mission-finops --aws-governance-fit
Methodology and sources
Built from AWS's own Control Tower, Landing Zone, Account Factory for Terraform, and Landing Zone Accelerator documentation.
Control Tower and Landing Zone
- AWS multi-account landing zone overview
- Landing Zone 4.0 migration guide
- Extending governance in Control Tower
- Working with existing Config resources
- How Control Tower controls work
- Control Tower pricing
- Plan your AWS Control Tower landing zone
- AWS Control Tower: limitations and quotas
Account provisioning: Account Factory, AFT, Service Catalog
- Methods of account provisioning
- Account Factory for Terraform overview
- AFT pricing
- Account Factory Customization (AFC)
- Create a customized account from a blueprint (AFC)
- Single-Region Terraform support for Account Factory
- Automate account provisioning with Service Catalog APIs
- Service Catalog: ProvisionProduct API
- Service Catalog: UpdateProvisionedProduct API
- Update and move Account Factory accounts
- Unenroll an account through Service Catalog
- Close an Account Factory account
- AWS Organizations: CloseAccount API
- AWS account vending via ServiceNow and AFT
- terraform-aws-control_tower_account_factory releases
- Community-reported AFT caveat: opaque error on a failed Control Tower account creation
GovCloud and Landing Zone Accelerator
- Control Tower in AWS GovCloud (US)
- Landing Zone Accelerator on AWS: solution overview
- LZA prerequisites (Control Tower or Organizations-only)
- LZA deployment options
- LZA cost estimate
Organizing a multi-account estate
- Organizing your AWS environment using multiple accounts
- Design principles for your multi-account strategy
- Recommended OUs and accounts
- When multiple AWS Organizations are justified
- Best practices for the AWS Organizations management account
- AWS Security Reference Architecture: dedicated accounts
Starter policies: SCPs and RCPs
- AWS-published Service Control Policy examples
- AWS-published Resource Control Policy examples
- AWS-published data-perimeter policy examples
- Manage AWS Organizations policies as code
- Resource control policies (RCPs)
- AWS Organizations: higher SCP quotas (May 2026)
- Quotas and service limits for AWS Organizations
IAM Identity Center and human access
- IAM Identity Center and AWS Organizations
- Delegated administration (IAM Identity Center)
- Permission sets concept
- Manage permission sets
- Manage account assignments
- Key changes in Landing Zone 4.0
- Shared account resources (Control Tower)
Root access management
- AWS account root user
- Root user best practices
- Centralized root access management
- Best practices for AWS Organizations
AWS Backup and Control Tower 4.0
- AWS Backup integration (Control Tower)
- Backup integration prerequisites
- Enable the Backup integration
- Backup integration resources (Central Backup and Backup Administrator accounts)
- Types of baselines (Control Tower)
- Manage cross-account backup
- AWS Backup Vault Lock
- Logically air-gapped vaults
- Restore testing
IAM Access Analyzer
- Delegated administrator (IAM Access Analyzer)
- Create an external-access analyzer
- Access Analyzer findings
- Create an unused-access analyzer
- IAM policy validation (ValidatePolicy)
- IAM Access Analyzer pricing
AWS Support pricing
Security Hub and Config pricing
- AWS Security Hub pricing
- Security Hub CSPM's service-linked Config recorder
- AWS Config pricing
- AWS Pricing Calculator
- AWS Security Hub Cost Estimator
Last reviewed: September 2, 2026
Independent educational guidance from Mission FinOps. Not affiliated with or endorsed by Amazon Web Services. This is not a security, compliance or certification determination.