Skip to main content

Scheduled Service Change: AWS Security Events Framework Resource Cleanup

Event:
2026-01-26 08:00:00
Expected Duration:
2026-01-26 16:00:00
Status:
Closed
Brief Description:
Resources in Cornell AWS accounts that support the original Cornell AWS Security Events framework will be removed. (More information in the full description.)
User Impact:
N/A
Services Affected:
Servers & Cloud Infrastructure
Subsites Affected:
Cloudification
Full Description:
Resources in Cornell AWS accounts that support the original Cornell AWS Security Events framework will be removed. This functionality has been migrated to a centralized deployment that no longer requires resources within individual Cornell AWS accounts. 

Within each AWS region, the following resources will be removed from Cornell AWS accounts: 

  • EventBridge Rules with the following names: 
    • Cornell-Standard-Security-Event-Console-Signin-v1.1.2 
    • Cornell-Standard-Security-Event-Exposed-Access-Key-v1.1.2
    • Cornell-Standard-Security-Event-Root-API-Activity-v1.1.2 
  • CloudFormation stacks that deployed the resources named above. The target stacks have names following the pattern StackSet-Cornell-Standard-Security-Event-Rules-main-*. 
Globally, the IAM Role with name Cornell-Standard-Security-Event-Action-Role-v1.1.2 will be removed.

For more details see this Confluence page (login required).

CIT TDX ID:
2093553



Timeline of Changes

Description Current Status Date Time
Resources in Cornell AWS accounts that support the original Cornell AWS Security Events framework will be removed. This functionality has been migrated to a centralized deployment that no longer requires resources within individual Cornell AWS accounts. 

Within each AWS region, the following resources will be removed from Cornell AWS accounts: 

  • EventBridge Rules with the following names: 
    • Cornell-Standard-Security-Event-Console-Signin-v1.1.2 
    • Cornell-Standard-Security-Event-Exposed-Access-Key-v1.1.2
    • Cornell-Standard-Security-Event-Root-API-Activity-v1.1.2 
  • CloudFormation stacks that deployed the resources named above. The target stacks have names following the pattern StackSet-Cornell-Standard-Security-Event-Rules-main-*. 
Globally, the IAM Role with name Cornell-Standard-Security-Event-Action-Role-v1.1.2 will be removed.

For more details see this Confluence page (login required).

2026-01-15 10:44:45