Skip to content

Lesson 08 β€” Enterprise Build Project

Learning Path

☁️ Phase 2 – AWS Cloud Security

πŸ“˜ Module 03 – AWS Organizations & Multi-Account Security


Congratulations!

You have completed all the lessons in this module.

Now it’s time to think like a Cloud Security Architect.

In this project, you will design the AWS Organization for CloudNova Technologies.

Rather than configuring AWS services, your goal is to design a secure, scalable and enterprise-ready AWS environment.


πŸ“š Project Information

Estimated Time: 3–5 Hours

Difficulty: Intermediate

Prerequisites: Lessons 01–07

Deliverable: Enterprise Architecture Design


CloudNova Technologies is rapidly expanding.

Current business profile:

  • 2,000+ Employees
  • 40 Development Teams
  • 120 Applications
  • Global Operations
  • Hybrid Workforce
  • Multiple Compliance Requirements

The executive leadership wants a cloud platform that can support the next five years of business growth.

You have been appointed as the Lead Cloud Security Engineer.

Your responsibility is to design the enterprise AWS Organization.


The new cloud platform must provide:

  • Secure account separation
  • Centralized governance
  • Centralized billing
  • Scalable architecture
  • Operational efficiency
  • Regulatory compliance
  • Secure workload isolation

Complete the following activities.


Create the CloudNova AWS Organization.

Include:

  • Management Account
  • Member Accounts
  • Organizational Units (OUs)

Your design should support future business growth.


Create Organizational Units for:

  • Security
  • Infrastructure
  • Workloads
  • Sandbox

Explain the purpose of each OU.


Design the following AWS accounts.

AWS Account Purpose
Management Governance & Billing
Security Operations Security Monitoring
Audit Compliance
Log Archive Log Storage
Networking Shared Networking
Shared Services Common Enterprise Services
CI/CD Deployment Pipelines
Development Development Environment
Testing Testing Environment
Staging Pre-Production
Production Live Workloads
Sandbox Learning & Innovation

Feel free to add additional accounts if required.


Describe how CloudNova will manage:

  • AWS Organizations
  • Organizational Units
  • Service Control Policies
  • AWS Control Tower

Keep the design simple and scalable.


Recommend how CloudNova will protect its AWS environment.

Consider:

  • Account isolation
  • Central logging
  • Security monitoring
  • Least Privilege
  • Governance guardrails

You do not need to configure these servicesβ€”simply describe the architecture.


CloudNova plans to launch:

  • AI Platform
  • Data Platform
  • European Region
  • Disaster Recovery Environment

Explain how your architecture can support future expansion without requiring a redesign.


Use the following architecture as your starting point.

CloudNova AWS Organization
Management Account
β”‚
β”œβ”€β”€ Security OU
β”‚ β”œβ”€β”€ Security Operations
β”‚ β”œβ”€β”€ Audit
β”‚ └── Log Archive
β”‚
β”œβ”€β”€ Infrastructure OU
β”‚ β”œβ”€β”€ Networking
β”‚ β”œβ”€β”€ Shared Services
β”‚ └── CI/CD
β”‚
β”œβ”€β”€ Workloads OU
β”‚ β”œβ”€β”€ Development
β”‚ β”œβ”€β”€ Testing
β”‚ β”œβ”€β”€ Staging
β”‚ └── Production
β”‚
└── Sandbox OU
β”œβ”€β”€ Student Labs
β”œβ”€β”€ Innovation
└── Research

This is a reference design only.

You may improve or expand it if needed.


Prepare a design document containing:

  • AWS Organization Diagram
  • Organizational Unit Structure
  • AWS Account List
  • Governance Strategy
  • Security Strategy
  • Future Growth Plan

Imagine you are presenting your design to CloudNova’s leadership team.

Be prepared to explain:

  • Why multiple AWS accounts are used.
  • Why Organizational Units are required.
  • Why governance is centralized.
  • How the design improves security.
  • How the architecture supports future business growth.

Task Status
Designed AWS Organization ☐
Created Organizational Units ☐
Designed AWS Accounts ☐
Defined Governance Strategy ☐
Defined Security Strategy ☐
Planned Future Expansion ☐
Prepared Architecture Diagram ☐
Completed Design Document ☐

Congratulations!

You can now:

  • Design an AWS Organization.
  • Build a scalable multi-account architecture.
  • Organize AWS accounts using Organizational Units.
  • Apply governance using Service Control Policies.
  • Understand how AWS Control Tower supports enterprise deployments.
  • Recommend a secure AWS architecture for enterprise environments.

These are core skills expected of a Cloud Security Engineer and Cloud Solutions Architect.


➑️ Lesson 09 β€” Module Review