CLOUD SECURITY | AWS
13 min read

AWS Organizations Multi-Account Security Architecture: SCPs, Centralized Logging, and Security Hub

85%
of organizations with 10+ AWS accounts have at least one account with misconfigured logging or missing security controls — AWS customer security assessments
SCPs
Service Control Policies — the only AWS mechanism that restricts even the root user in member accounts, making them the highest-leverage security control in a multi-account environment
4 foundational
AWS accounts every multi-account organization should have: Management (org root only), Security/Audit (logging and security tooling), Log Archive (immutable log storage), and Shared Services
15 minutes
time for AWS CloudTrail to deliver organization-level API event records to a centralized S3 bucket — the detection lag between an API call and a SIEM alert

SponsoredRetool

Retool's new app builder is where AI-generated code ships safely

Building apps with AI is easy. Getting them to production safely is another story.

Start building for free today

AWS Organizations allows you to manage multiple AWS accounts under a single organizational hierarchy. Security teams commonly encounter multi-account environments after acquisitions, after cloud adoption matures beyond a single team, or after adopting AWS Control Tower. The security architecture for a multi-account environment must be designed at the organizational level — per-account security controls applied independently to 20 accounts create 20 different security postures instead of one.

This guide covers the foundational multi-account security architecture: account structure, Service Control Policies that apply guardrails across all accounts, centralized logging in an immutable log account, Security Hub aggregation for a single visibility pane, and GuardDuty delegated administration.

Foundational account structure

The account structure you establish early determines the security architecture options available later. AWS's Security Reference Architecture defines four foundational accounts that every multi-account organization should establish.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Service Control Policies: the highest-leverage security control

SCPs are policies attached to organizational units (OUs) or individual accounts that restrict what API actions can be performed in those accounts — even by the account's root user. They are deny-by-default: an SCP allowlist limits all member accounts to only the actions listed, regardless of IAM policies. An SCP denylist blocks specific actions across all accounts in the OU.

The most effective SCP strategy uses a denylist approach: allow all actions by default (FullAWSAccess), then attach specific deny SCPs that block high-risk actions organization-wide.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Free daily briefing

Briefings like this, every morning before 9am.

Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.

Centralized CloudTrail: organization-level trail configuration

A CloudTrail organization trail, configured in the management account, captures API events from all member accounts and delivers them to a centralized S3 bucket in the Log Archive account. This is a single configuration in the management account that provides logging coverage for all current and future member accounts automatically.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Security Hub and GuardDuty at organization scale

AWS Security Hub and GuardDuty both support Organization-level delegation, where a designated Security account aggregates findings from all member accounts into a single pane. Configure both services at organization level rather than account by account.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

The bottom line

Multi-account AWS security is an architecture problem, not a configuration problem. The decisions made about account structure, SCP design, and centralized logging in the early stages of a multi-account environment determine whether you have one defensible security posture or 20 different security postures that each need to be audited and maintained separately. The four foundational accounts, five core SCPs, organization-level CloudTrail, and Security Hub/GuardDuty delegation described here provide a scalable baseline that covers all current and future accounts automatically.

Frequently asked questions

What is the difference between AWS Control Tower and manual Organizations setup?

AWS Control Tower is a managed service that automates the deployment of a multi-account environment with guardrails (implemented as SCPs and AWS Config rules), the foundational account structure (Management, Audit, Log Archive), and ongoing drift detection. Manual Organizations setup gives more flexibility but requires manual implementation of everything Control Tower provides. Control Tower is the right choice for organizations starting a multi-account environment from scratch or standardizing an existing informal multi-account setup. Manual Organizations is appropriate when Control Tower's guardrails are too restrictive for specific use cases or when migrating an existing complex environment where Control Tower's account vending model doesn't fit.

How do SCPs interact with IAM policies?

SCPs and IAM policies use a combined evaluation model. An API call is allowed only if: (1) the SCP allows the action (or the account has FullAWSAccess and no deny SCP blocks it), AND (2) the IAM policy allows the action. Either layer can deny the action — an IAM allow does not override an SCP deny. This means SCPs create a ceiling: even if an IAM policy grants s3:DeleteBucket, an SCP that denies s3:DeleteBucket prevents the action. SCPs do not grant permissions on their own — they only restrict what IAM policies can allow.

What is the cost of running Security Hub and GuardDuty organization-wide?

GuardDuty pricing is based on data volume analyzed (CloudTrail events, DNS logs, VPC Flow Logs) per account per region. For a mid-size organization (20 accounts, 3 active regions), GuardDuty typically costs $500-$2000/month at scale. Security Hub pricing is based on finding ingestion volume — the first 10,000 finding ingestions per account per month are free; additional findings are $0.0030 per finding. For most organizations, Security Hub costs $100-$500/month organization-wide. These are estimates — use AWS Cost Calculator with your expected CloudTrail volume for accurate estimates.

Sources & references

  1. AWS Security Reference Architecture
  2. AWS Organizations SCP Design Guide
  3. AWS Well-Architected Security Pillar

Free resources

25
Free download

Critical CVE Reference Card 2025–2026

25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.

No spam. Unsubscribe anytime.

Free download

Ransomware Incident Response Playbook

Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.

No spam. Unsubscribe anytime.

Free newsletter

Get threat intel before your inbox does.

50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.

Unsubscribe anytime. We never sell your data.

Eric Bang
Author

Founder & Cybersecurity Evangelist, Decryption Digest

Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.

Black Hat Giveaway

Win a $2,495 Black Hat pass.

Full-access to Black Hat USA 2026 in Las Vegas. Subscribe free to enter.

Joins Decryption Digest daily briefing. Unsubscribe anytime.

Giveaway: Black Hat USA 2026 Full-Access Pass ($2,495 value)

Details →
Daily Briefing

Subscribe to enter the giveaway

Every subscriber is automatically entered. You also get daily threat intel every morning: zero-days, ransomware, and nation-state campaigns. Free. No spam.

Already subscribed? You're already entered.

Giveaway

Win a $2,495 Black Hat USA 2026 pass.