0Pricing
AWS Security Academy · Lesson

Centralized Log Archive Accounts

Isolate logs in a separate account out of an attacker's reach.

Isolating the Evidence

The strongest log protection puts logs in a separate AWS account dedicated to archival, isolated from the accounts that run workloads. If an attacker compromises a production account, they still cannot reach or delete the logs stored in an account they do not control. This isolation is a cornerstone of mature security architecture.

The Log Archive Account

In a multi-account organization, a dedicated Log Archive account receives logs from every other account. AWS Control Tower creates exactly this account by default in its landing zone, reflecting how strongly AWS recommends the pattern. Centralizing logs here gives one protected home for all audit evidence.

All lessons in this course

  1. Why Log Tampering Is a Threat
  2. CloudTrail Log File Validation
  3. Locking Down Log Storage Buckets
  4. Centralized Log Archive Accounts
← Back to AWS Security Academy