AWSHow-To & HardeningRetrospectives

Control Tower Guardrail Selection Checklist

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from June 2019, written in 2026 with the benefit of hindsight.

Control Tower offers hundreds of controls. Use this checklist to choose a practical starting set.

Always enable

  • Mandatory controls (enabled automatically).
  • Region deny for regions you don't use.
  • Disallow changes to CloudTrail and AWS Config set up by Control Tower.
  • Disallow deletion of log archive buckets.

Identity and access

  • Detect IAM users with access keys older than 90 days.
  • Detect root user access keys and MFA status.
  • Disallow creation of IAM user access keys in workload accounts (if your teams use Identity Center).

Data protection

  • Detect S3 buckets without Block Public Access.
  • Detect unencrypted EBS volumes and RDS instances.
  • Require encryption at rest for new resources via proactive controls.

Network

  • Detect security groups allowing unrestricted SSH or RDP.
  • Detect internet gateways in accounts that shouldn't have them.

Compute

  • Detect EC2 instances not requiring IMDSv2.

For each control, decide

  • Which OUs it applies to (production may be stricter than sandbox).
  • Preventive or detective — prevent where the action is never legitimate.
  • Who receives findings and how quickly they must act.

Review

  • Revisit control selection twice a year as AWS adds new controls and your workloads change.
control tower guardrail selection checklistAWS Control Tower GA2019

More on this story