AWS Security ChangesHomeSearch

AWS managedservices: Add AWS Control Tower governance guidance for MALZ transition

Service: managedservices · 2026-09-27 · Documentation medium

File: managedservices/latest/userguide/transition-to-accelerate.md · Type: logging

Summary

Adds a new optional section explaining how MALZ customers can enable AWS Control Tower during the AMS Accelerate transition, covering preventive guardrails/controls, centralized logging, CloudTrail organization trail changes, CloudWatch Logs retention differences, and Operations on Demand support.

Security assessment

The change documents security-relevant governance capabilities (preventive guardrails comparable to SCPs, centralized detective controls, AWS Config/CloudTrail integration, drift detection) and explicitly notes audit-logging changes such as shorter CloudWatch Logs retention and a single organization trail. It is guidance/best-practice documentation rather than a fix for a specific vulnerability or incident, so it is security-adjacent (medium) rather than high.

Evidence

+  * Preventive guardrails (controls) comparable to the Service Control Policies you had in MALZ

Diff

diff --git a/managedservices/latest/userguide/transition-to-accelerate.md b/managedservices/latest/userguide/transition-to-accelerate.md
index 3a135f856..2c18b835b 100644
--- a//managedservices/latest/userguide/transition-to-accelerate.md
+++ b//managedservices/latest/userguide/transition-to-accelerate.md
@@ -7 +7 @@
-How AMS Advanced and Accelerate differHow the transition worksHow we support you through the transitionWhat changes at a glanceEC2 instance accessAMS Amazon Machine Images (AMIs)Endpoint securityMonitoring and alarmsBackup managementChange management and configuration compliancePatch managementTimeline and supportRelated resources
+How AMS Advanced and Accelerate differHow the transition worksHow we support you through the transitionWhat changes at a glanceEC2 instance accessAMS Amazon Machine Images (AMIs)Endpoint securityMonitoring and alarmsBackup managementChange management and configuration compliancePatch managementLanding zone governance with AWS Control TowerTimeline and supportRelated resources
@@ -40,0 +41,2 @@ This guide helps you understand what is changing during the transition and what
+  * Landing zone governance with AWS Control Tower (optional)
+
@@ -54 +56 @@ AMS Accelerate uses a detect-and-respond model: you make changes directly using
-Both plans share the same core operational services: monitoring, incident management, patch management, backup management, cost optimization, reporting, and dedicated CSDM and CA support. Some capabilities that are unique to AMS Advanced (such as the RFC system, managed access, and endpoint security) don't carry over directly—the table in the following section explains what's available in Accelerate and what you manage yourself.
+Both plans share the same core operational services: monitoring, incident management, patch management, backup management, cost optimization, reporting, and dedicated Cloud Service Delivery Manager (CSDM) and Cloud Architect (CA) support. Some capabilities that are unique to AMS Advanced (such as the RFC system, managed access, and endpoint security) don't carry over directly—the table in the following section explains what's available in Accelerate and what you manage yourself.
@@ -92 +94 @@ Capability | Available in Accelerate? | What's different
-**Landing zone management** | Customer-managed | For MALZ customers, core accounts (Management, Shared Services, Networking, Security, Logging) are handed over to you. AMS removes AMS-managed infrastructure from these accounts during offboarding. Your VPCs, subnets, and network configurations remain in place and are yours to manage.  
+**Landing zone management** | Customer-managed (MALZ: AWS Control Tower available) | For MALZ customers, AMS can transition your multi-account landing zone to AWS Control Tower, an AWS-native service that provides automated account provisioning, preventive guardrails, and centralized governance. Your core accounts (Management, Shared Services, Networking, Security, Logging) carry forward into AWS Control Tower's account structure. AMS removes AMS-managed infrastructure during offboarding; your VPCs, subnets, and network configurations remain in place. For more information, see Landing zone governance with AWS Control Tower (optional).  
@@ -239,0 +242,65 @@ The following operational details change after migration:
+## Landing zone governance with AWS Control Tower (optional)
+
+For multi-account landing zone (MALZ) customers, AMS Advanced manages your multi-account landing zone today, handling account provisioning, preventive guardrails, and centralized logging and configuration compliance across your organization. After the transition to AMS Accelerate, landing zone management becomes customer-managed: your organization, accounts, and network configurations remain in place and are yours to operate. This section doesn't apply to single-account landing zone (SALZ) customers.
+
+To help you maintain centralized, automated governance in Accelerate, AWS offers AWS Control Tower, an AWS-native service purpose-built for multi-account environments. AWS Control Tower provides automated account provisioning, preventive guardrails, and centralized configuration compliance, giving you a supported path to continue the governance practices you rely on today. You can optionally have AMS enable AWS Control Tower as part of your transition engagement.
+
+MALZ and AWS Control Tower share the same foundational multi-account architecture. Your MALZ environment already has dedicated accounts for security operations (security account) and centralized logging (logging account), which map directly to AWS Control Tower's audit account and log archive account. The management account is the same in both models. Because these accounts already exist, enabling AWS Control Tower imports and builds on them rather than creating new ones. Your existing log storage, security tooling, and organizational structure carry forward.
+
+###### Important
+
+AWS Control Tower can only be enabled during the transition, not after it. Before your transition is initiated, tell your CA if you want AWS Control Tower enabled. If you opt in, AMS enables it as part of your engagement. If you don't opt in, your accounts transition to Accelerate without it and you would need to enable AWS Control Tower yourself post-transition. All MALZ core accounts (Management, Security, Logging, Shared Services, Networking) must be transitioned to Accelerate before or during the AWS Control Tower enablement. Deciding early lets your CA plan prerequisites and sequencing into your transition.
+
+###### What AWS Control Tower provides
+
+After you enable AWS Control Tower, you have the following capabilities:
+
+  * Automated account provisioning through Account Factory
+
+  * Preventive guardrails (controls) comparable to the Service Control Policies you had in MALZ
+
+  * Centralized detective controls and logging managed from your management account
+
+
+
+
+AWS Control Tower also offers the following capabilities that go beyond what MALZ provides:
+
+  * Governance dashboard – A centralized view of provisioned accounts, enabled controls, and noncompliant resources organized by account and organizational unit (OU).
+
+  * Proactive controls – Controls that evaluate resources before deployment (through AWS CloudFormation hooks), preventing noncompliant resources from being created in the first place.
+
+  * Drift detection – Continuous monitoring of your landing zone that alerts you when accounts or OUs diverge from your baseline configuration.
+
+
+
+
+After you enable AWS Control Tower, you can choose which controls to apply from the [AWS Control Tower controls reference](https://docs.aws.amazon.com/controltower/latest/controlreference/controls-reference.html), which spans multiple compliance frameworks, so you can match or extend the protections you had under AMS Advanced.
+
+###### What AWS Control Tower doesn't provide
+
+AWS Control Tower doesn't recreate MALZ networking. Your networking account transitions to Accelerate just like other application accounts. Account Factory can create a standalone VPC in a new account, but it doesn't attach accounts to a transit gateway or set up shared egress and shared-services connectivity the way MALZ did. Cross-account networking remains your responsibility.
+
+###### What to expect during the transition
+
+Enabling AWS Control Tower imports your current organization and accounts without creating new organizational units. Your existing security and logging accounts map to their AWS Control Tower equivalents (audit and log archive). AWS Config and AWS CloudTrail integration are enabled as part of setup, with other service integrations available self-service. AWS Control Tower requires AWS Config to be disabled in your accounts beforehand, which AMS coordinates for you. After setup, adding or changing controls is self-service.
+
+When you enable AWS Control Tower, AMS replaces your MALZ AWS CloudTrail setup with the AWS Control Tower organization trail. This is a deliberate switch to a single, organization-wide trail that changes how audit logs are structured:
+
+  * One organization trail instead of per-account trails – MALZ deploys an in-account trail in every account; AWS Control Tower uses a single organization trail from your management account that automatically covers all member accounts.
+
+  * CloudWatch Logs retention is shorter (14 days instead of 10 years) – Your durable audit history is preserved in the Amazon S3 log bucket in your log archive account; historical Amazon S3 logs aren't deleted. If you depend on long-lived CloudWatch Logs, plan for this change or update the retention setting self-service.
+
+  * Logs are centralized, not per-account – MALZ writes events to a CloudWatch log group in each account; AWS Control Tower consolidates all events into the management account.
+
+  * Notifications move to your home Region – MALZ delivers trail Amazon SNS notifications across all Regions from the security account; AWS Control Tower delivers from the log archive account in your home Region only.
+
+
+
+
+If these differences affect your workflows, discuss them with your CA before opting in.
+
+###### Additional support through Operations on Demand
+
+AWS Control Tower is designed to be self-service for day-to-day governance tasks. For occasional customizations or one-off operational needs such as OU restructuring, SCP changes, drift remediation, SSO user management, AWS Control Tower upgrades, or building custom account-vending pipelines beyond what Account Factory provides, AMS Accelerate offers Operations on Demand (OOD). OOD is purchased in 20-hour monthly blocks with no long-term commitment. Talk to your CSDM or CA to scope an engagement.
+