Ensure centralized root access in AWS Organizations
Ensure authorization guardrails for all AWS Organization accounts
Ensure Organizations management account is not used for workloads
Ensure Organizational Units are structured by environment and sensitivity
Ensure delegated admin manages AWS Organizations policies
Ensure delegated admins manage AWS Organizations-integrated services
Ensure multi-factor authentication (MFA) is enabled for all IAM users that have a console password
Ensure credentials unused for 45 days or more are disabled