QuestionQ39

Security Foundations and Governance

A company is operating a new workload across accounts in an AWS Organizations organization. Every running resource must have a CostCenter tag, and that tag must contain one of three approved values. The company must enforce this policy and prevent any CostCenter tag changes to a value that is not approved.

Which solution meets these requirements?

Explanation

AWS Organizations tag policies can specify the permitted values for the CostCenter tag and enforce noncompliant tagging operations, preventing requests that set the tag to an unapproved value. Because tag-policy value enforcement does not require a tag to be supplied at resource creation, an SCP using a Null condition on aws:RequestTag/CostCenter is needed to deny creation requests that omit the required tag.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!