AWS Control Tower
- Easy way to setup and govern a secure and compliant multi-account AWS environment based on best practices.
- It uses AWS organizations to create accounts.
- Setup env in few clicks, automate policy management using guardrails.
Guardrails
- Provides ongoing governance.
- Preventive Guardrail, using SCPs (Restrict regions across all accounts).
- Detective Guardrails, using AWS Config
