Landing Zone
A landing zone is a pre-configured, secure cloud environment that gives an organization a ready-made foundation for running workloads in a cloud platform such as AWS, Microsoft Azure, or Google Cloud. It sets up the baseline structure, security controls, and governance an organization needs before deploying applications at scale. Note that the term also has an unrelated military meaning referring to the physical point where aircraft land, which is not the sense used in cloud and security contexts.
In cloud architecture, a landing zone is a modular, scalable baseline configuration and orchestration framework that establishes the foundational environment for adopting a cloud platform across multiple accounts or subscriptions. It typically encompasses governance, identity, security, networking, and account or subscription structure so that workloads can be deployed in a consistent and controlled manner. Provider-specific implementations vary: AWS describes it as an orchestration framework providing a baseline for multi-account architecture, Microsoft Azure frames it as an architecture for governing, securing, and scaling a multi-subscription environment, and Google Cloud describes it as a modular, scalable cloud foundation. From a security leadership perspective, a landing zone is a governance and control mechanism rather than an operational service; its effectiveness depends on how the baseline controls are defined, maintained, and aligned to the organization's risk posture over time.
Why it matters
A landing zone matters because the security and governance decisions made at the foundational layer of a cloud environment shape the risk posture of everything deployed on top of it. When an organization adopts a platform such as AWS, Microsoft Azure, or Google Cloud without a deliberate baseline, individual teams often provision accounts, subscriptions, identities, and network configurations inconsistently. This fragmentation makes it harder to enforce consistent controls, monitor for misconfiguration, and demonstrate that governance expectations are being met across the environment. A well-designed landing zone establishes the account or subscription structure, identity model, networking, and security guardrails before workloads are deployed at scale, so that consistency is built in rather than retrofitted.
For security leadership, the value of a landing zone lies in treating it as a governance and control mechanism rather than a one-time setup task. The baseline controls it defines must be maintained and aligned to the organization's risk posture over time; a landing zone that is provisioned and then left unmanaged can drift from its intended state as workloads and requirements evolve. It is also important to be clear about accountability: a landing zone provides a structured foundation, but responsibility for defining appropriate controls and organizational accountability for security decisions remain with the organization and its officers. The landing zone does not by itself guarantee a secure outcome.
Equally important is understanding scope. A landing zone establishes foundational governance, identity, security, and networking structure, but it is not an operational service and does not perform ongoing monitoring, tooling administration, or incident response on its own. Its effectiveness depends heavily on how the baseline is defined, how well it maps to the organization's cloud adoption goals, and how consistently it is enforced and updated as the environment grows.
Who it's relevant to
Inside Landing Zone
Common questions
Answers to the questions practitioners most commonly ask about Landing Zone.