6Management and Security Governance
- 6.1Multi-Account Security Governance
Understand org-scale governance—AWS Organizations/SCP, Control Tower, delegated administrators, central log/security accounts, and Firewall Manager. Enforce consistent guardrails across accounts.
- 6.2Configuration Compliance and Auto-Remediation
Understand continuous compliance—AWS Config (rules/conformance packs), auto-remediation, Security Hub standards, Audit Manager, and Systems Manager. Continuously assess compliance and auto-fix drift.
- 6.3Operational Governance and Cost/Secret Control
Understand operational governance—tagging strategy, Trusted Advisor, cost anomaly detection, patch/config compliance, org-wide secret management, and backup policies. Balance security and operations.
- 6.4In-scope services for management and security governance
A roundup of in-scope SCS-C03 services for management and security governance.

