Guide
Five Free Service Control Policies to Use Today
This guide provides five ready-to-use AWS Service Control Policies for strengthening cloud security. The policies prevent perimeter bypasses through unauthorized SageMaker presigned URLs and Lambda function URLs, block tampering with CloudTrail, GuardDuty, EC2 logs, and S3 public-access controls, and enforce foundational practices by restricting default VPCs, IAM users, access keys, and disabling EBS encryption. Additional policies require approved S3 encryption and enforce separation of duties for IAM and AWS Identity Center administration. Each example includes policy code and implementation notes for exemptions and exceptions. The guide offers a practical starting point for applying organization-wide guardrails, reducing privilege escalation, protecting security controls, and improving
