SCS-C03 · D6 · 14%

Security Foundations and Governance

Apply repeatable account governance, secure deployment, compliance evidence, policy enforcement, delegated administration, and exception handling.

Provider facts checked 2026-08-03

Objective coverage

Objective 6.1 · high

Centrally deploy and manage AWS accounts

Use organization design, delegated administration, account vending, shared services, and centrally governed security capabilities.

Lesson
d6-lesson
Practice pool
d6-questions
Application
scs-l01, scs-l05
Objective 6.2 · high

Deploy resources consistently and securely

Turn security requirements into versioned infrastructure, preventive controls, drift detection, exception workflows, and automated remediation.

Lesson
d6-lesson
Practice pool
d6-questions
Application
scs-l08
Objective 6.3 · normal

Meet compliance requirements

Map requirements to controls and evidence, evaluate scope and inheritance, preserve auditability, and remediate gaps proportionately.

Lesson
d6-lesson
Practice pool
d6-questions
Application
scs-l01, scs-l08

title: "Security Foundations and Governance" summary: "Governance decisions for AWS organizations, preventive controls, assurance evidence, ownership, and exception management."

Governance is a control system

Effective governance connects a requirement to ownership, a preventive or directive mechanism, detection of deviation, evidence, an exception path, remediation, and periodic improvement. A dashboard without an owner is not governance; a policy without enforcement or evidence is only intent.

Accounts and delegated administration

Use AWS Organizations, OUs, account vending, shared services, log archives, security accounts, delegated administration, organization policies, and identity federation to create explicit boundaries. Avoid placing every function in one account or granting the management account routine workload access. Design for account creation, movement, closure, acquisition, exception, and incident lifecycles.

Secure, consistent deployment

Translate security requirements into versioned infrastructure, policy-as-code, pipeline gates, approved modules, image and dependency controls, drift detection, and reversible remediation. Prevent high-confidence prohibited states and detect context-dependent risk. Keep emergency changes auditable and reconcile them back into code.

Compliance evidence

Separate requirement, scope, control objective, implementation, evidence, assessment result, exception, and remediation. Use AWS Artifact for provider reports where relevant and services such as Config, Security Hub, Audit Manager, logs, and deployment records for customer-side evidence. A passing automated rule may prove only one configuration predicate.

Self-check

Trace one control from a regulatory requirement through account creation, preventive deployment, continuous evaluation, evidence retention, exception approval, and closure.