@@ -10,80 +10,63 @@ It is anticipated we will offer multiple sample architectures with the AWS SEA s
1010
1111<!-- TOC depthFrom:2 -->
1212
13- - [ AWS Secure Environment Architecture] ( #aws-secure-environment-architecture )
14- - [ Table of Contents] ( #table-of-contents )
15- - [ 1. Introduction] ( #1-introduction )
16- - [ 1.1. Purpose of Document] ( #11-purpose-of-document )
17- - [ 1.2. Overview] ( #12-overview )
18- - [ 1.3. Document Convention] ( #13-document-convention )
19- - [ 1.3.1. AWS Account Numbers] ( #131-aws-account-numbers )
20- - [ 1.3.2. JSON Annotation] ( #132-json-annotation )
21- - [ 1.3.3. IP Addresses] ( #133-ip-addresses )
22- - [ 1.4. Department Naming] ( #14-department-naming )
23- - [ 1.5. Relationship to AWS Landing Zone] ( #15-relationship-to-aws-landing-zone )
24- - [ 2. Account Structure] ( #2-account-structure )
25- - [ 2.1. Accounts] ( #21-accounts )
26- - [ 2.2. Master Account] ( #22-master-account )
27- - [ 2.2.1. AWS SSO] ( #221-aws-sso )
28- - [ 2.2.2. Organizational Units] ( #222-organizational-units )
29- - [ 2.2.2.1. Core OU] ( #2221-core-ou )
30- - [ 2.2.2.2. Central OU] ( #2222-central-ou )
31- - [ 2.2.2.3. Functional OU: Sandbox] ( #2223-functional-ou-sandbox )
32- - [ 2.2.2.4. Functional OU: UnClass] ( #2224-functional-ou-unclass )
33- - [ 2.2.2.5. Functional OU: Dev] ( #2225-functional-ou-dev )
34- - [ 2.2.2.6. Functional OU: Test] ( #2226-functional-ou-test )
35- - [ 2.2.2.7. Functional OU: Prod] ( #2227-functional-ou-prod )
36- - [ 2.2.2.8. Suspended OU] ( #2228-suspended-ou )
37- - [ 2.3. Mandatory Accounts] ( #23-mandatory-accounts )
38- - [ 2.3.1. Master] ( #231-master )
39- - [ 2.3.2. Perimeter] ( #232-perimeter )
40- - [ 2.3.3. Shared Network] ( #233-shared-network )
41- - [ 2.3.4. Operations] ( #234-operations )
42- - [ 2.3.5. Log Archive] ( #235-log-archive )
43- - [ 2.3.6. Security] ( #236-security )
44- - [ 2.4. Functional Accounts] ( #24-functional-accounts )
45- - [ 2.5. Account Level Settings] ( #25-account-level-settings )
46- - [ 2.6. Private Marketplace] ( #26-private-marketplace )
47- - [ 3. Networking] ( #3-networking )
48- - [ 3.1. Overview] ( #31-overview )
49- - [ 3.2. Perimeter] ( #32-perimeter )
50- - [ 3.2.1. IP Ranges] ( #321-ip-ranges )
51- - [ 3.3. Shared Network] ( #33-shared-network )
52- - [ 3.3.1. Transit Gateway] ( #331-transit-gateway )
53- - [ 3.3.2. Endpoint VPC] ( #332-endpoint-vpc )
54- - [ 3.3.3. Endpoint VPC: Interface Endpoints] ( #333-endpoint-vpc-interface-endpoints )
55- - [ 3.3.4. Endpoint VPC: Hybrid DNS] ( #334-endpoint-vpc-hybrid-dns )
56- - [ 3.3.4.1. Within The Cloud] ( #3341-within-the-cloud )
57- - [ 3.3.4.2. From Cloud to On-Premises] ( #3342-from-cloud-to-on-premises )
58- - [ 3.3.4.3. From On-Premises to Cloud] ( #3343-from-on-premises-to-cloud )
59- - [ 3.3.5. Workload VPCs] ( #335-workload-vpcs )
60- - [ 3.3.5.1. Security Groups] ( #3351-security-groups )
61- - [ 3.3.5.2. NACLs] ( #3352-nacls )
62- - [ 3.3.6. Central VPC] ( #336-central-vpc )
63- - [ 3.3.6.1. Domain Joining] ( #3361-domain-joining )
64- - [ 3.3.7. Sandbox VPC] ( #337-sandbox-vpc )
65- - [ 4. Authorization and Authentication] ( #4-authorization-and-authentication )
66- - [ 4.1. Relationship to the Master Account] ( #41-relationship-to-the-master-account )
67- - [ 4.2. Break Glass Accounts] ( #42-break-glass-accounts )
68- - [ 4.3. Control Plane Access via AWS SSO] ( #43-control-plane-access-via-aws-sso )
69- - [ 4.3.1. SSO User Roles] ( #431-sso-user-roles )
70- - [ 4.3.2. Principal Authorization] ( #432-principal-authorization )
71- - [ 4.4. Root Authorization] ( #44-root-authorization )
72- - [ 4.5. Service Roles] ( #45-service-roles )
73- - [ 4.6. Service Control Policies] ( #46-service-control-policies )
74- - [ 4.6.1. PBMM Only] ( #461-pbmm-only )
75- - [ 4.6.2. PBMM Unclass Only] ( #462-pbmm-unclass-only )
76- - [ 4.6.3. PBMM Guardrails (Parts 1 and 2)] ( #463-pbmm-guardrails-parts-1-and-2 )
77- - [ 4.6.3.1. Encryption at Rest] ( #4631-encryption-at-rest )
78- - [ 4.6.4. Quarantine Deny All] ( #464-quarantine-deny-all )
79- - [ 4.6.5. Quarantine New Object] ( #465-quarantine-new-object )
80- - [ 5. Logging and Monitoring] ( #5-logging-and-monitoring )
81- - [ 5.1. CloudTrail] ( #51-cloudtrail )
82- - [ 5.2. VPC Flow Logs] ( #52-vpc-flow-logs )
83- - [ 5.3. GuardDuty] ( #53-guardduty )
84- - [ 5.4. Config] ( #54-config )
85- - [ 5.5. Cloudwatch Logs] ( #55-cloudwatch-logs )
86- - [ 5.6. SecurityHub] ( #56-securityhub )
13+ - [ 1. Introduction] ( #1-introduction )
14+ - [ 1.1. Purpose of Document] ( #11-purpose-of-document )
15+ - [ 1.2. Overview] ( #12-overview )
16+ - [ 1.3. Document Convention] ( #13-document-convention )
17+ - [ 1.3.1. AWS Account Numbers] ( #131-aws-account-numbers )
18+ - [ 1.3.2. JSON Annotation] ( #132-json-annotation )
19+ - [ 1.3.3. IP Addresses] ( #133-ip-addresses )
20+ - [ 1.4. Department Naming] ( #14-department-naming )
21+ - [ 1.5. Relationship to AWS Landing Zone] ( #15-relationship-to-aws-landing-zone )
22+ - [ 2. Account Structure] ( #2-account-structure )
23+ - [ 2.1. Accounts] ( #21-accounts )
24+ - [ 2.2. Master Account] ( #22-master-account )
25+ - [ 2.2.1. AWS SSO] ( #221-aws-sso )
26+ - [ 2.2.2. Organizational Units] ( #222-organizational-units )
27+ - [ 2.3. Mandatory Accounts] ( #23-mandatory-accounts )
28+ - [ 2.3.1. Master] ( #231-master )
29+ - [ 2.3.2. Perimeter] ( #232-perimeter )
30+ - [ 2.3.3. Shared Network] ( #233-shared-network )
31+ - [ 2.3.4. Operations] ( #234-operations )
32+ - [ 2.3.5. Log Archive] ( #235-log-archive )
33+ - [ 2.3.6. Security] ( #236-security )
34+ - [ 2.4. Functional Accounts] ( #24-functional-accounts )
35+ - [ 2.5. Account Level Settings] ( #25-account-level-settings )
36+ - [ 2.6. Private Marketplace] ( #26-private-marketplace )
37+ - [ 3. Networking] ( #3-networking )
38+ - [ 3.1. Overview] ( #31-overview )
39+ - [ 3.2. Perimeter] ( #32-perimeter )
40+ - [ 3.2.1. IP Ranges] ( #321-ip-ranges )
41+ - [ 3.3. Shared Network] ( #33-shared-network )
42+ - [ 3.3.1. Transit Gateway] ( #331-transit-gateway )
43+ - [ 3.3.2. Endpoint VPC] ( #332-endpoint-vpc )
44+ - [ 3.3.3. Endpoint VPC: Interface Endpoints] ( #333-endpoint-vpc-interface-endpoints )
45+ - [ 3.3.4. Endpoint VPC: Hybrid DNS] ( #334-endpoint-vpc-hybrid-dns )
46+ - [ 3.3.5. Workload VPCs] ( #335-workload-vpcs )
47+ - [ 3.3.6. Central VPC] ( #336-central-vpc )
48+ - [ 3.3.7. Sandbox VPC] ( #337-sandbox-vpc )
49+ - [ 4. Authorization and Authentication] ( #4-authorization-and-authentication )
50+ - [ 4.1. Relationship to the Master Account] ( #41-relationship-to-the-master-account )
51+ - [ 4.2. Break Glass Accounts] ( #42-break-glass-accounts )
52+ - [ 4.3. Control Plane Access via AWS SSO] ( #43-control-plane-access-via-aws-sso )
53+ - [ 4.3.1. SSO User Roles] ( #431-sso-user-roles )
54+ - [ 4.3.2. Principal Authorization] ( #432-principal-authorization )
55+ - [ 4.4. Root Authorization] ( #44-root-authorization )
56+ - [ 4.5. Service Roles] ( #45-service-roles )
57+ - [ 4.6. Service Control Policies] ( #46-service-control-policies )
58+ - [ 4.6.1. PBMM Only] ( #461-pbmm-only )
59+ - [ 4.6.2. PBMM Unclass Only] ( #462-pbmm-unclass-only )
60+ - [ 4.6.3. PBMM Guardrails (Parts 1 and 2)] ( #463-pbmm-guardrails-parts-1-and-2 )
61+ - [ 4.6.4. Quarantine Deny All] ( #464-quarantine-deny-all )
62+ - [ 4.6.5. Quarantine New Object] ( #465-quarantine-new-object )
63+ - [ 5. Logging and Monitoring] ( #5-logging-and-monitoring )
64+ - [ 5.1. CloudTrail] ( #51-cloudtrail )
65+ - [ 5.2. VPC Flow Logs] ( #52-vpc-flow-logs )
66+ - [ 5.3. GuardDuty] ( #53-guardduty )
67+ - [ 5.4. Config] ( #54-config )
68+ - [ 5.5. Cloudwatch Logs] ( #55-cloudwatch-logs )
69+ - [ 5.6. SecurityHub] ( #56-securityhub )
8770
8871<!-- /TOC -->
8972
0 commit comments