About This Architecture
AWS Security Reference Architecture implementing multi-account strategy with Organizations, GuardDuty threat detection, Security Hub aggregation, WAF and Shield for perimeter defense, IAM and Cognito for identity, and CloudTrail with Config for compliance. Follows AWS prescriptive guidance for centralized security governance. Fork this diagram on Diagrams.so to customize the security controls and account structure for your organization's compliance requirements. Source: https://docs.aws.amazon.com/prescriptive-guidance/