Listing Thumbnail

    Enterprise AWS Landing Zone Implementation with Control Tower

     Info
    Deploy a full-scale, well-governed AWS foundation that supports an IT estate of any size. VSO configures AWS Control Tower, AWS Organizations, and service control policies into a landing zone that scales from a single application to multi-organization enterprise shared services, with AWS IAM Identity Center for federated identity, AWS Config and AWS CloudTrail for detective controls and audit, AWS Transit Gateway or AWS Cloud WAN for multi-account and multi-Region connectivity, and Cloud Custodian, the open source policy engine hosted by the CNCF, for automated policy enforcement.

    Overview

    Deploy a full-scale, well-governed AWS foundation that supports an IT deployment of any size. VSO configures AWS Control Tower, AWS Organizations, and service control policies into a landing zone suited to everything from a single application to multi-organization enterprise IT shared services and support.

    The build covers account structure and organizational units in AWS Organizations, preventive controls through service control policies and detective controls through AWS Config rules, centralized logging and audit with AWS CloudTrail and Amazon CloudWatch Logs, federated identity through AWS IAM Identity Center, network foundations built on Amazon VPC with AWS Transit Gateway or AWS Cloud WAN and a centralized inspection VPC on AWS Network Firewall, and cost and tagging policy enforcement through Cloud Custodian and AWS Budgets. You get an environment that is ready to run production workloads and ready to govern them. For public sector and regulated customers, VSO can deliver the build on Landing Zone Accelerator on AWS, the AWS solution that layers compliance-aligned configuration on top of Control Tower.

    VSO can also stand up FogLifter® on the new landing zone, connecting AWS billing, infrastructure, CMDB, service, and operational records into one governed data foundation. That gives finance and operations accurate cost and asset visibility from the first month rather than a year in, once the spend is already hard to explain. Pair the landing zone with VSO managed cloud operations for monitoring, patching, and incident response, and the same foundation is what VSO uses to bring existing AWS accounts under centralized governance.

    Highlights

    • Enterprise-scale landing zone on AWS Control Tower and AWS Organizations, with controls enforced through service control policies and AWS Config.
    • Federated access through AWS IAM Identity Center, centralized audit through AWS CloudTrail and Amazon CloudWatch Logs.
    • Scales from a single application to multi-organization enterprise shared services.

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Pricing

    Custom pricing options

    Pricing is based on your specific requirements and eligibility. To get a custom quote for your needs, request a private offer.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Support

    Vendor support

    Sales Support: Please reach out to vsoapn@vso-inc.com  with any questions about VSO services, contract options, or pricing terms.

    Technical Support: For help with onboarding, configuration, or ongoing support for your VSO solution, please reach out to aws-support@vso-inc.com .

    Software associated with this service