Executive Summary
One of State-Owned Bank in Indonesia has a need to meet Compliance and Governance standards. Providing services that are always there for bank customers and providing convenience for the bank IT team in terms of services, data center facilities and also enabling security of server resources in a short time is the main concern.
Customer Challange
As the Bank embarked on its cloud transformation journey, several key challenges had to be overcome to ensure a secure, compliant and scalable AWS Landing Zone implementation. And here is basic compliance and security governance to IT standardization, which includes:
a. Identity & Access Management (Role Authorization)
b. Resource Organization & Hierarchy Management (Resource Management)
c. Cost/Billing Management (Financial Management)
d. Network Architecture (Enterprise Network Design)
Solution
PT. Mastersystem Infotama Tbk as Amazon AWS Partner, provides AWS Landing Zone using AWS Control Tower as a solution to fulfil the needs of the Bank. Landing Zone is a well-architected, multi-account AWS environment that’s based on security and compliance best practices. The following is the High Level Diagram offered for the account structure on the AWS Landing Zone :

Management Account is the initial Account that is used to manage the Billing Account and Organizational Structure of the AWS Account that is a member of the Organization Account. The Management Account is fully managed by the service provider and is responsible for the control of infrastructure and financial policies arising from the accounts within its organization. In the Management Account there is an AWS Organization that helps the central manage AWS resources used by the Bank such as managing access from various teams in the Bank that are given access to the AWS console. In addition to the Management Account, there are also several accounts such as the Log Archive Account, Audit Account and Shared and Network Account. Audit Account, is an account that is used to monitor and audit other accounts in an AWS environment. It is typically used by security and compliance teams to track activity, identify potential security risks, and investigate incidents, AWS services such as AWS Security Hub, AWS Config, Amazon GuardDuty. Log Archive Account, is an account that is used to store logs from other accounts in the organization. This can be useful for compliance, auditing, and troubleshooting purposes. Shared and Network Accounts are accounts used as AWS service centres that are shared and used across multiple Workload the Bank accounts, AWS Service such as AWS Direct Connect.
The Bank maintains a hybrid security architecture where third-party security appliances are deployed in the on-premise data center. These on-premise security solutions inspect and protect traffic flowing between the Bank’s data center and AWS cloud environment. The connectivity between on-premise and AWS is established through AWS Direct Connect, providing dedicated, low-latency, and high-bandwidth private network connectivity.
AWS Direct Connect provides the secure, dedicated network link between the Bank’s on-premise data center and AWS:
• Dedicated Direct Connect connection (100 Mbps) from on-premise data center to AWS Region
• Private Virtual Interface (VIF) for secure communication to VPCs via Transit Gateway
• Traffic from AWS workloads routed through Direct Connect to on-premise security appliances for inspection before reaching the internet
• Redundant Direct Connect connections across multiple locations for high availability
• AWS Transit Gateway connecting all workload VPCs with route tables directing traffic to on-premise firewalls
Mastersystem Infotama established a structured Incident Response framework for the Bank that integrates AWS-native security services with the on-premise third-party SIEM and security operations center (SOC). This framework ensures that security incidents are detected rapidly, triaged accurately, contained effectively, and remediated completely – whether the incident originates in the cloud or on-premise environment.
Continuous monitoring across hybrid environment for early threat identification:
- Amazon GuardDuty enabled across all accounts for ML-based threat detection.
- AWS Security Hub aggregates findings from GuardDuty, Inspector, and Config.
- AWS CloudTrail logs all API activity for audit and forensic analysis.
- VPC Flow Logs and CloudWatch Alarms for network anomaly detection.
- On-premise SIEM correlates events from AWS and on-premise security appliances.
Structured assessment process to prioritize and route security events:
- Automated severity classification (Critical/High/Medium/Low) via Security Hub scoring.
- Amazon SNS alert routing to appropriate response team based on severity.
- Impact assessment with asset context enrichment (account, resource, business criticality).
Rapid actions to limit blast radius and prevent lateral movement:
- Automated Security Group modification to isolate compromised instances.
- Emergency SCP enforcement to restrict actions in affected accounts.
- On-premise NGFW rules updated to block attack source IPs on Direct Connect.
- Resource quarantine and tagging for forensic investigation.
Complete resolution and prevention of recurrence:
- AWS Systems Manager Automation runbooks for patching and configuration correction.
- Root cause analysis using CloudTrail, VPC Flow Logs, and GuardDuty findings.
- AWS Config auto-remediation rules to enforce compliant configurations.
- Post-incident review with documented lessons learned.
Mastersystem Infotama implemented a Multi-AZ (Multiple Availability Zones) architecture for the Bank to ensure high availability, fault tolerance, and rapid recovery of critical banking systems. By distributing workloads across physically separated data centers within the same AWS Region, the Bank achieves near-zero downtime and automatic failover capabilities without manual intervention.
Multi-AZ Architecture.
All critical workloads deployed across multiple Availability Zones for fault tolerance and automatic failover:
- Amazon EC2 instances deployed across minimum 2 AZs with Auto Scaling Groups for automatic recovery.
- Amazon RDS multi-AZ with synchronous replication and automatic failover (RPO: 0, RTO: < 2 minutes).
- Elastic Load Balancer (ALB) distributing traffic across AZs with health checks.
- VPC subnets spanning multiple AZs for network-level redundancy.
Layered backup approach ensuring data protection and rapid restoration:
- AWS Backup with automated daily snapshots of EC2 (EBS) and RDS resources.
- Cross-AZ snapshot replication for immediate recovery in case of AZ failure.
- Backup Vault Lock (WORM) to prevent accidental or malicious deletion.
Documented and tested recovery procedures for various failure scenarios:
- AZ Failure: Automatic failover via ALB health checks and Auto Scaling – no manual intervention.
- Database Recovery: RDS automatic failover to standby in secondary AZ within minutes.
- Instance Recovery: Auto Scaling launches replacement instances in healthy AZ automatically.
- Data Recovery: Restore from EBS snapshots or RDS automated backups when needed.
- Quarterly DR drills to validate multi-AZ failover and measure actual RTO/RPO
Result and Benefit
By implementing AWS Landing Zone, Bank improved 75% for operational performance and agility, workload scalability, leveraging Cloud infrastructure also provides increased availability for users which can help optimize and streamline business activities without neglecting the security of services residing on cloud infrastructure.
A key enabler of this success is the integration of AWS IAM Identity Center, which has streamlined user access management across multiple AWS accounts. With centralized single sign-on (SSO) and role-based access control (RBAC), the Bank has eliminated the operational overhead of managing separate IAM users in each account. This has led to:
- Faster onboarding of teams and users,
- Improved access governance and compliance,
- Reduced risk of misconfigured permissions or unauthorized access,
- Simplified auditability for security and compliance teams.
Together, these improvements have empowered the Bank to scale securely in the cloud, maintain strong security posture, and enhance user productivity while adhering to regulatory and operational requirements.

