AWS Certified SysOps Administrator – AssociateSecurity and ComplianceMedium
A global enterprise uses multiple AWS accounts managed under AWS Organizations. The security team needs to enforce a policy that restricts all IAM users and roles in member accounts from creating or updating S3 buckets that are not configured with default encryption. This policy must apply to all new and existing accounts within the organization. Which AWS service should the security team use to implement this control?
- AIAM Identity Center (formerly AWS SSO)
- BAWS Resource Access Manager (RAM)
- CAWS Config rules with auto-remediation
- DAWS Organizations Service Control Policies (SCPs)
Show answer & explanationAnswer & explanation
Correct answer: D. AWS Organizations Service Control Policies (SCPs)
Service Control Policies (SCPs) in AWS Organizations allow you to centrally manage permissions for all accounts in your organization. They act as guardrails, setting maximum available permissions for IAM users and roles, effectively preventing member accounts from performing actions that violate the policy, such as creating unencrypted S3 buckets.
Why the other options are wrong
- A. IAM Identity Center manages access to AWS accounts and applications, but not organizational-level permissions enforcement.
- B. RAM allows sharing of AWS resources between accounts, but does not enforce permission boundaries.
- C. AWS Config rules detect non-compliance and can remediate, but SCPs provide preventative control at a higher organizational level.
AWS Organizations Service Control Policies (SCPs)
Service Control Policies (SCPs) are a type of organization policy that you can use to manage permissions in your organization. SCPs offer central control over the maximum available permissions for all accounts in your organization.
- Applied to OUs or individual accounts, not principals.
- Act as 'guardrails' for permissions.
- Do not grant permissions; they filter them.
- Inherited by child OUs and accounts.
Memory trick: SCPs are the Organization's Strict Compliance Police.