Building an AWS Data Perimeter, Part 2: SCPs, RCPs, and Proving the Perimeter Holds
Attaching SCPs and RCPs to an AWS Organization, enforcing the new aws:VpceOrgID condition, and running denial tests against an external account with CloudTrail evidence.