Control Tower 1 Flashcards
Control Tower
Control Tower basic value prop?
Set up and govern multi-account environment following best practices.
Control Tower
Four basic parts of Control Tower set up?
Landing Zone, Controls, Account Factory, Dashboard
Control Tower
Why have multiple accounts?
Highest level of isolation
Control Tower
Major AWS services orchestrated by Control Tower?
Organizations, IAM (SCPs), IAM Identity Center, Service Catalog, Config
Control Tower
How much does Control Tower cost?
Nothing (but services it configures have charges)
Control Tower
Example of security bad thing without Control Tower?
No central place to control identity and access across all accounts
Control Tower
Example of cost bad thing without Control Tower?
Untagged resources aren’t costed correctly to workloads
Control Tower
Example of operational excellence bad thing without Control Tower?
No off-account, central place with comprehensive logging and auditing across accounts.
Control Tower
Example of management bad thing without Control Tower?
No central place to monitor and understand metrics across all accounts
Control Tower
What is a Landing Zone?
Multi-account environment based on security and compliance best practice.
Control Tower
What is IN a Landing Zone?
OUs, accounts, users, anything you want to be subject to compliance regulation.
Control Tower
AWS service that does LZs?
ControlTower, Landing Zone Accelerator
Control Tower
How does Control Tower create all these resources in all the accounts?
Mostly just CloudFormation
Control Tower Accounts
What is the top-level account and what does it do?
Management account – root of Org, roll-up billing goes here, owns the LZ
Control Tower Accounts
How does the Management account manage accounts?
Assumes the AWS ControlTowerExecution in each account, assumes it. Role created by Control Tower.