All technological notes.
AWS OrganizationsService Control Policies (SCP)CloudTrail on all accounts, send logs to central S3 accountSend CloudWatch Logs to central logging account


AWS Control Tower - compliant environment, >OrgansAWS Control Tower runs on top of AWS Organizations:
SCPs (Service Control Policies)AWS Service Catalog - Compliant Product Listensure stacks that are compliant / in line with the rest of the organization
Admin Tasks: CloudFormation Templates -> Portfolio -> Control