Home icon

AWS Control Tower Landing Zone updates managed policies and controls

News



The article discusses updates to AWS Control Tower's Landing Zone, which is a well-architected, multi-account AWS environment based on security and compliance best practices.

Specifically, the article covers:

  • Introduction of a new IAM global condition key, aws:SourceOrgID, enabling AWS services to access resources only on behalf of the organization or OU
  • Example use case of using aws:SourceOrgID with S3 bucket policies to ensure CloudTrail logs can only be written by accounts within the organization
  • A new version of the Region Deny control and improved KMS drift reporting
  • Availability of AWS Control Tower in different AWS Regions and references to release notes and IAM documentation


Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.