Generated by Merlin Studio (https://app.merlin-studio.cloud). Licensed under the Apache License, Version 2.0 (https://www.apache.org/licenses/LICENSE-2.0).
Score: 100/100 | Grade: A
| Category | Check | Status | Weight | Explanation |
|---|---|---|---|---|
| Account Hierarchy | Mandatory accounts (Management/LogArchive/Audit) | ✅ PASS | 25 | All three mandatory accounts have emails configured. log_archive, audit use PLACEHOLDER_* values — replace with real, globally-unique mailboxes before bootstrap (see PLACEHOLDERS.md). |
| Account Hierarchy | OU structure | ✅ PASS | 15 | OU structure 'by_business_unit' with 4 workload account(s). |
| IAM | IAM Identity Center | ✅ PASS | 20 | Identity provider: iam_idc, 5 permission set(s). |
| IAM | SCPs (Service Control Policies) | ✅ PASS | 15 | 7 effective SCP(s) attached (Deny-Root-Access, Guardrails-Sandbox, Guardrails-Security, Protect-Security-Services, Quarantine-Policy, Region-Restriction-EUOnly, Require-IMDSv2). |
| Networking | VPC count vs profile | ✅ PASS | 10 | 5 VPC(s) for profile advanced (expected 2-21, +1 for compliance overlay VPCs). |
| Networking | Transit Gateway | ✅ PASS | 15 | Transit Gateway enabled for cross-VPC/region routing. |
| Networking | VPC Flow Logs | ✅ PASS | 10 | Flow Logs enabled on all 5 VPC(s). |
| Networking | Public/private subnet separation | ✅ PASS | 10 | All VPCs have private subnets alongside any public ones. |
| Security Baseline | GuardDuty | ✅ PASS | 20 | GuardDuty enabled with appropriate protection features. |
| Security Baseline | Security Hub | ✅ PASS | 15 | Security Hub on with 3 standard(s). |
| Security Baseline | CloudTrail org-trail | ✅ PASS | 20 | Multi-region organization-level CloudTrail configured. |
| Security Baseline | AWS Config | ✅ PASS | 10 | AWS Config recorder enabled. |
| Security Baseline | CMK encryption | ✅ PASS | 10 | CMK log encryption enabled with 3 declared key(s). |
| Advanced Security | Macie | ✅ PASS | 15 | Macie enabled — appropriate for declared compliance/sensitivity. |
| Advanced Security | Inspector | ✅ PASS | 10 | Inspector enabled for ECR / EC2 / Lambda vulnerability scanning. LZA users: enable out-of-band — see security-config.yaml header (LZA 1.14.x has no native Inspector block). OpenTofu / CDK / tfvars render natively. |
| Advanced Security | Inspector (LZA enablement) | 0 | LZA bundle only: Landing Zone Accelerator 1.14.x has no native Amazon Inspector block, so Inspector stays OFF until you run the out-of-band enablement (aws inspector2 enable + aws inspector2 update-organization-configuration) — see the security-config.yaml header. This row does not affect the score; it flags the manual step so '✅ PASS' isn't read as 'deployed by LZA'. |
|
| Advanced Security | Network Firewall | ✅ PASS | 15 | Centralized egress inspection is live: AWS Network Firewall in the 'inspection' VPC, with spokes routing 0.0.0.0/0 through the Transit Gateway to the firewall (appliance mode) before NAT/IGW. CDE traffic is isolated in its own TGW route domain. |
| Logging | Centralized log bucket | ✅ PASS | 15 | Centralized log bucket: acmecorp-central-logs-PLACEHOLDER_ACCOUNT_ID_LogArchive. |
| Logging | Log retention | ✅ PASS | 15 | 1825 days meets required floor (365). |
| Compliance | Region pinning vs sovereignty | ✅ PASS | 20 | All enabled regions (5) within EU sovereignty zone. |
| Compliance | HSM-backed CMK | ✅ PASS | 10 | HSM-backed KMS declared org-wide (kms_use_hsm=true). See PLACEHOLDERS.md for the CloudHSM custom-key-store ID. |
| Compliance | GovCloud alignment | ✅ PASS | 5 | GovCloud not required. |
| Backup & DR | AWS Backup vault | ✅ PASS | 15 | AWS Backup vault with Vault Lock enabled. |
| Backup & DR | Cross-region backup copy | ✅ PASS | 10 | Backups copied to secondary region: eu-west-1. |
| Cost | Budgets + Anomaly Detection | ✅ PASS | 10 | Both Budgets and Cost Anomaly Detection enabled. |