logo

Using Service Control Policies to protect security baselines

ID: 6643f20f-644d-5037-bbb0-ab6d7544d90b

STIX ID: report--6643f20f-644d-5037-bbb0-ab6d7544d90b

Feed Name: Wiz Blog

Date Published: 2023-03-20

Date Updated: 2026-05-01

...
...

This guide explains how to enforce a security baseline across AWS accounts using Service Control Policies (SCPs), including protections for critical IAM roles, safeguarding CloudTrail and GuardDuty configurations, preventing accounts from leaving an organization, and restricting risky root-user and account-contact changes; it provides concrete SCP examples, exception handling for StackSet roles and delegated admin, and cautions on usability and debugging considerations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.