AWS Organizations
What this tool proves, in the authored overlay. Every recipe below names AWS Organizations; the controls are what their output is evidence for. The mapping is this project’s opinion (overlay v3.0.0) — the upstream FedRAMP rules name no vendor and no product.
Recipes calling AWS Organizations (2)
- partialexternal-access-inventory-and-trust-boundaryquarterly
The machine-generated inventory of every resource an external entity can reach — IAM Access Analyzer's active ExternalAccess findings — read against the declared zone of trust, so the terms-and-conditions review has a list to work from rather than a memory
- partialchange-authority-restrictions-and-enforcementcontinuous
The enforced half of who may change what: the service control policy type actually enabled in the organization root, the customer-authored SCPs and the roots, OUs and accounts each one is attached to, and the permissions boundary carried by every principal your own tagging marks as a change authority
Controls it carries evidence for (2)
The reverse of the join above. A mark here is the control’s own grade across the whole corpus, not its grade from this tool alone — a control this tool partly proves may be fully proved with another.
Tool names are canonical, from data/overlays/aws-services.json and data/overlays/pipeline-tools.json. The two overlays that name services spelled five of them two ways; a page keyed on the raw string would have split those in half.