The ITGix AWS Landing Zone continues to evolve with a clear goal: enabling organizations to build secure, compliant, and scalable AWS environments with less operational overhead.
Across recent releases (v1.2.0 through v1.6.0), we’ve introduced major improvements spanning security, compliance, CI/CD automation, networking, observability, and operational efficiency. These updates are designed for teams managing multi-account AWS architectures that require strong governance without sacrificing flexibility.
In this post, we highlight the most impactful updates and explain how they improve day-to-day operations for cloud and platform teams.

CI/CD Pipelines for AWS Landing Zone Changes
One of the most requested capabilities is now available: automated CI/CD pipelines for the Landing Zone itself.
Built on AWS CodePipeline and CodeBuild, the new pipeline module enables infrastructure deployments across multiple AWS accounts directly from a version control repository using AWS CodeConnections.
To ensure safe and reliable deployments, the pipeline includes multiple hardening mechanisms:
- SHA-256 checksum validation for plan integrity
- Commit SHA validation between plan and apply stages
- Account and region validation
- Plan metadata tracking with build IDs and timestamps
- TTL enforcement for plan validity (default: 30 minutes)
- Strict artifact presence validation – apply stages use only approved plan files, with no re-planning
This brings the same rigor teams expect from application CI/CD into infrastructure lifecycle management.
Strengthened Security and Compliance Controls
Security remains a core focus across every release of the ITGix AWS Landing Zone.
PCI DSS v4.0.1 Support
Support for PCI DSS v4.0.1 has been added to SecurityHub scanning, complementing existing NIST and CIS Benchmark checks. Combined with targeted remediation of findings, this significantly strengthens the default compliance posture.
AWS Config Integration
AWS Config is now enabled across all accounts, automatically collecting configuration data and storing historical state in S3. Conformance packs can be enabled quickly to scan against multiple security standards.
IAM and Access Hardening
Several organization-wide access improvements have been implemented:
- Stronger IAM password policies aligned with PCI DSS 4.0.1
- Prevention of public S3 bucket access across all accounts
- Root credential management enabled for member accounts
- Default EBS volume encryption enforced everywhere
Organization-Wide Guardrails with Service Control Policies (SCPs)
A comprehensive set of Service Control Policies now provides preventive guardrails, including:
- Mandatory resource tagging for cost allocation
- Disabled IAM user and access key creation (Identity Center only)
- Region restrictions to approved AWS regions
- Protection against accounts leaving the organization
- Deletion protection for CloudTrail, S3, DynamoDB, and KMS
- Enforced encryption for S3 object uploads
- Account quarantine capability for security incidents
These controls reduce risk while maintaining operational consistency.
Enhanced Threat Detection with GuardDuty
GuardDuty has been refactored to support the latest AWS APIs and expanded to include all supported detection types:
- S3 Data Events
- EKS Audit Logs
- EBS Malware Protection
- RDS Login Events
- Lambda Network Logs
- Runtime Monitoring
Each detection feature can now be enabled or disabled conditionally, allowing teams to balance coverage and cost.
Just-In-Time Access with the TEAM Tool
The Landing Zone now includes a Just-In-Time (JIT) access tool, known as the TEAM tool, deployed in the Security account.
Key capabilities include:
- Predefined groups for requestors, approvers, and administrators
- Scheduled access windows for future access needs
- Full auditability of access requests and approvals
This eliminates standing production access and enforces least-privilege access by design.
Centralized Observability with AWS OAM
Using AWS Observability Access Manager (OAM), logs and metrics from all accounts are now centralized in the Logging & Auditing account.
This enables:
- Centralized log search via CloudWatch Log Insights
- Organization-wide alerting on CloudWatch metrics
- A single operational view across all accounts
Networking Improvements Across Environments
Refactored AWS Client VPN
AWS Managed Client VPN has been refactored to integrate more efficiently with Transit Gateway. A single VPN endpoint can now provide access to dev, stage, and prod environments, with access controlled via groups and Identity Center SSO.
Alternative Networking Options
New options include:
- Simplified per-account VPC deployments (HA across 3 AZs)
- Automated VPC peering
- WireGuard VPN behind an NLB
- Shared-services VPC support
DNS and Route 53 Enhancements
Updates include:
- Federated DNS zones across environments
- Route 53 resolver query logging per VPC
- Optional DNS query/response logging
- Updated diagrams and documentation
Operational Efficiency and Cost Optimization
Automated Patching Strategy
An automated script now checks for newer Terraform module versions and generates update reports, simplifying Landing Zone maintenance.
Instance Scheduler
Automated start/stop schedules for EC2 and RDS help reduce non-production costs.
Automatic Remediation
CloudWatch log groups with unlimited retention are now automatically updated to a 365-day retention policy.
Centralized Backup Management
AWS Backup is centrally managed with organization-wide policies. Resources can be automatically backed up by applying a simple tag.
Platform and Tooling Improvements
Recent infrastructure-level updates include:
- AWS Control Tower integration
- Terraform AWS provider v6 upgrade
- Terraform state locking moved to S3
- GitHub-based Terraform module repositories
- GitHub OIDC integration for role assumption
- Improved documentation, diagrams, and client handover artifacts
What’s Next for the ITGix AWS Landing Zone
With each release, the ITGix AWS Landing Zone moves closer to a fully self-service, compliance-ready cloud platform.
Upcoming roadmap items include:
- Self-service Client VPN portal
- IPAM integration
- IPv6 support
- Expanded multi-region service coverage
If your organization is looking to accelerate its AWS journey with a secure and scalable foundation, contact our team to learn how the ITGix AWS Landing Zone can help.

