AWS Technical Curriculum · SISGOV

Security Governance at Scale

Governance and developer speed are not a trade-off. This companion site unpacks how AWS Organizations, Control Tower, Service Catalog, AWS Config and Systems Manager combine into a single operating model — one that lets platform teams keep central control while builders ship fast.

1-day instructor-led 3 hands-on labs 5 modules Engineers & architects
3Focal points
2Control types
8Core services
13Pages here

Getting started

How to join the room, which Skill Builder track to pick, what you need before the labs, what this course assumes you already know, and how to get the most out of the day.

Join the class remotely

Two links to keep open for the day. The session itself runs on Webex, and the group exercises happen on a shared Figma whiteboard. Both links stay the same across all three blocks — morning, afternoon and the labs — so you can join once and leave the tabs open, or rejoin on the same links after a break.

Both open in a new tab. Webex works from the browser if you would rather not install the desktop app. The Figma board is open for editing — you can sketch on it directly, no account needed to view.

If your corporate network blocks either button, paste the address straight into your browser instead — proxies often strip the click-through but allow the URL. Figma in particular tends to be blocked on managed laptops more than Webex is.
https://awsvirtual.webex.com/awsvirtual/j.php?MTID=m4bfd03d4a84acb70b9a1012390563531 https://www.figma.com/board/rBsmTgKViCaIRV15ACWQhw/secgov-7sep?node-id=0-1&t=6fR6wEXCqEpnqBzP-1

Join the lab workshop

The three hands-on labs run in AWS Workshop Studio. You get a temporary AWS account that is already provisioned with everything the labs need — you do not use your own account, and you do not need to enter a credit card.

The access code is already embedded in the link, so the button is enough. The code is shown separately in case you need to type it in manually.

1

Open the join link

The access code arrives prefilled. If you land on a blank join page instead, go to catalog.us-east-1.prod.workshops.aws/join and enter the code above by hand.

2

Sign in when prompted

Choose the email one-time passcode option unless you already have an AWS Builder ID. You will be emailed a short code to paste back in. This signs you in to the workshop only — it is not an AWS account login and it does not touch your corporate credentials.

3

Accept the terms and join the event

Read the terms, tick the box, then join. Provisioning your lab account takes a short while the first time — do this before the lab block starts rather than when it does.

4

Open the AWS console from the left panel

Once you are in, the left-hand panel has the button that opens the console in your temporary account, and the lab instructions sit alongside it. Keep both open next to this site.

The lab account is disposable and region-pinned. Everything in it is deleted when the event closes, so do not put anything you want to keep in there. The labs also pin you to one AWS Region — if a console action fails with an explicit deny mentioning a region policy, check the Region selector in the top right before assuming the lab is broken.

Take it on AWS Skill Builder — two tracks

The same syllabus you are sitting through is available on Skill Builder in two forms. The only real difference is whether you get the hands-on lab environment. Pick whichever fits what you need after class.

Which one? If you only want to re-hear the explanation, take the free track — it costs nothing and needs no account approval. If you want to redo the labs after class, you need the digital classroom, because the lab environment is what the subscription pays for. The classroom labs you get today expire; the Skill Builder ones do not.

Lab access via AWS Builder Labs (alternative route)

Use the Workshop Studio link above unless your instructor says otherwise. This section applies only if your session is provisioned through AWS Builder Labs with a registration email instead of a workshop access code.
1

Find your registration link

Your instructor sends a welcome email before class containing a registration URL that is unique to your session. That link is what ties your account to this specific class — a generic sign-up will not give you the labs.

2

Create your AWS Builder Labs account through that link

Use the registration URL rather than signing up separately. Going in this way applies your class licence automatically, so you will not need a separate code from the instructor.

3

Open your guides from the dashboard

Once you are in, the Lab Guide and Student Guide buttons sit at the top right of the Builder Labs dashboard. They stay greyed out until the class officially starts. Both guides can be read online or downloaded and kept.

4

Check your machine before the first lab, not during it

Any current Windows, macOS or Linux machine works. Use Chrome, Firefox or Edge. Turn off ad blockers and script blockers for the lab domains — they are the single most common cause of a lab that appears broken.

What this course assumes

This is a technical course pitched at people who already work with AWS. It does not re-teach IAM basics or VPC fundamentals.

Expected first AWS Security Fundamentals and AWS Security Essentials. If you have not done these, the IAM and policy-evaluation material in M02 and M03 will move fast.
Helpful, optional Introduction to AWS Control Tower, Automated Landing Zone, Introduction to AWS Service Catalog, and the AWS Cloud Management Assessment. Any of these will make the afternoon feel more like reinforcement than first contact.
Assumed comfort Reading and writing IAM policy JSON, navigating the AWS console, and a general grasp of what a CloudFormation template does.
Not assumed Prior experience with Organizations, Control Tower, Service Catalog or Config. Those are what the course is for.

What you should be able to do afterwards

How to use this site

Every page follows the same shape: a sticky tab bar under the hero, one panel visible at a time. Nothing is hidden behind scroll position, so you can jump straight to the part you want mid-discussion.

How the day fits together

The course is built as one argument, not five topics. Morning establishes why central governance stops scaling manually and how Control Tower automates the foundation. Afternoon splits control into its two halves — stopping bad things up front, and catching them when they slip through — then hands you the reference material to keep going.

The through-line

Implement

Stand up a multi-account foundation once, from a blueprint, instead of hand-building each account. This is the landing zone.

Provision

Let builders help themselves from a catalogue of pre-approved, pre-constrained products, so speed does not cost you compliance.

Operate

Keep watching after launch. Record configuration, evaluate it against rules, alert on drift, and remediate without a human in the loop.

Read this first if you only have ten minutes. The single most important idea in the course is the split between preventive and detective controls — what each one can and cannot do, and why you need both. The Preventive vs Detective deep dive covers it end to end with the actual policy documents.

Module explainers

One page per module, each built as a short tab tour rather than a long scroll. Every page opens with the problem the module exists to solve, then works through the mechanics with diagrams you can click.

Morning — strategy & automation

M01 – M02
M01 · 20 slides

Governance at Scale

Why the manual approach breaks. The business and technical pressures of a mixed cloud portfolio, the false choice between control and agility, and the three focal points that frame everything after: account management, security and compliance automation, and budget management.

Focal points OU inheritance Organizations
M02 · 47 slides

Governance Automation

The biggest module, and the structural heart of the course. Multi-account design patterns, the landing zone reference architecture, Control Tower setup and prelaunch checks, centralised identity through IAM Identity Center, Account Factory, and the first real look at control types.

Control Tower Landing zone Account Factory Identity Center

Afternoon — controls & operations

M03 – M05
M03 · 41 slides

Preventive Controls

Self-service without a free-for-all. Developer friction and what causes it, AWS Service Catalog portfolios and products, launch constraints, the administrator and end-user workflows, the hub-and-spoke sharing model, budget enforcement, and ITSM integration.

Service Catalog Constraints Budgets Lab 1
M04 · 35 slides

Detective Controls

What happens after launch. The two pillars of an effective governance framework, then the four services that deliver them at multi-account scale: AWS Config for configuration recording and rule evaluation, Systems Manager for grouped action and remediation, GuardDuty for threat detection, Security Hub for aggregation.

AWS Config Systems Manager GuardDuty Labs 2 & 3
M05 · 26 slides

Resources & Next Steps

The AWS Security Checklist walked through as five practical areas mapped to the Well-Architected Security Pillar, plus the certification landscape and a structured path for continuing after class.

Security checklist Well-Architected Certification
Module 0 is not a page here. The course-overview deck is classroom logistics — introductions, prerequisites, lab-portal registration, and machine requirements. Everything from it that you actually need after class lives on the Getting started tab.

Lab companions

Three labs, all in the afternoon. These pages are not a substitute for the official lab guide — they are the context around it: what the lab is actually demonstrating, why each step matters, and which idea from the module it proves.

Lab 1 · with M03

Deploy Cloud Resources from AWS Service Catalog

Build a portfolio, define a product, attach a launch constraint that limits what the product can do, grant a role access to browse it, then deploy from it as an end user. The full administrator-to-consumer loop in one sitting.

Portfolio Launch constraint IAM role
Lab 2 · with M04

Taking Action with AWS Systems Manager

Group resources by a shared property rather than addressing them one by one, view aggregated operational data for the group, then run an automated action against the whole group at once.

Resource Groups Automation Run Command
Lab 3 · with M04

Compliance and Security Automation with AWS Config

Apply managed rules to selected resources, watch the compliance dashboard flag what fails, then wire up automatic remediation so the fix happens without anyone opening a ticket.

Managed rules Auto-remediation Dashboard

What each lab proves

LabModule idea it demonstratesThe moment that matters
Lab 1 A preventive control can be an enablement mechanism, not just a blocker. The launch constraint. The product deploys with permissions the end user does not personally hold — that indirection is the whole trick.
Lab 2 At scale you operate on sets of resources, never individuals. Running one automation against a resource group and watching it fan out. No SSH, no per-instance login.
Lab 3 Detection without remediation is just a nicer inbox. Attaching the remediation action. The rule stops being a report and becomes a control loop.
Lab environments use plain IAM users, not IAM Identity Center. That is a constraint of the sandbox, not a recommendation. In anything resembling production, federate through IAM Identity Center and stop issuing long-lived access keys — which is exactly what M02 argues.

Services in scope

Eight services carry the course. The point is never the individual service — it is how they compose. Organizations provides the boundary, Control Tower automates the setup, Service Catalog gates provisioning, Config and Systems Manager close the loop after launch.

Foundation — the account boundary

AWS Organizations The account boundary itself. OUs, consolidated billing, and the attachment point for service control policies. M01 · M02
AWS Control Tower Automates the whole landing zone from a blueprint — OUs, shared accounts, controls, and Account Factory. M02
IAM Identity Center One place to manage workforce access across every account. SAML federation, SCIM provisioning, permission sets. M02
AWS CloudFormation The template layer underneath everything. Service Catalog products, Config rules, and account baselines are all stacks. M02 · M03

Preventive — stop it before it happens

AWS Service Catalog Curated portfolios of pre-approved products. Builders self-serve; constraints decide what they can actually launch. M03 · Lab 1
AWS Budgets Cost as a governance control. Thresholds, alerts, and budget actions that restrict provisioning when spend runs hot. M03

Detective — find out when it does

AWS Config Records what every resource looks like and how it changed, then evaluates that against rules. The audit backbone. M04 · Lab 3
AWS Systems Manager Groups resources, surfaces operational data, and runs the automation that actually fixes what Config flags. M04 · Lab 2
Amazon GuardDuty Continuous threat detection over CloudTrail, VPC flow logs and DNS logs, using threat intel and machine learning. M04
AWS Security Hub Aggregates findings across accounts and providers, runs standards checks, and prioritises what to act on first. M04

Supporting cast

AWS CloudTrail The API activity record. Centralised into the log archive account so no member account can quietly erase its own history. M02 · M04
Amazon CloudWatch Metrics, dashboards and the event bus that turns a detection into an action. M04
AWS Transit Gateway Lives in the network account of the landing zone, providing shared connectivity rather than per-account peering sprawl. M02
AWS IAM Still the engine underneath. Roles, policies, and the permission boundaries that constraints and SCPs build on. All modules

Deep dives

Three pages that go past what the slides cover. Each one takes a single idea the course only has time to state and turns it into something you can interrogate.

Interactive

Landing Zone Builder

Assemble a Control Tower landing zone one decision at a time. Add OUs, place the shared accounts, choose where a control attaches, and watch inheritance cascade through the hierarchy. Answers the question the static architecture slide cannot: what changes if I put this control one level lower?

Click-to-build Inheritance Shared accounts
Side by side

Preventive vs Detective

The same governance intent expressed two ways — once as a service control policy that refuses the API call, once as a Config rule that notices afterwards. Real policy documents, the states each control can be in, guidance categories, and an honest account of what each approach cannot do.

SCP Config rule Guidance tiers
Walkthrough

Governance Lifecycle

Implement, provision, operate — then back to implement. Follow one requirement ("no unversioned buckets") all the way round the loop and see which service owns each leg, where the handoffs are, and where most organisations break the cycle.

Define → detect Alert → remediate

Reference

Link library

Resource Library

Every whitepaper, blog post, documentation page, video and workshop referenced across the course, grouped by topic and annotated so you know why each one is worth your time. This is the page to bookmark.

Whitepapers Blogs Videos Docs