HNSEC02-BP01 Implement a landing zone
Implementing a landing zone establishes a standardized, secure foundation for hybrid networking infrastructure. A landing zone provides centralized identity and access management, standardized security controls, governance mechanisms, network architecture, and account structures that enable scalable growth while maintaining compliance. By automating resource provisioning and implementing guardrails from the start, organizations can avoid costly rework later while accelerating their cloud adoption journey with confidence, knowing they have established proper security boundaries and operational efficiency from day one.
Desired outcome: Establish a secure foundation for your hybrid networking environment with consistent architecture and configuration controls.
Level of risk exposed if this best practice is not established: High
Benefits of establishing this best practice:
-
Ensures consistent security and compliance across all accounts
-
Automates account provisioning and governance
-
Reduces operational overhead and human error
-
Enables scalable and secure hybrid networking environment
Implementation guidance
-
Deploy a landing zone using services such as AWS Control Tower.
-
Apply preventive and detective guardrails for governance and compliance.
-
Standardize account creation and management through Account Factory.
-
Monitor the landing zone using services such as AWS Control Tower dashboard and Security Hub CSPM.