Which solution will meet these requirements in the MOST operationally efficient way?

1 Comment

  1. Evelyn
    Author

    My best guess is:
    Create an AWS CloudFormation template that defines the standard account resources. Deploy the template to all accounts from the organization’s management account by using CloudFormation StackSets. Create an SCP that prevents updates or deletions to CloudTrail resources or AWS Config resources unless the principal is an administrator of the organization’s management account.

Leave a Reply

Your email address will not be published. Required fields are marked *

4 + 13 =