Member accounts must be prevented from leaving the organization or disabling central security services. Which governance control should the architect apply?
Select an answer to reveal the explanation.
Short Explanation
SCPs are the charter amendments member cities can’t quietly repeal. Deny LeaveOrganization and deny turning off the mandated security stack. Handshakes, deletable local IAM, or blog posts aren’t enforceable governance.
Full Explanation
Service control policies attach at the organization, OU, or account level and restrict what member accounts can do even with AdministratorAccess. Denying organization leave actions and denying API calls that disable central security services (for example GuardDuty, CloudTrail, or Security Hub as mandated) keeps accounts inside the governed boundary. Local IAM alone can be removed by account admins; informal agreements and documentation lack enforcement. SCPs are the appropriate multi-account governance mechanism for these denies.