๐Ÿ•ฐ๏ธ ์ž‘์„ฑ์ผ : 2024.04.30

AWS Control Tower Enable ํ•˜๊ธฐ(2)

AWS Control Tower Enable ํ•˜๊ธฐ(3)

Organization Unit Best Practice

1. ๊ธฐ์กด Account Enroll ์‹œ ์ฃผ์˜ ์‚ฌํ•ญ

Control Tower๋ฅผ ํ™œ์„ฑํ™”ํ•˜๋ฉด Audit/Log Account๋งŒ ์ƒ์„ฑํ•˜๊ฒŒ ๋˜๋ฏ€๋กœ, ๊ธฐ์กด์˜ Account์—๋Š” ์˜ํ–ฅ์„ ์ฃผ์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ๊ธฐ์กด์˜ Account๋ฅผ Control Tower์˜ OU์— ๋“ฑ๋กํ•  ๊ฒฝ์šฐ ์ˆ˜๋™์œผ๋กœ ๋“ฑ๋กํ•˜๋ฏ€๋กœ, Control Tower๋งŒ์„ ํ™œ์„ฑํ™”ํ•œ๋‹ค๊ณ ํ•˜์—ฌ ๊ธฐ์กด Account์˜ ๋ฆฌ์†Œ์Šค์—๋Š” ์˜ํ–ฅ์„ ์ฃผ์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ๊ธฐ์กด Account๋ฅผ Enroll์‹œ ์•„๋ž˜์˜ ์‚ฌํ•ญ์„ ์ฒดํฌํ•ด์•ผํ•ฉ๋‹ˆ๋‹ค.

  1. Region Deny๋ฅผ ์„ค์ •ํ•˜๋ฉด ์ปจํŠธ๋กค ํƒ€์›Œ์— ๋“ฑ๋ก๋œ Account๋Š” ํ•ด๋‹น Region์— ๋Œ€ํ•œ ์•ก์„ธ์Šค ๊ถŒํ•œ์„ ์žƒ๊ฒŒ ๋ฉ๋‹ˆ๋‹ค. Region Deny๋ฅผ ์„ค์ •ํ•˜๊ธฐ ์ด์ „์— ๊ฐ Account์— ๋ฐฐํฌ๋œ Workload๋“ค์˜ Region์„ ํ™•์ธํ•˜๊ณ  ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.
  2. Control Tower์—์„œ org trail์„ ์‚ฌ์šฉํ•˜๊ธฐ๋กœ ์„ ํƒํ•œ ๊ฒฝ์šฐ ์ถ”๊ฐ€ ์š”๊ธˆ์ด ๋ถ€๊ณผ๋˜์ง€ ์•Š๋„๋ก account/org trail์„ ๋™์‹œ์— ๋กœ๊น…ํ•˜๊ณ  ์žˆ์ง€ ์•Š์€์ง€ ํ™•์ธ์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค.
  3. Enroll ํ•˜๋Š” Account์— AWSControlTowerExecution Role์ด ์ƒ์„ฑ๋˜์–ด ์žˆ๋Š”์ง€ ํ™•์ธํ•œ ํ›„์— Enroll ์ž‘์—…์„ ์ง„ํ–‰ํ•ฉ๋‹ˆ๋‹ค. ํ•ด๋‹น Role์ด ์ƒ์„ฑ๋˜์–ด ์žˆ์ง€ ์•Š์œผ๋ฉด Enroll์— ์‹คํŒจํ•ฉ๋‹ˆ๋‹ค.
  4. ๊ธฐ์กด ๊ณ„์ •์˜ AWS Config ๋ฆฌ์†Œ์Šค๊ฐ€ ์žˆ์„ ๊ฒฝ์šฐ Enroll์— ์‹คํŒจ ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด ๊ฒฝ์šฐ AWS Config๋ฅผ ์ˆ˜์ • ํ›„ Enrollํ•ด์•ผํ•˜๋ฉฐ, โ€˜3. AWS Config / CloudTrail์— ๋Œ€ํ•œ ์žฌ์‚ฌ์šฉโ€™์— ๋ช…์‹œํ•œ ๋Œ€๋กœ ๊ธฐ์กด์˜ Config๋ฅผ ์ˆ˜์ •ํ•˜์—ฌ Enroll ์ž‘์—…์„ ์ง„ํ–‰ํ•ฉ๋‹ˆ๋‹ค.
  5. ์ž์ฃผ ๋ฐœ์ƒํ•˜๋Š” ์ด์Šˆ์— ๋Œ€ํ•œ Trouble-shooting์€ ํ•ด๋‹น ๋งํฌ์—์„œ ํ™•์ธ ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

2. ๊ธฐ์กด Log / Security Account๋ฅผ Control Tower๋กœ ์ด๊ด€

๊ธฐ์กด์˜ Landing Zone์„ ๊ตฌ์„ฑํ•ด๋‘์—ˆ๊ณ  Log Account์™€ Security Account๊ฐ€ ๊ตฌ์„ฑ๋˜์–ด ์žˆ๋‹ค๋ฉด, Control Tower๋ฅผ ํ™œ์„ฑํ™” ํ•  ๋•Œ ๊ธฐ์กด์˜ ๊ณ„์ •์„ Control Tower์˜ Log ๋ฐ Audit Account๋กœ ์„ ํƒํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ธฐ์กด์˜ ๋ณด์•ˆ ๋ฐ ๋กœ๊น… ๊ณ„์ •์„ Control Tower๋กœ ์ด๊ด€ํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” ํ•ด๋‹น ๋งํฌ์— ๋‚˜์—ด๋œ ๊ณ ๋ ค ์‚ฌํ•ญ์„ ์ฐธ๊ณ ์‹œ๋ฉด ๋ฉ๋‹ˆ๋‹ค.

Log ๋ฐ Security Account๋ฅผ Control Tower์— ๋“ฑ๋กํ•œ๋‹ค๊ณ ํ•ด์„œ ๊ธฐ์กด ๊ณ„์ •์— ์ƒ์„ฑ๋˜์–ด ์žˆ๋Š” ๋ฆฌ์†Œ์Šค๋ฅผ ์ œ๊ฑฐํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ Control Tower์—์„œ ๋ฆฌ์ „ ์ ‘๊ทผ ์ •์ฑ…์ด ์ ์šฉ๋˜์–ด ์žˆ๋‹ค๋ฉด, ๊ฑฐ๋ถ€๋œ ๋ฆฌ์ „์˜ ์•ก์„ธ์Šค๋ฅผ ์ฐจ๋‹จํ•  ์ˆ˜ ์žˆ์œผ๋‹ˆ Control Tower Set-up ์‹œ ์‚ฌ์šฉ ํ•  ๋ฆฌ์ „์„ ์ถฉ๋ถ„ํžˆ ์ฒดํฌํ•ด์•ผํ•ฉ๋‹ˆ๋‹ค.

์•„๋ž˜๋Š” ๊ธฐ์กด์˜ Account ๋“ค์„ Log / Audit Account์— ๋“ฑ๋กํ–ˆ์„๋•Œ์˜ ์˜ˆ์‹œ ์Šคํฌ๋ฆฐ์ƒท์ž…๋‹ˆ๋‹ค

๊ธฐ์กด Log ๊ณ„์ •์„ Control Tower๋กœ ์ด๊ด€ํ•œ๋‹ค๋ฉด ๊ธฐ์กด Trail์€ ์œ ์ง€๋˜์–ด์žˆ๊ณ , Control Tower์—์„œ ์ƒˆ๋กœ์šด Trail์„ ํ”„๋กœ๋น„์ €๋‹ํ•ฉ๋‹ˆ๋‹ค.

Untitled