AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesEasy
A global company uses AWS Organizations to manage multiple AWS accounts. They need to enforce a security policy that prevents any AWS account within their organization from creating Amazon S3 buckets that are publicly accessible. This policy must be applied centrally and automatically to all current and future accounts. Which AWS service and feature should be used to achieve this?
- AAmazon S3 bucket policies applied to each bucket
- BAWS Organizations Service Control Policies (SCPs)
- CAWS Config rules for S3 public access
- DAWS IAM policies applied to individual accounts
Show answer & explanationAnswer & explanation
Correct answer: B. AWS Organizations Service Control Policies (SCPs)
Service Control Policies (SCPs) in AWS Organizations allow you to centrally manage permissions for all accounts in your organization. They can be used to set maximum available permissions for an account or organizational unit (OU), effectively preventing actions like creating public S3 buckets across the entire organization.
Why the other options are wrong
- A. S3 bucket policies are applied to individual buckets and would not prevent the creation of new public buckets.
- C. AWS Config rules detect non-compliance but do not prevent actions from occurring. The requirement is to prevent, not just detect.
- D. IAM policies are applied at the account level and would require manual configuration for each account, which is not scalable for a global company with multiple accounts.
AWS Organizations SCPs
Service Control Policies (SCPs) are a type of policy that you can use to manage permissions in your organization. SCPs offer central control over the maximum available permissions for all accounts in your organization.
- Applied to OUs or the root of an organization.
- Acts as a 'guardrail' or maximum permission boundary.
- Does not grant permissions, only restricts them.
Memory trick: SCPs Securely Control Permissions for Organizational Purity.