Skip to main content
Category: Cloud Security

Landing Zone

Also known as: Cloud Landing Zone, Cloud Foundation, Azure Landing Zone, AWS Landing Zone
Simply put

A landing zone is a pre-configured, secure cloud environment that gives an organization a ready-made foundation for running workloads in a cloud platform such as AWS, Microsoft Azure, or Google Cloud. It sets up the baseline structure, security controls, and governance an organization needs before deploying applications at scale. Note that the term also has an unrelated military meaning referring to the physical point where aircraft land, which is not the sense used in cloud and security contexts.

Formal definition

In cloud architecture, a landing zone is a modular, scalable baseline configuration and orchestration framework that establishes the foundational environment for adopting a cloud platform across multiple accounts or subscriptions. It typically encompasses governance, identity, security, networking, and account or subscription structure so that workloads can be deployed in a consistent and controlled manner. Provider-specific implementations vary: AWS describes it as an orchestration framework providing a baseline for multi-account architecture, Microsoft Azure frames it as an architecture for governing, securing, and scaling a multi-subscription environment, and Google Cloud describes it as a modular, scalable cloud foundation. From a security leadership perspective, a landing zone is a governance and control mechanism rather than an operational service; its effectiveness depends on how the baseline controls are defined, maintained, and aligned to the organization's risk posture over time.

Why it matters

A landing zone matters because the security and governance decisions made at the foundational layer of a cloud environment shape the risk posture of everything deployed on top of it. When an organization adopts a platform such as AWS, Microsoft Azure, or Google Cloud without a deliberate baseline, individual teams often provision accounts, subscriptions, identities, and network configurations inconsistently. This fragmentation makes it harder to enforce consistent controls, monitor for misconfiguration, and demonstrate that governance expectations are being met across the environment. A well-designed landing zone establishes the account or subscription structure, identity model, networking, and security guardrails before workloads are deployed at scale, so that consistency is built in rather than retrofitted.

For security leadership, the value of a landing zone lies in treating it as a governance and control mechanism rather than a one-time setup task. The baseline controls it defines must be maintained and aligned to the organization's risk posture over time; a landing zone that is provisioned and then left unmanaged can drift from its intended state as workloads and requirements evolve. It is also important to be clear about accountability: a landing zone provides a structured foundation, but responsibility for defining appropriate controls and organizational accountability for security decisions remain with the organization and its officers. The landing zone does not by itself guarantee a secure outcome.

Equally important is understanding scope. A landing zone establishes foundational governance, identity, security, and networking structure, but it is not an operational service and does not perform ongoing monitoring, tooling administration, or incident response on its own. Its effectiveness depends heavily on how the baseline is defined, how well it maps to the organization's cloud adoption goals, and how consistently it is enforced and updated as the environment grows.

Who it's relevant to

Security and governance leaders (including virtual and fractional CISOs)
Security leaders advising on cloud adoption often treat the landing zone as a governance and control mechanism to shape at the outset. A virtual or fractional CISO typically provides strategy and direction on how the baseline controls should be defined and aligned to organizational risk, rather than performing the hands-on configuration themselves. Accountability for the resulting decisions generally remains with the client organization and its officers.
Organizations adopting or scaling cloud platforms
Organizations moving workloads to AWS, Microsoft Azure, or Google Cloud rely on a landing zone to establish a consistent, secure foundation before deploying applications at scale. This is especially relevant for those operating across multiple accounts or subscriptions, where inconsistency in structure, identity, and networking can otherwise accumulate risk.
Cloud architects and platform teams
Teams responsible for designing and maintaining the cloud foundation build and operate the landing zone's account or subscription structure, identity model, networking, and security guardrails. Their ongoing maintenance is central to keeping the baseline aligned with the organization's needs and preventing drift from the intended configuration over time.
Risk and compliance stakeholders
Those responsible for demonstrating consistent governance across a cloud environment benefit from the standardized baseline a landing zone provides. However, they should recognize that a landing zone supports consistent control application and does not by itself assert or guarantee compliance with any particular framework or standard.

Inside Landing Zone

Account or Subscription Structure
A defined hierarchy that separates workloads, environments, and business units into distinct accounts or subscriptions, supporting isolation and blast-radius reduction. The specific structure often varies by cloud provider and organizational needs.
Identity and Access Management
Centralized identity federation and access controls that govern who can access which resources and under what conditions, forming a core part of the landing zone's security foundation.
Network Architecture
Segmented and controlled networking that defines connectivity, isolation, and traffic boundaries between environments and to external systems.
Guardrails
Preventive and detective policies that enforce governance and security requirements automatically, helping keep deployed workloads within organizational risk tolerance.
Centralized Logging and Monitoring
Consolidated audit, log, and monitoring capabilities that support detection, compliance evidence, and visibility across the environment.
Baseline Security Controls
Foundational controls applied consistently across the environment so that workloads inherit a governed, policy-compliant starting point rather than requiring configuration from scratch.

Common questions

Answers to the questions practitioners most commonly ask about Landing Zone.

Does a virtual CISO build and manage our landing zone directly?
Not typically. A landing zone is a pre-configured, secure cloud foundation, and its hands-on construction and administration usually fall to cloud engineers, platform teams, or a managed service provider. A virtual CISO generally advises on the governance, risk, and security requirements that shape the landing zone, such as identity and access policies, network segmentation principles, logging expectations, and control mappings, rather than performing the implementation. Where a vCISO does take on build tasks, that would be an explicit and often unusual addition to scope, and it should be defined in the engagement contract.
Is having a landing zone the same as being compliant with frameworks like SOC 2 or ISO 27001?
No. A well-designed landing zone can support readiness for frameworks such as NIST CSF, ISO 27001, SOC 2, PCI DSS, or CMMC by embedding baseline controls into the cloud foundation, but the presence of a landing zone does not by itself demonstrate or guarantee compliance or certification. Compliance depends on evidence, operating effectiveness of controls over time, documented processes, and in many cases an independent audit or assessment. A virtual CISO may help align landing zone controls to a target framework, but that is supporting readiness, not asserting certification.
What should a virtual CISO clarify about the landing zone before an engagement begins?
In many engagements, a vCISO will want to establish scope boundaries early: whether they are advising on landing zone design versus reviewing an existing one, which stakeholders and platform teams they can access, and what target frameworks or regulatory drivers apply. They typically also confirm who holds accountability for approving and operating the environment, since legal and organizational accountability for security decisions usually remains with the client's officers even when the vCISO provides direction.
How does a virtual CISO prioritize security controls within a landing zone?
Priorities often depend on organizational maturity, risk tolerance, and applicable obligations. A vCISO typically focuses first on foundational governance controls such as identity and access management, separation of environments, centralized logging and monitoring readiness, and baseline network segmentation, because these are difficult and costly to retrofit. The specific sequencing may vary by provider and by the client's existing capabilities, and effective prioritization depends on cooperation from the teams who will implement and operate the controls.
Who is responsible for ongoing operation of a landing zone after a virtual CISO defines its requirements?
Operational responsibility usually stays with the client's cloud, platform, or operations teams, or with a contracted managed service provider. A virtual CISO generally does not perform hands-on operational tasks such as tool administration, monitoring, or incident response execution unless those are explicitly contracted. It is a common mistake to assume a vCISO functions like a managed security service provider or replaces an internal team; the vCISO advises and directs at the governance level while execution remains elsewhere.
How can a virtual CISO help govern changes to a landing zone over time?
A vCISO can help establish governance mechanisms such as change approval expectations, control baselines, periodic reviews, and risk assessment triggers for significant modifications. This guidance helps ensure the landing zone continues to reflect the organization's risk posture as it evolves. The value of this oversight depends heavily on defined scope, access to relevant stakeholders, and the client's willingness to enforce the recommended governance, since the vCISO advises rather than holds unilateral authority over the environment.

Common misconceptions

A landing zone guarantees compliance with frameworks such as NIST CSF, ISO 27001, SOC 2, or PCI DSS once it is deployed.
A well-designed landing zone can support readiness for these frameworks by embedding relevant controls and guardrails, but it does not by itself constitute certification or continuous compliance. Compliance depends on ongoing operation, evidence, scope, and validation, and outcomes may vary by organization and provider.
A virtual CISO who advises on a landing zone is responsible for building and administering it.
A vCISO typically advises on the governance, risk requirements, and control objectives the landing zone should satisfy. Hands-on engineering, tool administration, and ongoing operation generally remain with the client's cloud or engineering teams unless explicitly contracted. Accountability for security decisions usually remains with the client organization and its officers.
Once a landing zone is established, the security foundation is complete and requires no further attention.
A landing zone is a starting foundation, not a finished state. Its value depends on sustained governance, organizational maturity, stakeholder cooperation, and continued maintenance of guardrails and controls as the environment evolves.

Best practices

Define the governance intent, risk requirements, and control objectives before implementation, so that the landing zone reflects business and regulatory needs rather than only technical defaults.
Clearly document what is in scope and out of scope for each engagement, distinguishing advisory guidance on the landing zone from hands-on engineering and operational administration.
Implement guardrails as both preventive and detective controls, and use infrastructure-as-code where possible to support consistency and repeatability.
Centralize identity, logging, and monitoring early so that visibility and access governance are established as foundational rather than retrofitted.
Treat the landing zone as an evolving foundation that requires ongoing governance, stakeholder cooperation, and maintenance rather than a one-time deployment.
Align landing zone controls to any applicable frameworks such as NIST CSF, ISO 27001, or SOC 2 to support readiness, while recognizing that alignment supports rather than guarantees certification or compliance.