
I automated an AWS Security Maturity Model recommendation across 40 accounts — design decisions included
The AWS Security Maturity Model has a recommendation in Phase 1 — Quick Wins that seems trivial: assign a security contact in each account of your AWS Organization. It's not glamorous. It doesn't have a complex architecture diagram. It doesn't require enabling any new service. It's literally filling out a form with a name, an email, and a phone number. And yet, in most organizations I work with in LATAM, it isn't done. Not because nobody knows about it — but because in environments with dozens of accounts, "filling out a form" becomes a manual process that depends on someone remembering, having access, and doing it correctly in each account. And when Control Tower provisions a new account, that process starts from scratch all over again. The question that kicked off this project was simple: why am I doing this by hand? The problem An active AWS Organization isn't static. New projects arrive, development environments get created, teams join. With Control Tower, provisioning a new accoun
Continue reading on Dev.to Python
Opens in a new tab




