14.2 AWS Control Tower Landing Zone & Guardrail Framework
Key Takeaways
AWS Control Tower orchestrates AWS Organizations, IAM Identity Center, AWS Config, and AWS CloudTrail to deploy an automated, multi-account landing zone with dedicated Log Archive and Audit accounts.
Control Tower controls are categorized by behavior into Preventive (enforced synchronously via Organizations SCPs), Detective (monitored asynchronously via AWS Config and Security Hub), and Proactive (evaluated pre-provisioning via AWS CloudFormation Hooks).
Control Tower controls have three guidance levels: Mandatory (always on and can't be removed, such as disallowing changes to AWS Config and CloudTrail set up by Control Tower), Strongly Recommended, and Elective.
Account Factory leverages AWS Service Catalog to automate standardized, compliant account vending with pre-configured networking, IAM baselines, and optional extension via Account Factory for Terraform (AFT) or Customizations for Control Tower (CfCT).
Governance drift occurs when resources Control Tower manages are changed outside it, such as an enrolled account moved between OUs or a managed SCP detached; remediation is re-registering the OU, updating the account, or resetting the landing zone.
14.2 AWS Control Tower Landing Zone & Guardrail Framework
Establishing a secure, production-ready multi-account foundation requires coordinating multiple foundational services, directory integrations, and compliance mechanisms. Manually wiring together AWS Organizations, IAM Identity Center, AWS Config, and CloudTrail across dozens of accounts introduces human error and operational drift. AWS Control Tower provides an automated service wrapper that provisions and manages a compliant multi-account Landing Zone according to AWS best practices.
Landing Zone Architecture & Core Baseline
A Control Tower Landing Zone automatically configures an orchestrated organizational hierarchy with specialized core accounts, centralized identity access, and pre-configured audit trails.
Foundational Accounts in the Core OU
Control Tower sets up two foundational member accounts within a Core (or Foundational) Organizational Unit:
- Log Archive Account: Functions as the central immutable clearinghouse for organizational telemetry. It contains dedicated Amazon S3 buckets that aggregate multi-Region CloudTrail logs and AWS Config configuration history from every account in the organization. S3 Object Lock, strict bucket policies, and cross-account access restrictions prevent any single account administrator from tampering with historical audit evidence.
- Audit Account (Security Tooling Account): Serves as the operational hub for security operations center (SOC) analysts and compliance auditors. Control Tower automatically configures cross-account IAM roles granting read-only and remediation access into all member accounts from this account. It is the designated primary target for Delegated Administration of centralized security services.
Account Factory: Standardized Automated Account Vending
Account proliferation without automated governance creates security blind spots. Account Factory is the built-in account vending mechanism in AWS Control Tower. It standardizes account creation, network baselines, and security configurations across the enterprise.
How Account Factory Operates
Account Factory is delivered as an AWS Service Catalog product in the Management account:
- Self-Service Vending: Authorized teams invoke the Account Factory product via the AWS Service Catalog console, API, or automated CI/CD pipelines.
- Network Baselines: Account Factory automatically provisions a standardized VPC topology, specifies authorized CIDR blocks, creates public and private subnets, configures internet connectivity, and disables default VPCs across selected regions.
- Identity Integration: Automatically integrates the new account with IAM Identity Center, mapping administrative and developer permission sets to federated directory groups.
- Baseline Enrollment: Enrolls the account directly into the specified Organizational Unit, instantly inheriting all active guardrails and monitoring rules.
Extending Account Factory: CfCT and AFT
For enterprise infrastructure-as-code (IaC) governance, AWS provides two architectural extensions:
- Customizations for AWS Control Tower (CfCT): Uses AWS CodePipeline, AWS CodeCommit, and CloudFormation StackSets to deploy custom security baselines (such as custom IAM roles, default KMS keys, and endpoint monitors) across member accounts whenever a new account is vended or an OU is modified.
- Account Factory for Terraform (AFT): Enables platform engineering teams to define account vending and customization pipelines using Terraform. AFT provisions a dedicated pipeline architecture featuring an AFT management account, Git-driven workflow repositories, and DynamoDB state tracking.
Control Classifications: Guidance Levels
In AWS Control Tower, governance rules are formally termed Controls (formerly referred to as Guardrails). Control Tower classifies controls into three guidance categories:
| Guidance Level | Behavior & Enforcement | Example Enterprise Rules |
|---|---|---|
| Mandatory Controls | Automatically enabled when the Landing Zone is created. Cannot be disabled or bypassed. Enforces foundational organizational integrity. | Disallow configuration changes to AWS Config and CloudTrail set up by Control Tower; Disallow deletion of the Log Archive and changes to its encryption and logging; Disallow changes to IAM roles, Lambda functions, and CloudWatch resources set up by Control Tower; Detect the public read setting of the Log Archive bucket. |
| Strongly Recommended Controls | Based on enterprise security best practices and compliance standards (such as the CIS AWS Foundations Benchmark). Enabled by default or selectively applied to OUs. | Detect whether public read access to Amazon S3 buckets is allowed; Detect whether MFA is enabled for the root user; Detect whether Amazon EBS volumes are encrypted; Disallow creation of access keys for the root user. |
| Elective Controls | Optional, enterprise-specific guardrails. Security architects selectively activate elective controls based on specific compliance frameworks (NIST SP 800-53, PCI DSS). | Disallow non-approved AWS regions; Disallow creation of internet gateways in workload subnets; Enforce specific customer managed KMS keys for S3 encryption. |
Implementation Mechanisms: Preventive, Detective & Proactive
Control Tower implements governance controls through three distinct technical mechanisms across the resource lifecycle:
Comprehensive Mechanism Comparison
| Attribute | Preventive Controls | Detective Controls | Proactive Controls |
|---|---|---|---|
| Underlying Technology | AWS Organizations Service Control Policies (SCPs) | AWS Config Rules & AWS Security Hub Controls | AWS CloudFormation Hooks |
| Enforcement Point | Synchronous at AWS API execution. | Asynchronous post-provisioning continuous monitoring. | Pre-provisioning during CloudFormation stack creation or update. |
| Action on Non-Compliance | Rejects the API call with an AccessDenied error; resource is never created. | Records resource as NON_COMPLIANT in dashboards; optionally triggers automated remediation. | Fails the CloudFormation hook check; stack deployment is aborted before resource provisioning starts. |
| Blast Radius Mitigation | Maximum; prevents prohibited configurations from ever existing. | Moderate; resource exists in a non-compliant state until detected and remediated. | High; blocks non-compliant infrastructure-as-code templates in deployment pipelines. |
| Limitations | Does not evaluate resource-level configuration attributes (e.g., checking if an existing volume is unencrypted). Does not apply to the Management account. | Remediation lag (window of vulnerability between creation and detection). | Only inspects resources provisioned via AWS CloudFormation; direct console or CLI API calls bypass hooks. |
Proactive Governance via CloudFormation Hooks
A critical architectural innovation in modern landing zones is the adoption of Proactive Controls. In traditional environments, a developer might deploy an unencrypted Amazon S3 bucket via CloudFormation. A detective AWS Config rule evaluates the resource minutes later, flags it as non-compliant, and triggers a remediation Lambda function to encrypt the bucket or delete it. During that intervening window, unencrypted data may have already been written, creating a compliance breach.
CloudFormation Hooks intercept stack creation and update events in the deployment engine:
- When a stack operation begins, CloudFormation invokes registered proactive hooks at the
preCreateorpreUpdatelifecycle points. - The hook evaluates the target resource configurations against defined compliance policies (such as verifying that
BucketEncryptionis enabled onAWS::S3::Bucket). - If the configuration violates the policy, the hook returns a
FAILUREstatus with a descriptive error message, causing CloudFormation to abort the stack operation and roll back before any cloud resource is instantiated.
Exam Tip: For the exam, recognize the lifecycle timing: Proactive controls stop non-compliant CloudFormation deployments before resources exist; Preventive controls block unauthorized API calls at execution time; Detective controls flag non-compliant resources after they are provisioned.
Managing Governance Drift & Baseline Re-Registration
Governance Drift occurs when the actual state of accounts, OUs, or guardrails within the organization diverges from the baseline configured by AWS Control Tower. Drift introduces hidden security exposures and audit non-compliance.
Common Sources of Drift
- Manual Policy Alteration: An administrator with Management account access directly edits or detaches a Control Tower SCP in the AWS Organizations console.
- Moved or Removed Member Account: An enrolled account is moved to another OU, or removed from the organization, in the Organizations console instead of through Control Tower.
- Deleted Control Tower Resources: A Control Tower role, OU (such as the Security OU), or control is deleted or changed from outside Control Tower. (Member-account users can't simply turn off the Config recorder, because mandatory controls deny changes to Control Tower's AWS Config and CloudTrail settings.)
- Landing Zone Version Lag: AWS releases updates to the Control Tower baseline that have not been applied to existing accounts.
Detecting and Remediating Drift
- Console Visibility: Control Tower continuously audits organizational state and flags drifted components with a status of Drifted in the Landing Zone dashboard.
- Re-registering an OU: When drift occurs at the OU level (for example, if member accounts within an OU lack mandatory SCPs or baseline roles), the administrator executes Re-register OU in the Control Tower console. This action reapplies all baseline configurations, provisions missing StackSets, and attaches mandatory guardrails across all accounts in that OU.
- Updating the Account or Landing Zone: A moved account is fixed by updating it in Account Factory (or re-registering its OU). Landing-zone-level drift, such as a deleted Security OU account or role, is fixed with Reset or a landing zone update, which is also how you adopt new landing zone versions.
Specialty Exam Traps & Architectural Pitfalls
- Relying Solely on Preventive Controls for Compliance Audits: Preventive controls (SCPs) prevent unauthorized API actions, but they cannot report on the compliance posture of existing resources created before the SCP was attached. True compliance requires Detective controls (AWS Config) to audit historical and current resource state.
- Assuming Proactive Controls Block Direct AWS CLI Calls: CloudFormation Hooks only evaluate infrastructure deployed via AWS CloudFormation. If a developer uses the AWS CLI to execute
aws s3api create-bucket, the proactive hook is completely bypassed. To block direct manual resource creation, organizations must enforce Preventive controls (SCPs) that restrict direct provisioning permissions. - Resolving Drift by Deleting Accounts: When Control Tower reports an account or OU as drifted, never delete or disassociate the account. The standard, non-destructive resolution is to use the Re-register OU or Enroll Account action in the Control Tower console.
- Preventive Guardrail Immunity in the Management Account: Control Tower preventive guardrails (SCPs) do not apply to the Management account. If a workload is mistakenly deployed into the Management account, it will operate completely unconstrained by Control Tower preventive guardrails.
A healthcare enterprise requires that no Amazon S3 buckets can ever be created with unencrypted storage configurations. The compliance team mandates that non-compliant S3 buckets must be rejected before CloudFormation provisions the resource, avoiding the lag and risk of post-provisioning detective remediation. Which Control Tower mechanism satisfies this requirement?
Deploy an AWS Config detective rule with automatic Systems Manager Automation runbook remediation.
Enable a proactive control implemented via AWS CloudFormation Hooks that evaluates the template during stack deployment and aborts creation if encryption is omitted.
Attach an SCP to the member accounts with an explicit Deny on s3:PutBucketPolicy when server-side encryption headers are absent.
Configure Amazon Macie to continuously scan all S3 buckets for unencrypted objects and trigger an EventBridge quarantine rule.
A cloud engineer signed in to the management account uses the AWS Organizations console, not Control Tower, to detach a Control Tower-managed SCP (a preventive control) from a registered OU that contains 12 enrolled accounts. What will AWS Control Tower report, and what is the proper resolution?
Control Tower will automatically close the 12 accounts because a mandatory baseline was violated.
The Account Factory product will roll back and recreate each account from scratch.
Control Tower will report governance drift for the OU, and the administrator should re-register the OU in Control Tower to restore the managed controls.
AWS Organizations will block all API calls in the affected accounts until the SCP is reattached manually.
A security architect is establishing the governance baselines for an enterprise Landing Zone. Which of the following describes a Mandatory control in AWS Control Tower?
Detect whether Amazon EBS volumes attached to EC2 instances are encrypted at rest.
Disallow the creation of internet gateways in workload subnets.
Require multi-factor authentication (MFA) for all IAM console users.
Disallow configuration changes to the AWS Config and CloudTrail resources that Control Tower set up, and protect the Log Archive bucket from deletion.
An enterprise wants to automate the provisioning of standardized workload accounts with pre-configured transit gateway attachments, approved VPC CIDRs, and default IAM roles. The security team also requires all provisioning requests to be submitted through an internal self-service portal. Which native capability of Control Tower provides this standardized account vending framework?
Account Factory, integrated with AWS Service Catalog and optionally customized via Account Factory for Terraform (AFT) or Customizations for Control Tower (CfCT).
AWS Resource Access Manager sharing default VPCs across member accounts upon invitation acceptance.
AWS Proton environment templates coupled with CloudFormation StackSets triggered via SNS.
Amazon QuickSight account templates connected to Organizations All Features mode.
Sections you finish are checked off in the contents.