Governance Services Flashcards
Maintain control over cost, compliance, and security across AWS accounts
Governance Services
Centrally manage multiple AWS accounts under one umbrella.
Organizations
Allows for a group of multiple accounts, and a single payment for all accounts
Organizations
Used to enforce permissions you want everyone in the organization to follow
SCP - Service Control Policies
Grouping of AWS accounts that are similar
Organization Units (OU)
Account group by departmental area (IT, Shared Services, Marketing)
Marketing Organization Unit
Standard individual accounts that contain your AWS resources
Shared Services Accounts
Receive one bill for multiple AWS accounts
Consolidated Billing
Receive volume discounts since usage is combined across accounts
Cost Savings
A quick and automated way to create accounts or invite existing accounts
Account Governance
Save money using Reserved Instance sharing, which allows accounts in the organization to receive the hourly cost-benefit of RI purchased by any other account
Organizations
Ensure new and old accounts conform to company-wide policies by workign directly with AWS Organizations
Control Tower
Govern multi-account environment by enabling cross-account security audits or preventing/detecting security issues through mandatory or optional guardrails
Control Tower
Visibility and control over AWS resources
Systems Manager
Group resources and automate operational tasks on them
Systems Manager
Patch and run commands on multiple EC2 instances or manage RDS instances
Systems Manager
Deploy operating system and software patches automatically across a large group of instances
Systems Manager
Real-time guidance to help you provision your resources following AWS best practices
Trusted Advisor
Helps you understand best practices, and see service limits
Trusted Advisor
Checks your account and makes recommendations
Trusted Advisor
Checks for unrestricted access for specific ports on EC2 instances
Trusted Advisor
Checks S3 bucket permissions to determine if public access
Trusted Advisor
Checks for MFA on the root account
Trusted Advisor
Checks IAM password policy with business or enterprise plan
Trusted Advisor
Checks for RDS public snapshots
Trusted Advisor
Checks service usage greater than 80% over service limit with business or enterprise plan
Trusted Advisor
Checks for exposed access keys with business or enterprise plan
Trusted Advisor
Checks for CloudFront content delivery optimization with business or enterprise plan
Trusted Advisor
Manage software licenses
License Manager
Helps provision and manage SSL/TLS certificates
Certificate Manager