Deploy the guidance
Guidance for Account Assessment for AWS Organizations uses the AWS Cloud Development Kit (AWS CDK) and AWS CloudFormation stacks to automate deployment. The AWS CDK code defines the AWS resources included in this guidance and their properties. AWS CDK synthesizes CloudFormation templates and deploys the stacks.
Resource-based policy validation
We designed this guidance to aggregate scan findings for customers. This guidance does not check the validity or correctness of your underlying resource-based policies. When changing policies that allow account migration to another AWS Organization, we recommend:
-
Verifying that your policies work as intended before making changes.
-
Using AWS Identity and Access Management (IAM) Access Analyzer to verify that your policies achieve your desired permissions.
-
Reviewing and updating the
Conditionpolicy element to meet your security requirements. Do not delete theConditionwithout reviewing the underlying impact. -
Engaging with AWS Solutions Architects, Technical Account Managers, and AWS Professional Services to review your AWS Organizations-based dependencies identified by the guidance before initiating account migration.
Dependencies outside this guidance’s scope
Dependencies outside the scope of this guidance can impact account migration between AWS Organizations. Examples include AWS Organizations quotas, resources shared by AWS Resource Access Manager (AWS RAM)
Deployment process overview
Deploy this guidance from the AWS CDK application in the GitHub repository
The guidance consists of three AWS CDK stacks:
-
Hub stack – Deploys the web UI, API, assessment functions, workflows, and data stores in a member account.
-
Org-Management stack – Deploys the IAM role that the Hub stack uses to read AWS Organizations data. Deploy this stack in the Organizations management account.
-
Spoke stack – Deploys the IAM roles that the Hub stack uses to assess an account. Deploy this stack in each account that you want to assess.
Deploy the Hub stack first, followed by the Org-Management and Spoke stacks.
Time to deploy: Approximately 30 to 45 minutes
Anonymized operational metrics
This guidance sends anonymized operational metrics to AWS by default. We use this data to better understand how customers use this guidance and related services and products. AWS owns the data gathered through this survey. Data collection is subject to the AWS Privacy Notice
To opt out, open source/infra/lib/account-assessment-hub-stack.ts before you build the guidance. In the AnonymousData mapping, change the Data value from Yes to No. For more information, see Anonymized data collection.