Instiq
Chapter 6 · Management and Security Governance·v2.0.0·Updated 6/5/2026·~11 min

What's changed: Deepened SCS-C02 Chapter 6 (added comparison tables, scenarios, FAQs, exam traps, deep-dive paragraphs to each section; localized figures to Japanese)

6.1Multi-Account Security Governance

Key points

Understand org-scale governance—AWS Organizations/SCP, Control Tower, delegated administrators, central log/security accounts, and Firewall Manager. Enforce consistent guardrails across accounts.

Security at scale comes from org-level governance. Use Organizations and SCPs to impose guardrails and separate accounts by role.

6.1.1Organizational security governance

Diagram of multi-account security governance: AWS Organizations nests accounts into OUs, with SCPs (permission ceilings, preventive guardrails); Control Tower builds a landing zone and guardrails automatically; GuardDuty/Security Hub/Config managed org-wide via a delegated administrator (a dedicated security account); logs aggregated into a dedicated log-archive account; and Firewall Manager applies WAF/SG rules across the organization.
Multi-account security governance
  • Organizations/SCP: impose preventive guardrails (permission ceilings) on OU hierarchy (e.g., region restriction).
  • Control Tower: auto-build landing zone and guardrails for standardization.
  • Delegated admin/dedicated accounts: manage GuardDuty/Security Hub/Config from a dedicated security account.
  • Firewall Manager: apply WAF/Shield/SG rules org-wide.
Exam point

Common on SCS-C02: preventive guardrail = SCP (permission ceiling, not a grant), landing-zone automation = Control Tower, org-wide security service management = delegated administrator (dedicated account), logs to a dedicated log account. An SCP is effective only with both IAM allow AND SCP allow.

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.