VeUP
← All case studies
AWS Config · Org-wide Config recording
An AI meeting-intelligence SaaS companyIdentity protected

CLIPr: remediating a 13-account Control Tower landing zone for a clean security audit

Well-Architected ReviewLanding zone remediationPreventive controlsMulti-account segmentationCentralized workforce identityCentralized immutable audit loggingAudit-readiness evidence packDay-2 runbooks & team enablementHigh-risk-issue remediation roadmapResilience-gap assessment (RTO/RPO)Observability-gap assessmentAdvisory
13/13
accounts validated and governed in Control Tower
Audit-ready
complete evidence set for the third-party audit
Built to carry
SOC 2, PCI-DSS, and HIPAA work ahead
AWS ConfigAWS Control TowerAWS Security HubAWS CloudTrail

An audit does not accept “Config should be on everywhere.” In the audit-readiness remediation of this customer’s 13-account AWS Organization, VeUP verified AWS Config recording in every member account — one of the load-bearing validations that turned a drifted Control Tower landing zone into an estate whose governance can be demonstrated, not asserted.

The challenge

The customer’s AWS Organization — 13 member accounts on a Control Tower landing zone — had drifted from its intended baseline, and a third-party security audit was coming. Configuration recording is the control every other control leans on: without Config reliably recording in every account, there is no configuration history, no drift evidence, and no way to prove the remediation itself stuck. But in a drifted landing zone, recording is exactly the kind of control that fails silently — disabled in one account during troubleshooting, never enabled in another, delivering to a broken channel in a third — and nobody can say which without checking all thirteen.

The solution

VeUP’s infrastructure-validation workstream treated Config recording as something to prove per account, not assume per organization. Every one of the 13 member accounts was checked: recorder present, recording enabled, delivering correctly — with the validation performed alongside the enrollment verification of each account into Control Tower, so governance and its evidence channel were confirmed together. The Config validation sat inside the broader remediation VeUP delivered for the audit: AWS Security Hub enabled organization-wide with the FSBP and CIS standards, CloudTrail logging remediated, IAM Identity Center reconciled, SCP guardrails hardened, organizational AWS Backup policies deployed, and StackSet drift checked — producing the remediation, validation, and documentation the customer needed to walk into a governance or compliance audit with evidence instead of intentions.

Production outcomes

KPIResult
Recording coverageAWS Config recording verified across 13 of 13 member accounts — configuration history restored as a provable, organization-wide control.
Governance validatedAll 13 account enrollments in Control Tower validated in the same pass — the landing zone’s governance and its evidence layer confirmed together.
Audit readinessConfig validation delivered within the full remediation — org-wide Security Hub (FSBP + CIS), remediated CloudTrail, reconciled Identity Center, hardened SCPs, and Backup policies — with documentation an auditor can follow.
Lessons & continuationIn multi-account estates, controls decay per account and must be validated per account; Config recording is the first thing to verify in any remediation, because it is the instrument every later claim is measured with.
AWS services in production
AWS Config (13/13 accounts)AWS Control Tower (v4.0)AWS Security Hub (FSBP + CIS)AWS CloudTrailAWS IAM Identity CenterAWS Organizations (SCPs)AWS Backup (org policies)