A DevOps engineer must apply a core set of security controls to an existing collection of AWS accounts. The accounts belong to an organization in AWS Organizations. Individual teams will manage individual accounts by using the AdministratorAccess AWS managed policy. AWS CloudTrail and AWS Config must be enabled in every available AWS Region for all accounts. Individual account administrators must not be able to modify or delete any baseline resources. However, those administrators must be able to modify or delete their own CloudTrail trails and AWS Config rules.
Which solution meets these requirements in the MOST operationally efficient manner?
Community Discussion
No comments yet. Be the first to start the discussion!
Community Discussion