Overview
Service Overview
Cloud Control service is a managed service that supports building, operating, and managing a multi‑account environment easily and securely on the Samsung Cloud Platform.
The Cloud Control service automates an organization’s cloud governance (security, compliance, standardization, etc.) and provides consistent, centralized account and resource management based on Samsung Cloud Platform best practices.
Features
The Cloud Control service offers the following advantages.
- Landing Zone (Landing Zone) Automatic Provisioning: Automatically configure essential infrastructure such as Samsung Cloud Platform accounts, organizational units (OU), guardrails, logging, etc. * In a standardized environment, you can create new accounts and invite existing accounts.
- Centralized governance and policy enforcement: Automatically apply security, compliance, and operational policies (guardrails) across the entire organization. * Provides policy violation detection and monitoring capabilities.
- Multi-Region and Scalability: You can apply the same governance and policies across multiple Samsung Cloud Platform regions.
Provided Features
The Cloud Control service provides the following features.
- Automated Landing Zone (Landing Zone) Setup: Security, logging, and account structure based on Samsung Cloud Platform best practices are configured automatically.
- Apply Guardrail
- Preventive Guardrail : Blocks the creation of resources that violate policy
- Detective Guardrail: Automatically detect and notify policy-violating resources
- Integrate with ACP, Samsung Cloud Platform Config Inspection, etc., of the Samsung Cloud Platform Organization
- Dashboard provision: You can visually monitor the account, OU, guardrail implementation status, and compliance status of the entire organization.
- Centralized logging and auditing
- Provides centralized log storage and audit accounts for all accounts via Logging&Audit, Object Storage, Config Inspection, and other methods.
- ID and Permission Management Integration: Integrates with Samsung Cloud Platform ID Center to manage account-level access control and permission groups.
- Monitoring and Notification (Notification) feature: Provides real-time alerts for policy violations, Cloud Control configuration changes, etc.
Component
Landing Zone (Landing Zone)
The basic architecture of a standardized Samsung Cloud Platform environment, including governance, security, networking, and logging, is as follows.
| Category | Detailed description |
|---|---|
| admin account |
|
| Log account |
|
| audit account |
|
Guardrails
The guardrails that are automatically applied for policy violation detection and prevention (detect/prevent type) rules, and security/compliance standards are as follows.
| Category | Detailed description |
|---|---|
| Preventive Guardrail | Preemptive blocking role to prevent policy violations
|
| Detection Guardrail | Continuously monitor for policy violations or abnormal configurations, and provide alerts when violations occur
|
Baseline (Baseline)
The essential resources and configuration sets, such as security, logging, and networking, that are automatically deployed per account are as follows.
| Category | Detailed description |
|---|---|
| AuditBaseline |
|
| LogArchiveBaseline |
|
| IDCenterBaseline |
|
Provision status by region
The Cloud Control service is available in the environments below.
| Region | Provision status |
|---|---|
| Korea West 1 (kr-west1) | Provided |
| Korea East 1 (kr-east1) | Provided |
| South Korea 1 (kr-south1) | Provided |
| South Korea South 2 (kr-south2) | Provided |
| South Korea 3 (kr-south3) | Provide |
Pre-service
This is a list of services that must be pre-configured before creating the service. For detailed information, please refer to the guide provided for each service and prepare in advance.
| Service Category | service | Detailed description |
|---|---|---|
| Storage | Object Storage | Object storage that simplifies data storage and retrieval |
| Management | Loggin&Audit | A service that collects and analyzes user activity data |
| Management | Organization | A service that organizes accounts by organizational units, manages them hierarchically, and controls resource access permissions. |
| Management | ID Center | A service that enables easy centralized management of access permissions for resources by account |