Centrally deploy and manage AWS accounts
Use organization design, delegated administration, account vending, shared services, and centrally governed security capabilities.
- Lesson
- d6-lesson
- Practice pool
- d6-questions
- Application
- scs-l01, scs-l05
Apply repeatable account governance, secure deployment, compliance evidence, policy enforcement, delegated administration, and exception handling.
Use organization design, delegated administration, account vending, shared services, and centrally governed security capabilities.
Turn security requirements into versioned infrastructure, preventive controls, drift detection, exception workflows, and automated remediation.
Map requirements to controls and evidence, evaluate scope and inheritance, preserve auditability, and remediate gaps proportionately.
Effective governance connects a requirement to ownership, a preventive or directive mechanism, detection of deviation, evidence, an exception path, remediation, and periodic improvement. A dashboard without an owner is not governance; a policy without enforcement or evidence is only intent.
Use AWS Organizations, OUs, account vending, shared services, log archives, security accounts, delegated administration, organization policies, and identity federation to create explicit boundaries. Avoid placing every function in one account or granting the management account routine workload access. Design for account creation, movement, closure, acquisition, exception, and incident lifecycles.
Translate security requirements into versioned infrastructure, policy-as-code, pipeline gates, approved modules, image and dependency controls, drift detection, and reversible remediation. Prevent high-confidence prohibited states and detect context-dependent risk. Keep emergency changes auditable and reconcile them back into code.
Separate requirement, scope, control objective, implementation, evidence, assessment result, exception, and remediation. Use AWS Artifact for provider reports where relevant and services such as Config, Security Hub, Audit Manager, logs, and deployment records for customer-side evidence. A passing automated rule may prove only one configuration predicate.
Trace one control from a regulatory requirement through account creation, preventive deployment, continuous evaluation, evidence retention, exception approval, and closure.