanning for container images, EC2 AMIs, Lambda packages)
aws securityhub enable-import-findings-for-product \
  --product-subscription-arn "arn:aws:securityhub:us-east-1::product/aws/inspector"

# Enable IAM Access Analyzer (cross-account access, unused permissions findings)
aws securityhub enable-import-findings-for-product \
  --product-subscription-arn "arn:aws:securityhub:us-east-1::product/aws/access-analyzer"

# List all currently enabled product integrations
aws securityhub list-enabled-products-for-import

GuardDuty is the highest-value integration for MCP server operators — it surfaces threat-detection findings (compromised credentials, C&C activity, crypto mining) alongside the compliance findings from standards. Inspector v2 covers container image vulnerabilities in ECR (if your MCP servers deploy as Docker images) and Lambda function package scanning. IAM Access Analyzer surfaces overly-permissive resource policies — critical if your MCP server uses S3 buckets or KMS keys accessible from external accounts.

IntegrationFinding types for MCP opsPrerequisiteAuto-send to Hub
GuardDutyThreat findings (InstanceCredentialExfiltration, C&CActivity, CryptoCurrency)GuardDuty detector enabled in same regionYes — no extra config in GuardDuty
Inspector v2CVE findings for ECR images, Lambda packages, EC2 AMIsInspector v2 enabledYes — auto-sends on finding creation
MacieSensitive data in S3 buckets (secrets in config files, env vars in logs)Macie enabled with S3 scanning jobs configuredYes — sends policy and classification findings
IAM Access AnalyzerExternal access to S3 buckets, KMS keys, Lambda functionsAnalyzer created in same regionYes — sends on finding generation
Firewall ManagerWAF rule compliance, Network Firewall policy violationsOrganizations + Firewall Manager admin accountYes — sends policy non-compliance findings

Cross-region aggregation

If your MCP servers run in multiple AWS regions, enable finding aggregation to funnel all regional findings into a single home region. Without aggregation, you must check Security Hub in each region separately — there is no global view by default.

# Create a finding aggregator in your home region (the region where you want all findings)
# This is a one-time setup — run in the region you want as the aggregation target
aws securityhub create-finding-aggregator \
  --linking-mode ALL_REGIONS

# Output: {"FindingAggregatorArn": "arn:aws:securityhub:us-east-1:123456789012:finding-aggregator/abcd1234"}

# Verify aggregation status — LinkedRegions should list all active regions
aws securityhub get-finding-aggregator \
  --finding-aggregator-arn "arn:aws:securityhub:us-east-1:123456789012:finding-aggregator/abcd1234"

# If you only want specific regions (not all):
aws securityhub create-finding-aggregator \
  --linking-mode SPECIFIED_REGIONS \
  --regions us-east-1 us-west-2 eu-west-1

# Update aggregation config to add new regions later
aws securityhub update-finding-aggregator \
  --finding-aggregator-arn "arn:aws:securityhub:us-east-1:123456789012:finding-aggregator/abcd1234" \
  --linking-mode ALL_REGIONS_EXCEPT_SPECIFIED \
  --regions ap-east-1 ap-southeast-3

Cross-region aggregation replicates findings to the home region but does not delete them from source regions. Findings updated in the home region propagate back to the source region within a few minutes. Aggregation adds a small delay (typically under 2 minutes) for findings from linked regions to appear in the home region. The home region change takes effect immediately but may cause a brief gap in finding aggregation — plan any home region changes during low-activity periods.

Pricing model

Security Hub pricing has two components: finding ingestion and compliance check evaluations. Understanding both is essential before enabling all standards and integrations.

ComponentFree tierPaid rateMCP impact
Finding ingestion (from AWS services)10,000 findings/month per account/region$0.00003/finding after free tierLow for most MCP deployments; GuardDuty + Inspector generate hundreds/month, not thousands
Custom finding ingestion (BatchImportFindings)10,000 findings/month per account/region (shared with above)$0.00003/findingRelevant if you build a custom ASFF integrator for MCP server health events
Config rule evaluations (standards)First 100,000/month free for 30 days$0.0008/evaluation/month after free tierEach CIS/FSBP/PCI control runs as a Config rule — 100 controls × 50 resources = 5,000 evaluations/month
Automation rulesIncludedNo additional chargeFree regardless of how many rules or findings they process
# Estimate your monthly finding volume before committing
# Count GuardDuty findings in the past 30 days
aws guardduty list-findings \
  --detector-id <detector-id> \
  --finding-criteria '{
    "Criterion": {
      "updatedAt": {
        "Gte": 1727740800000
      }
    }
  }' \
  --query 'length(FindingIds)'

# Count Security Hub findings currently active
aws securityhub get-findings \
  --filters '{"WorkflowStatus":[{"Value":"NEW","Comparison":"EQUALS"}]}' \
  --query 'length(Findings)'

Failure modes reference

FailureSymptomFix
No GuardDuty findings appearing in Security HubGuardDuty has active findings; Security Hub shows zero from GuardDutyGuardDuty integration not enabled; run enable-import-findings-for-product with GuardDuty product ARN
Default standards generating unexpected Config chargesAWS bill shows unexpected Config rule evaluation charges within hours of enablingCIS v1.2 auto-enabled by default; disable with batch-disable-standards or re-enable Hub with --no-enable-default-standards
Cross-region findings not appearing in home regionFindings visible in us-west-2 but not in us-east-1 aggregation regionSecurity Hub not enabled in us-west-2; Hub must be enabled in each linked region before aggregation works
Duplicate findings for same control violationSame S3 misconfiguration appears twice — once for FSBP, once for CISControlFindingGenerator set to STANDARD_CONTROL (legacy); update to SECURITY_CONTROL via update-security-hub-configuration
Inspector findings not appearingECR image vulnerabilities visible in Inspector console but absent from Security HubInspector integration not enabled in Security Hub; enable-import-findings-for-product with Inspector product ARN
enable-security-hub returns AlreadyExistsExceptionRunning enable-security-hub failsHub already enabled in this region/account; use describe-hub to verify existing configuration