Skip to main content

Milestone 1: Multi-account security platform

Design a governed security platform for at least five accounts and two Regions.

Include:

  • IAM Identity Center and workload roles,
  • SCPs and delegated security administration,
  • KMS, Secrets Manager, certificate, and data-classification controls,
  • centralized Config and CloudTrail,
  • Security Hub posture and finding aggregation,
  • GuardDuty, Inspector, Macie, and Access Analyzer coverage,
  • automated finding enrichment and bounded remediation,
  • protected security tooling and log archive accounts,
  • security metrics, exceptions, evidence, and cost governance.

Provide a coverage matrix and one tested security-response workflow.