A large enterprise is adopting a multi-account strategy on AWS, with hundreds of accounts organized into an AWS Organizations structure. The security team needs to enforce a baseline set of security policies, such as disallowing public S3 buckets, requiring encryption for EBS volumes, and restricting specific IAM actions across ALL accounts, including newly created ones. These policies must be mandatory and apply to all IAM users and roles within those accounts. Which AWS feature is the MOST effective for implementing these preventative, mandatory controls at scale across the organization?
- AIAM policies attached to individual roles in each account.
- BResource-based policies on each S3 bucket and EBS volume.
- CAWS Config rules with auto-remediation enabled in each account.
- DService Control Policies (SCPs) in AWS Organizations.
Show answer & explanationAnswer & explanation
Correct answer: D. Service Control Policies (SCPs) in AWS Organizations.
Service Control Policies (SCPs) in AWS Organizations enable you to centrally manage permissions for all accounts in your organization. They act as guardrails, defining the maximum available permissions for IAM users and roles within the affected accounts, effectively blocking disallowed actions even if an IAM policy grants them. This makes them ideal for enforcing mandatory, preventative security controls across a multi-account environment.
Why the other options are wrong
- A. IAM policies are account-specific and would require manual configuration or complex automation for hundreds of accounts, and they don't prevent root user actions.
- B. Resource-based policies are specific to individual resources and cannot enforce organization-wide preventative controls for all resource types or IAM actions.
- C. AWS Config rules are detective and reactive; they identify non-compliance and can remediate, but they don't prevent actions from happening in the first place, and they would need to be deployed and managed in each account.
Service Control Policies (SCPs)
A type of organizational policy that you can use to manage permissions in your organization. SCPs offer central control over the maximum available permissions for all accounts in your organization, acting as a security guardrail.
- Apply to all IAM users and roles, including the root user.
- Preventative controls: deny actions before they happen.
- Inherited down the Organizational Unit (OU) hierarchy.
- Do not grant permissions; they filter permissions granted by IAM policies.
Memory trick: SCPs are the organizational 'security chief' that sets the ultimate limits.