Skip to content

Commit 89b3d31

Browse files
committed
Updated descriptions of Log and Audit accounts to match AWS Control Tower documentation.
1 parent 0b42baf commit 89b3d31

1 file changed

Lines changed: 4 additions & 3 deletions

File tree

documentation/aws-account-and-identity-architecture.md

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -49,7 +49,7 @@ accounts for prototyping, security, and governance. The Helpful Engineering AWS
4949
```
5050
HelpfulEng AWS Org
5151
└ Core
52-
Security
52+
Log
5353
└ Audit
5454
└ Sandboxes
5555
└ he-sandbox2
@@ -77,9 +77,10 @@ provides a number of security and governance best practices out of the box.
7777

7878
**Core Accounts**
7979

80-
The `Security` account contains the organization's security logs such as CloudTrail logs.
80+
The `Log` account contains the organization's API activity logs (CloudTrail) and resource configurations (Config).
8181

82-
The `Audit` account contains the organization's audit findings such as Config and GuardDuty reports.
82+
The `Audit` account is a restricted account that gives security and compliance teams read and write access to all
83+
accounts in the landing zone.
8384

8485
** Sandbox Accounts **
8586

0 commit comments

Comments
 (0)