Upgrade to Pro — share decks privately, control downloads, hide ads and more …

AWS Landing Zone

Will
December 15, 2022

AWS Landing Zone

Powerpoint presentation for User Group discussing:

What is a landing Zone?
What are the benefits?
When should you use it?

Will

December 15, 2022
Tweet

More Decks by Will

Other Decks in Technology

Transcript

  1. Getting Started with AWS Landing Zones The key to manage

    and govern AWS accounts at scale Will Chalmers (he/him) Solutions Architect
  2. • The path to multiple AWS accounts • Where does

    a landing zone fit in? • AWS Multi-Account Strategy • Control Tower & Organizations Agenda
  3. You need a ‘Landing Zone’ • A configured, secure, scalable,

    multi-account AWS environment based on AWS Frameworks and best practices. • A starting point for new clients/projects/migrations/development & experimentation • An environment that allows for iteration and expansion over time
  4. AWS Organizations Provides tools to centrally govern and manage AWS

    Accounts • Quickly scale by creating accounts and allocate resources • Customize environments by applying governance policies • Secure and audit environments • Manage costs and identify cost-saving measures
  5. Guardrail examples Guardrail Type Requirement Enable MFA for the Root

    User Detective Strongly Recommended Disallow public read access to S3 Detective Strongly Recommended Enable AWS Config in All Available Regions Preventive Mandatory Disallow Policy Changes to Log Archive Preventive Mandatory Integrate CloudTrail Events with CloudWatch Logs Preventive Mandatory Disallow Amazon S3 Buckets That Are Not Versioning Enabled Detective Elective Disallow Delete Actions on Amazon S3 Buckets Without MFA Detective Elective