官术网_书友最值得收藏!

Managing your accounts

There are a number of ways to group and arrange your AWS accounts. How you do this is completely up to you, but here are a few examples to consider:

  • Business unit (BU) or location: You may wish to allow each BU to work in isolation on their own products or services, on their own schedule, without impacting other parts of the business
  • Cost center: Grouping according to cost may help you track spend versus allocated budget
  • Environment type: It may make sense to group your development, test, and production environments together in a way which helps you manage the controls across each environment
  • Workload type or data classification: Your company may want to isolate workload types from each other, or ensure that particular controls are applied to all accounts containing a particular kind of data

In the following fictitious example, we have isolated the Sitwell Enterprises Account from the rest of the organization by placing it in an OU called Sudden Valley. Perhaps they operate in a different geographical location and have different regulatory requirements around controls and access.

Organization hierarchy

Note that while it's also technically possible for us to put the master account inside an OU, we avoid doing this to make it obvious that:

  • It's the master account and has control over the entire organization
  • The rules we set, using SCPs for the member accounts in our organization, do not apply to the master account (because they can't)

Learn more about SCPs in the Adding a service control policy recipe in this chapter.

主站蜘蛛池模板: 平凉市| 长兴县| 皋兰县| 永川市| 贡觉县| 长兴县| 始兴县| 鹤庆县| 顺昌县| 新龙县| 和平区| 运城市| 永修县| 中方县| 镇巴县| 长寿区| 北海市| 寿光市| 日照市| 宁陵县| 呈贡县| 石门县| 洪江市| 石门县| 光泽县| 清流县| 铁岭县| 永年县| 宜君县| 张掖市| 长春市| 大荔县| 宜宾县| 阳谷县| 高雄市| 乐山市| 乌鲁木齐市| 文昌市| 永丰县| 革吉县| 台前县|