Milestone 1: Multi-account security platform
Design a governed security platform for at least five accounts and two Regions.
Include:
- IAM Identity Center and workload roles,
- SCPs and delegated security administration,
- KMS, Secrets Manager, certificate, and data-classification controls,
- centralized Config and CloudTrail,
- Security Hub posture and finding aggregation,
- GuardDuty, Inspector, Macie, and Access Analyzer coverage,
- automated finding enrichment and bounded remediation,
- protected security tooling and log archive accounts,
- security metrics, exceptions, evidence, and cost governance.
Provide a coverage matrix and one tested security-response workflow.