A Service Control Policy (SCP) is a policy type in AWS Organizations that sets the maximum permissions for member accounts. SCPs do not grant permissions - they restrict what permissions are available. Even if an IAM policy in a member account says "Allow": "ec2:*", an SCP can prevent that account from launching instances in certain regions.
guardduty:DeleteDetector, config:StopConfigurationRecorders3:PutObject without s3:x-amz-server-side-encryptions3:PutBucketPolicy with public principalA JSON document that defines permissions - which actions are allowed or denied on which AWS resources, and under what conditions.
An advanced IAM feature that sets the maximum permissions an IAM entity can have, acting as a ceiling on what identity-based policies can grant.
The security principle of granting only the minimum permissions needed to perform a task - no more, no less.
A preventive or detective control that enforces security boundaries across AWS accounts, implemented through SCPs, AWS Config rules, or Security Hub standards.
Using multiple AWS accounts to isolate workloads, environments, and teams, providing the strongest security boundary available in AWS.
Toc Consulting: AWS Security & Cloud Architecture
Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.