Glossary

    AWS Control Tower

    Compliance & Governance

    AWS Control Tower provides an automated way to set up and govern a secure, multi-account AWS environment called a landing zone. It implements AWS best practices for account structure, identity, logging, and compliance.

    What It Sets Up

    • Landing Zone: pre-configured multi-account environment with baseline security
    • Account Factory: automated provisioning of new accounts with consistent configuration
    • Guardrails (Controls): preventive (SCPs), detective (Config Rules), and proactive (CloudFormation hooks)
    • Dashboard: centralized view of compliance across all accounts

    Built-in Security

    • Centralized CloudTrail logging to a protected Log Archive account
    • Cross-account audit access via an Audit account
    • Mandatory guardrails: disallow public S3 access, require EBS encryption, enforce CloudTrail
    • IAM Identity Center integration for centralized access management

    When to Use It

    • New AWS environments - start with Control Tower from day one
    • Existing environments - Control Tower can enroll existing accounts and OUs
    • Regulated industries - built-in compliance guardrails for PCI DSS, HIPAA, NIST

    Related AWS Services

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.