View a markdown version of this page

Concepts and definitions - Account Assessment for AWS Organizations

Concepts and definitions

This section describes key concepts and defines terminology specific to this solution: 

Identity-based policy

Identity-based policies are attached to a user, group, or role. Use these policies to specify permissions for a given identity.

Resource-based policy

Resource-based policies are attached to a resource. Use these policies to specify who has access to the resource and what actions they can perform on it.

Service Control Policy Service control policies (SCPs) are a type of organization policy that are used to manage permissions in an organization, SCPs offer central control over the maximum available permissions for all accounts in the organization.

Trusted account

AWS account that contains the users that need to access the resource.

Trusting account

AWS account that owns the resource.

Principal

An entity in AWS that can perform actions and access resources. A principal can be an AWS account owner, a user, or a role.

Note

For a general reference of AWS terms, see the AWS glossary in the AWS General Reference.