Security & Compliance
Well-Architected
CloudAgent
White-Label
Pricing
Company
About UsWhat's NewTrust CenterDocs
Library
CFN Validation
Security & ComplianceWell-ArchitectedCloudAgent White-LabelPricingDocsAbout UsWhat's NewTrust CenterDocsLibraryCFN Validation
Security Controls
Service Control PoliciesResource Control PoliciesDeclarative PoliciesTag, Backup & AI Opt-Out PoliciesConfig RulesCloudWatch Alarms and Event RulesCloudFormation Guard RulesLogging & Monitoring ConfigurationsBackups & DRAuto Remediation RulesConformance PacksBilling and Cost ManagementS3 Bucket PoliciesSecurity Groups & NACLsIAM PoliciesVPC Endpoint Policies
AWS Services
VPC Security ControlsEC2 Security ControlsIAM Security ControlsS3 Security ControlsRDS Security ControlsOpenSearch/Elasticsearch Security ControlsEFS Security ControlsRoute53 Security ControlsAmazon DynamoDB & DAXECR Security ControlsEMR SecurityLambda SecurityCloudFormation SecurityCodeX Security ControlsCloudFront SecurityAWS Certificate Manager (ACM) SecurityAmazon GuardDutyAmazon InspectorAWS Security HubAWS Network FirewallRoute53 Resolver SecurityAmazon MacieAWS WAF & ShieldAWS Secrets ManagerAWS Systems ManagerAWS KMSAWS SSOLoad Balancers & Auto ScalingRDS Event SubscriptionsAWS Resource Access Manager (RAM)Amazon ECSAmazon EKSAmazon API GatewayAWS AppConfigAmazon AppFlowAWS App MeshAWS App RunnerAWS AppSyncApplication Auto ScalingAmazon AthenaAWS BatchAWS Billing ConductorAWS Clean RoomsAWS SNSAWS SQSAWS Service DiscoveryAWS Step FunctionsAWS CloudTrailAWS ConfigAmazon EventBridgeAWS CloudWatchAWS CognitoAmazon ConnectAWS GlueAWS Data Pipeline & Data SyncAmazon DetectiveAWS DevOps GuruAmazon DocumentDBAmazon ElastiCacheAWS Elastic BeanstalkAmazon FSxAmazon MQAmazon PrometheusAmazon CassandraAmazon FinSpaceAWS Fault Injection SimulatorAmazon GameLiftAWS Global AcceleratorAmazon GrafanaAWS IoT GreenGrassAWS IoT ServicesAWS Ground StationAmazon IVS (Interactive Live Streams)Amazon KinesisAWS LakeFormationAmazon LookoutAmazon Managed BlockchainAWS Media ServicesAWS Managed Apache AirflowAWS OpsWorksAWS OrganizationsAmazon PersonalizeAmazon QLDBAmazon RedshiftAmazon RekognitionAWS Resource ExplorerAWS Resource GroupsAmazon Lex & AlexaAWS RoboMakerAmazon SageMakerAWS Service CatalogAmazon SESAWS SimSpace WeaverAWS Support AppAWS TransferAWS X-RayAWS AmplifyAWS AppstreamAWS Audit ManagerAmazon BedrockAWS Cloud9AWS CloudHSMAmazon NeptuneAmazon Quicksight
Reference Guides
AWS Account Setup GuideEC2 Security StrategyS3 Security StrategyLogging & Monitoring Strategy Guide
Configuration Packages

Tag, Backup & AI Opt-Out Policies

A repository of AWS Organizations management policy templates: tag policies to standardize resource tagging, backup policies to enforce organization-wide backup plans, and AI services opt-out policies. Templates can be deployed using CloudFormation, Terraform, or AWS CLI scripts.

AWS (multi-service, tag-supported resources)
Enforce Allowed Values for a Required Cost-Allocation Tag

Defines a tag policy that requires the CostCenter tag key (exact case) to be one of a fixed set of values, and blocks EC2 resource creation that violates it.

CloudFormationTerraformAWS CLI
AWS Backup (multi-resource)
Enforce an Organization-Wide Backup Plan by Resource Tag

A backup policy attached at the org root (or a parent OU) that defines a named plan, the Regions it covers, a scheduled rule with a backup window, and tag-based resource selection — a centrally-mandated backup that member accounts cannot opt out of.

CloudFormationTerraformAWS CLI
AWS AI/ML services (multi-service)
Opt Out of AI Service Content Use by Default, Org-Wide

Sets an org-root policy that opts every account out of "content used for service improvement" for all current and future AI services, and locks the setting so child OUs and accounts cannot override it.

CloudFormationTerraformAWS CLI

© 2026 asecurecloud. All rights reserved.

  • Solutions
  • Docs
  • Pricing
  • About
  • What's New
  • Privacy Policy
  • Terms of Service