This article is a HOW-TO for how to setup your AWS Organization properly allowing you to deploy services and controls across your AWS Accounts.
AWS (Amazon Web Services) had their first security focused conference this year. It was basically an opportunity for AWS to release security related products and features but also create a gathering for security minded practitioners and those looking to consume security related information around AWS products.
AWS SCP is a maturing AWS Organization feature that allows you to apply IAM-like policies at the organizational level.
So you successfully ran Trusted Advisor, Scout2, Access Advisor, or hired an external firm to audit your AWS accounts? You found that the co-founder is still logging in using root keys and that you have security groups allowing 0.0.0.0/0 access from the internet. Not to mention the 20 developers offshore that are sharing the same IAM user and access keys. Oops!