Implementing Multi-Account Governance with AWS Organizations and Control Tower

ADVANCED
180 minutes
5 tasks

In this lab, you will build a governance framework using AWS Organizations and AWS Control Tower to manage multiple AWS accounts effectively. You'll create organizational units (OUs), apply service control policies (SCPs), and set up a control tower with guardrails in place. This exercise will guide you through the complexities of multi-account setups including creating policies that align with real-world constraints like budget and compliance. The goal is to ensure that you can manage AWS resources at scale in a secure and efficient manner. This advanced scenario will help you understand the intricacies of setting up AWS environments tailored to enterprise needs, considering both security and cost efficiency to align with best practices.

Scenario

Your company, a large financial services firm, has recently decided to migrate its IT infrastructure to AWS. The company is structured into multiple departments, each requiring its own AWS account due to different regulatory and operational requirements. Your task is to set up a governance framework using AWS Organizations and Control Tower to manage these multiple accounts. The objective is to ensure compliance across the board and optimize for cost and security. The firm has a strict budget of $5,000 monthly per department for cloud expenses and a response time SLA of 99.9% operational uptime for critical applications.

Learning Objectives

  • Set up a multi-account structure using AWS Organizations.
  • Implement governance using AWS Control Tower guardrails.
  • Apply service control policies for cost management and compliance.
  • Understand and implement AWS security best practices in a multi-account environment.

tasks (5)

task 1: Create a new AWS Organization.

20 min

task 2: Create organizational units and attach service control policies (SCPs).

30 min

task 3: Setup AWS Control Tower and implement guardrails.

40 min

task 4: Implement advanced security practices with AWS IAM Identity Center.

30 min

task 5: Enforce centralized logging and monitoring using AWS CloudTrail and CloudWatch.

60 min

Prerequisites

  • Basic understanding of AWS Organizations and Control Tower concepts.
  • Knowledge of IAM Identity Center and its use cases.
  • Familiarity with CloudTrail and CloudWatch for logging and monitoring.

Skills Tested

Implement multi-account governance using AWS Organizations.Configuring AWS Control Tower for centralized control.Setting up AWS IAM Identity Center for secure access management.Centralizing logging and monitoring with CloudTrail and CloudWatch.
    Implementing Multi-Account Governance with AWS Organizations and Control Tower - Hands-On Lab - CertiPass