A Multi-Account Strategy uses separate AWS accounts as security and billing boundaries. Each account isolates its resources, IAM principals, and network from other accounts. This is the strongest isolation mechanism in AWS - stronger than VPCs, subnets, or IAM policies.
An organization-wide guardrail that restricts what actions member accounts can perform, regardless of their IAM policies.
A preventive or detective control that enforces security boundaries across AWS accounts, implemented through SCPs, AWS Config rules, or Security Hub standards.
Dividing a network into isolated segments (subnets, VPCs) to limit lateral movement and contain the blast radius of a security breach.
The scope of impact when a security incident occurs - how many resources, accounts, or users are affected. Smaller blast radius means better security posture.
Toc Consulting: AWS Security & Cloud Architecture
Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.