Glossary

    AWS Organizations

    Compliance & Governance

    AWS Organizations lets you centrally manage and govern multiple AWS accounts. It's the foundation for multi-account security architecture.

    Key Features

    • Organizational Units (OUs): hierarchical grouping of accounts (e.g., Production, Development, Security, Sandbox)
    • Service Control Policies (SCPs): organization-wide permission guardrails that restrict what member accounts can do
    • Consolidated Billing: single payment method for all accounts with volume discounts
    • Delegated Administrator: designate member accounts to manage specific services (Security Hub, GuardDuty, Macie)
    • Tag Policies: enforce consistent tagging across all accounts
    • AI Services Opt-out Policies: control whether AWS AI services can store your data for improvement

    Multi-Account Strategy

    • Management Account: only for Organizations management, not workloads
    • Security Account: centralized security services (GuardDuty, Security Hub, log archive)
    • Log Archive Account: centralized, immutable logging (CloudTrail, Config)
    • Network Account: shared networking (Transit Gateway, VPN, Direct Connect)
    • Workload Accounts: separate accounts per environment/application

    Related AWS Services

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.