More Info:

Ensure that Amazon Organizations service is currently in use to gain central control over the use of AWS services across multiple AWS accounts (using Service Control Policies) in order to help you comply with the security and compliance policies within your company. AWS Organizations is an account management tool that enables you to centralize multiple AWS accounts into an organization that you create and administer. Amazon Organizations is available to all customers at no additional cost and has two main feature sets: Consolidated Billing features – which provides basic management tools that you can use to centrally manage all the accounts (master and member accounts) within your organization. With this feature you can get a combined view of AWS charges incurred by all your accounts and also take advantage of pricing benefits from aggregated usage.

Risk Level

Medium

Address

Security

Compliance Standards

CBP

Triage and Remediation

Remediation

The misconfiguration “AWS Organizations Should Be Used” is related to the lack of proper organization and management of AWS accounts. This can lead to security and compliance risks, as well as increased costs and complexity. To remediate this misconfiguration, you can follow the below steps:

  1. Log in to the AWS Management Console and navigate to the AWS Organizations service.

  2. Click on the “Create organization” button to create a new organization.

  3. Follow the prompts to set up your organization, including creating a root account and adding member accounts.

  4. Once your organization is set up, you can use the AWS Organizations console to manage and govern your AWS accounts, including setting policies and controls to ensure compliance and security.

  5. You can also use AWS Organizations to simplify billing and cost management across your accounts, by consolidating billing and using cost allocation tags.

  6. Finally, make sure to regularly review and update your organization’s policies and controls to ensure they are up-to-date and effective in mitigating risks and maintaining compliance.

By following these steps, you will be able to remediate the “AWS Organizations Should Be Used” misconfiguration and ensure that your AWS accounts are properly organized and managed.

Additional Reading: