Guardrails using AWS Organizations and Terraform

Presented by

Andrew Krug - Security Technical Evangelist at Datadog

About this talk

AWS Organizations is relatively new, having been released in 2017. The evolution from simply being consolidated billing to security controls seemed like a natural progression. In 2021 Organizations is one of the best tools in your arsenal to protect accounts. In this talk we’ll explore the pros and cons of using a feature in AWS Organizations called SCPs ( Security Control Policies ). SCPs are the most restrictive and broadest net we can cast with regard to the usage of APIs in the AWS control plane. We’ll look to understand how SCPs work, the tooling to configure them, and finally why Terraform is the best option we have to craft these policies. Attendees will leave with a firm understanding of the trade offs as well as a set of recommendations on why they should consider employing this model. Key Takeaways - What is AWS Organizations and Multi Account - How can you use terraform to create guardrails - Understand why Terraform is an excellent approach to creating SCPs
Related topics:

More from this channel

Upcoming talks (0)
On-demand talks (136)
Subscribers (12987)
HashiCorp events provide an opportunity to learn and share knowledge. Events focus on education and the best practices for using HashiCorp tools and products and trends in the industry.