Skip to content

Compliance and governance tools

This section covers the services that tell you whether an AWS estate is still in the shape you intended, and help keep it there.

AWS Config is the foundation. It records how every resource is configured over time and evaluates that record against rules, and most other compliance tooling reads from it. AWS Control Tower builds on Config and AWS Organizations to set up a governed multi-account landing zone with preventive, detective and proactive controls. When the question is “is this estate compliant, and will it stay that way?”, start with those two.

The remaining services answer narrower questions. Trusted Advisor and Compute Optimizer look for waste and risk in what is already running. AWS Health reports when AWS itself is the cause of a problem, so an incident is not chased inside your own systems. License Manager tracks vendor software entitlements, so you can prove what you are allowed to run.

AWS OpsWorks, which once covered configuration management in this space, has reached end of life. Its page is kept to record what replaced it, for anyone arriving from older guidance.