Terraform module to provision Service Control Policies (SCP) for AWS Organizations, Organizational Units, and AWS accounts
-
Updated
Jul 30, 2026 - HCL
Terraform module to provision Service Control Policies (SCP) for AWS Organizations, Organizational Units, and AWS accounts
Detect phantom IAM users, decode leaked AWS Bedrock and Claude Platform API keys, and prevent LLMjacking. CLI + SCPs + SIEM detection rules.
Awesome AWS service control policies (SCPs), Resource Control Policies (RCPs), and other organizational policies
Scan an AWS Organization and generate Terraform for the SCPs and RCPs your accounts already comply with, placed at the highest safe level.
Enforce encryption by tagging S3 buckets with KMS key ARNs
Enforce Intelligent Tiering by tagging S3 buckets (closest thing to changing S3's default storage class!)
Service Control Policies we use in the AWS Organizations configuration for the Hacker Sandbox
Reference Service Control Policy (SCP) examples for Tencent Cloud Organization — deny-list guardrails for privileged access, region controls, security-service protection, and compliance.
To associate your repository with the service-control-policy topic, visit your repo's landing page and select "manage topics."