Summary
In this chapter, we focused on large-scale cloud environments that contain multiple accounts.
We discussed how to deploy a multi-account organizational structure and how to set policies to check and enforce compliance over our entire organization.
Then, we learned how to achieve automation in cloud environments using IaC – from built-in services from AWS, Azure, and GCP, to a more cloud-agnostic solution called Terraform.
Finally, we reviewed security-related services from AWS, Azure, and GCP that allow us to maintain patch management, compliance, and threat management over large organizations containing multiple accounts/subscriptions/projects from a central place.
The information in this chapter should have helped you learn how to manage security in large cloud environments.