Glossary

    Resource Tagging

    Compliance & Governance

    Resource Tagging is the practice of labeling AWS resources with key-value metadata. Tags are fundamental to security governance at scale.

    Security Use Cases

    • Attribute-Based Access Control (ABAC): IAM policies that grant/deny access based on tags (e.g., aws:ResourceTag/Environment = Production)
    • Cost Allocation: track security spending by team, project, or compliance requirement
    • Compliance Scoping: tag resources as PCI=true or HIPAA=true for audit
    • Automation: target patching, backup, and remediation based on tags
    • Ownership: identify who owns and is responsible for each resource

    Enforcement

    • Tag Policies: enforce tag keys and allowed values across AWS Organizations
    • SCPs: deny resource creation without required tags
    • Config Rules: detect resources missing required tags
    • Service Catalog: enforce tags at provisioning time

    Related AWS Services

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.