Glossary

    Landing Zone

    Architecture & Design

    A Landing Zone is a well-architected, multi-account AWS environment that serves as the starting point for deploying workloads. It establishes the foundational security, networking, and governance controls.

    Core Components

    • Account Structure: OUs for Security, Infrastructure, Workloads, Sandbox
    • Identity: centralized access via IAM Identity Center, federated from corporate IdP
    • Networking: hub-and-spoke VPC architecture with Transit Gateway, shared services
    • Logging: centralized CloudTrail, Config, VPC Flow Logs in a dedicated Log Archive account
    • Security: GuardDuty, Security Hub, IAM Access Analyzer enabled in all accounts
    • Guardrails: SCPs, Config Rules, and preventive controls

    Implementation Options

    • AWS Control Tower: managed landing zone setup with Account Factory
    • Custom: Terraform/CDK-based landing zone for more control
    • AWS Landing Zone Solution: legacy AWS-provided solution (superseded by Control Tower)

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.