# Amazon Security Lake Rollout Checklist (July 2026)

Pricing dimensions: **ingestion** + **OCSF conversion** (AWS sources) + **S3** (+ Glue/EventBridge/SQS as used). Third-party/custom source ingest has no Security Lake GB fee (you still pay S3/query). New Region/account: **15-day free trial** — disable before trial ends if not adopting.

## Org setup

- [ ] Delegated admin + Organization trail for CloudTrail management events
- [ ] Enable sources per Region (CloudTrail, VPC Flow, Route 53 Resolver, Security Hub findings, …)
- [ ] Confirm OCSF Parquet landing + Glue tables; Lake Formation grants for analysts
- [ ] S3 lifecycle / Intelligent-Tiering for cold forensics retention

## Consumers

- [ ] Athena workgroup for hunters (scan limits)
- [ ] SIEM as **subscriber** for hot correlation only — not full raw feed
- [ ] Alert on `CreateSubscriber` / `UpdateSubscriber` via CloudTrail

## Counter-case

Security Lake is not real-time SOC alerting (typically minutes of lag). Keep Security Hub / SIEM for that path.
