Overview
CloudZone Landing Zone is a solution that helps customers quickly set up a secure, multi-account AWS environment based on AWS best practices. With a large number of design choices, setting up a multi-account environment can take a significant amount of time, involve the configuration of multiple accounts and services, and require a deep understanding of AWS services.
This solution can help save time by automating the set-up of an environment for running secure and scalable workloads while implementing an initial security baseline through the creation of core accounts and resources. It also provides a baseline environment to get started with a multi-account architecture, identity and access management, governance, data security, network design, and logging.
The goal of a Landing Zone is to create a baseline of AWS accounts, networks and security policies – all according to decided best practices.
The basic elements of Landing Zone focus around multi-account monitoring, centralized logging, governance, network design, identity and access management (IAM), automation using infrastructure as code, creating a security baseline and an option to expand AWS environments through an Account Vending Machine add-on.
CloudZone Landing Zone is made for companies that want to set up a multi-account environment but may not have the time or skills to implement a configuration of multiple accounts and services – since this may require an expert understanding of AWS services. Landing Zone will help automate the setup of a multi-account AWS environment that is secure and scalable.
Highlights
- ## Networking and network security - Transit Gateways, specific per OU or default - For each account deployed VPC with pre-configured connection to specified TGW - Centralized/Shared VPC for AWS Endpoints (Gateway and Interface) - Centralized VPC with AWS Network Firewall for Egress and east-west Inspection
- ## Security - Creates, deploys and applies Service Control Policies - Creates, deploys and applies AWS Config Rules using AWS StackSets - Sets Up SNS Alerting topics - Deploys custom Config rules - Deploys Security Hub Administrator account to Audit account, all the other accounts are joined as member accounts - Enables central deployment of GuardDuty - Centralized reports to Audit account - Deploys AWS IAM Access Analyzer to Audit account
- ## Budget Management - The Solution allows to link budget to each newly created account and configure alerting thresholds - Budget alerts are configured to send notifications via SNS topic
Details
Pricing
Custom pricing options
How can we make this page better?
Legal
Content disclaimer
Support
Vendor support
CloudZone provide 24/7 support by our interanl cloud proffesional team, please contact at: support@cloudzone.ioÂ