Glossary

    Multi-Account Strategy

    Compliance & Governance

    A Multi-Account Strategy uses separate AWS accounts as security and billing boundaries. Each account isolates its resources, IAM principals, and network from other accounts. This is the strongest isolation mechanism in AWS - stronger than VPCs, subnets, or IAM policies.

    Common Account Structure

    • Management account: Organizations root, billing, SCPs (no workloads)
    • Security account: centralized GuardDuty, Security Hub, CloudTrail
    • Log archive account: centralized, immutable log storage
    • Network account: Transit Gateway, shared VPCs, DNS
    • Workload accounts: separate per environment (dev, staging, prod) or per team
    • Sandbox accounts: experimentation with tight guardrails

    Related AWS Services

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.