AWS Certified Solutions Architect – ProfessionalContinuously Improve Existing SolutionsEasy

A global media company uses AWS Organizations to manage multiple accounts. They want to enforce consistent security policies across all accounts, such as requiring encryption for S3 buckets and preventing public access to resources, without manually configuring each account. They also need to ensure that new accounts automatically inherit these policies. Which AWS service combination should be used to achieve this?

  1. AIAM roles and policies applied to each account.
  2. BAWS Security Hub with custom insights.
  3. CService Control Policies (SCPs) in AWS Organizations.
  4. DAWS Config rules deployed via AWS CloudFormation StackSets.
Show answer & explanation

Correct answer: C. Service Control Policies (SCPs) in AWS Organizations.

Service Control Policies (SCPs) in AWS Organizations allow you to centrally manage permissions for all accounts in your organization. They are guardrails that define the maximum available permissions for accounts, effectively preventing actions like disabling encryption or allowing public access, and are automatically applied to new accounts within the OU.

Why the other options are wrong

  • A. IAM roles and policies are account-level permission controls. Manually applying them to each account and ensuring consistency across a growing organization is exactly what SCPs are designed to avoid.
  • B. AWS Security Hub aggregates findings and provides security posture visibility. It identifies issues but does not prevent non-compliant actions from occurring.
  • D. AWS Config rules can detect non-compliant resources, but they don't prevent actions from happening. While CloudFormation StackSets can deploy Config rules across accounts, SCPs are preventative and more suitable for enforcing 'preventative guardrails' at the organizational level.

Service Control Policies (SCPs)

Service Control Policies (SCPs) are a type of organization policy that you can use to manage permissions in your organization. SCPs offer central control over the maximum available permissions for all accounts in your organization.

  • Apply to all IAM users and roles in affected accounts.
  • Do not grant permissions directly; they filter permissions.
  • Preventative guardrails: block actions at the organizational level.
  • Automatically apply to new accounts added to an OU/Organization.

Memory trick: SCPs are the security 'Sentinels' for your AWS Organization, always watching and enforcing.

More Continuously Improve Existing Solutions questions