Control Tower Guardrail Selection Checklist
Retrospective: this article looks back at events from June 2019, written in 2026 with the benefit of hindsight.
Control Tower offers hundreds of controls. Use this checklist to choose a practical starting set.
Always enable
- Mandatory controls (enabled automatically).
- Region deny for regions you don't use.
- Disallow changes to CloudTrail and AWS Config set up by Control Tower.
- Disallow deletion of log archive buckets.
Identity and access
- Detect IAM users with access keys older than 90 days.
- Detect root user access keys and MFA status.
- Disallow creation of IAM user access keys in workload accounts (if your teams use Identity Center).
Data protection
- Detect S3 buckets without Block Public Access.
- Detect unencrypted EBS volumes and RDS instances.
- Require encryption at rest for new resources via proactive controls.
Network
- Detect security groups allowing unrestricted SSH or RDP.
- Detect internet gateways in accounts that shouldn't have them.
Compute
- Detect EC2 instances not requiring IMDSv2.
For each control, decide
- Which OUs it applies to (production may be stricter than sandbox).
- Preventive or detective — prevent where the action is never legitimate.
- Who receives findings and how quickly they must act.
Review
- Revisit control selection twice a year as AWS adds new controls and your workloads change.