官术网_书友最值得收藏!

Managing your accounts

There are a number of ways to group and arrange your AWS accounts. How you do this is completely up to you, but here are a few examples to consider:

  • Business unit (BU) or location: You may wish to allow each BU to work in isolation on their own products or services, on their own schedule, without impacting other parts of the business
  • Cost center: Grouping according to cost may help you track spend versus allocated budget
  • Environment type: It may make sense to group your development, test, and production environments together in a way which helps you manage the controls across each environment
  • Workload type or data classification: Your company may want to isolate workload types from each other, or ensure that particular controls are applied to all accounts containing a particular kind of data

In the following fictitious example, we have isolated the Sitwell Enterprises Account from the rest of the organization by placing it in an OU called Sudden Valley. Perhaps they operate in a different geographical location and have different regulatory requirements around controls and access.

Organization hierarchy

Note that while it's also technically possible for us to put the master account inside an OU, we avoid doing this to make it obvious that:

  • It's the master account and has control over the entire organization
  • The rules we set, using SCPs for the member accounts in our organization, do not apply to the master account (because they can't)

Learn more about SCPs in the Adding a service control policy recipe in this chapter.

主站蜘蛛池模板: 泽州县| 昌宁县| 呈贡县| 长宁县| 乌海市| 永春县| 通化县| 丰都县| 左贡县| 建昌县| 大埔县| 吉木萨尔县| 保山市| 舟曲县| 吉隆县| 富顺县| 建宁县| 华阴市| 金溪县| 灵武市| 运城市| 乌恰县| 县级市| 平度市| 建德市| 永善县| 大英县| 吴旗县| 盖州市| 黔南| 南平市| 琼海市| 巴里| 鸡东县| 同心县| 云梦县| 隆尧县| 桦南县| 准格尔旗| 渭源县| 滕州市|