Help Center/ Professional Services/ Service Overview/ Service Overview/ Cloudification and Implementation/ Landing Zone Design and Implementation/ FAQs/ About the Service/ What Are the Service Contents and Scenarios of Landing Zone Design and Implementation?
Updated on 2025-08-18 GMT+08:00

What Are the Service Contents and Scenarios of Landing Zone Design and Implementation?

Huawei Cloud Landing Zone design and implementation provides services for medium, large, and ultra-large scales in basic scenarios. It also provides services for high-level scenarios, such as data boundary, cloud financial management, and O&M management services. The following table lists the service contents and typical application scenarios. You can choose any combination of services that best fit your needs.

L4

L4.5

L6 Service Name

Service Content

Application Scenario

Landing Zone Design and Implementation

Design and Implementation for Basic Scenarios

Landing Zone Design for Basic Scenarios – Medium Scale

● Low level design (LLD): The Landing Zone foundation is designed, including organization accounts, identity and permissions, network planning, system security, and compliance audit.

● Technical tests are performed on selected technologies in LLD.

Medium- and large-sized enterprises are migrating services to Huawei Cloud. They need scalable, efficient cloud governance, in terms of organization accounts, identity and permissions, networks, security, and audit.

Landing Zone Design for Basic Scenarios – Large Scale

Landing Zone Design for Basic Scenarios – Ultra-Large Scale

Landing Zone Implementation for Basic Scenarios – Medium Scale

A cloud environment is deployed for basic scenarios as designed. This helps enable resources, create accounts, deploy the cloud infrastructure, set up multi-account and authorization systems, and provide cloud network and security protection.

Landing Zone Implementation for Basic Scenarios – Large Scale

Landing Zone Implementation for Basic Scenarios – Ultra-Large Scale

High-Level Scenarios – Data Boundary Management

Data Boundary Management Design

● LLD: Security control policies are designed for network and intranet boundaries. Routing tables, Access Control Lists (ACLs), and security groups are managed based on different permissions. Service control policies (SCPs) and guardrail policies are configured for VPC endpoints and resources to block all unexpected access paths.

● Technical tests are performed on selected technologies in LLD.

Medium- and large-sized enterprises are migrating services to Huawei Cloud. They need their data privacy and core data being strictly protected.

Data Boundary Management Implementation

Data boundary management is implemented for enterprises as the best practices.

High-Level Scenarios – Cloud Financial Management

Cloud Financial Management Design

● LLD: Hierarchical financial management is designed based on the organizational structure of Landing Zone and master-member account associations. Resources in each member account can be logically grouped by cost tag and costs can be split by cost tag.

● Technical tests are performed on selected technologies in this design.

Medium- and large-sized enterprises are migrating services to Huawei Cloud. They need to manage finances in a hierarchical manner.

Cloud Financial Management Implementation

Financial management is implemented and accepted.

High-Level Scenarios – O&M Management

O&M Management Design

● LLD: O&M and monitoring are performed for resource management, event management, and logs of all member accounts based on the organizational structure of Landing Zone.

● Technical tests are performed on selected technologies in this design.

Medium- and large-sized enterprises are migrating services to Huawei Cloud. They want to monitor and maintain their accounts and resources on a regular basis.

O&M Management Implementation

O&M management is implemented and accepted.

Landing Zone Support Service

Landing Zone Support Service-Basic

Based on the customer's actual service requirements, provide advanced support services when the customer's required scenario is less than the basic scenario. Additional purchases for delivery requirements not covered by the above standard items are applicable, constituting an L2 level delivery kit for 5 person-days. The specific delivery scope and deliverability will be assessed on a case-by-case basis according to the project.

For medium- and large-sized enterprises, HUAWEI CLOUD provides customized Landing Zone services, such as automatic script development, basic IaaS resource provisioning, and technical training support services, helping enterprises design and implement a scalable and efficient governance architecture on the cloud.

Landing Zone Support Service-Professional

Based on the customer's actual service requirements, Huawei provides advanced support services. Additional purchases are required for delivery needs that cannot be covered by the above standard items, including but not limited to the development of automation scripts for the eight scenarios of the Landing Zone, as well as technical training activities related to the Landing Zone domain. This constitutes a delivery package for 5 person-days at the L3 level. The specific delivery scope and deliverability will be assessed and evaluated on a case-by-case basis.

Landing Zone Governance Optimization

Landing Zone Governance Optimization-Standard Edition-Monthly (Medium-Scale)

After the delivery and implementation of the five basic scenarios of the Landing Zone, the system provides governance detection and repair for the five scenarios, including organizational structure, identity permission, network management, security management, and compliance audit, and provides historical detection record query.

After the Landing Zone environment is deployed for medium- and large-sized enterprises, routine governance is performed for five basic scenarios based on the Landing Zone best practices.

Landing Zone Governance Optimization-Standard Edition-Monthly (Large-Scale)

Landing Zone Governance Optimization-Standard Edition-Monthly (Ultra-Large Scale)

Landing Zone Governance Optimization-Standard Edition-Yearly (Medium-Scale)

After the delivery and implementation of the five basic scenarios of the Landing Zone, the system provides governance detection and repair for the five scenarios, including organizational structure, identity permission, network management, security management, and compliance audit, and provides historical detection record query. Provides automatic IaC script development and O&M for users with no more than 5 person-days.

Landing Zone Governance Optimization-Standard Edition-Yearly (Large-scale)

After the delivery and implementation of the five basic scenarios of the Landing Zone, the system provides governance detection and repair for the five scenarios, including organizational structure, identity permission, network management, security management, and compliance audit, and provides historical detection record query. Provides automatic IaC script development and O&M for users with no more than 10 person-days.

Landing Zone Governance Optimization-Standard Edition-Yearly (Ultra-Large Scale)

After the delivery and implementation of the five basic scenarios of the Landing Zone, the system provides governance detection and repair for the five scenarios, including organizational structure, identity permission, network management, security management, and compliance audit, and provides historical detection record query. Provides automatic IaC script development and O&M for users with no more than 15 person-days.

Landing Zone Governance Optimization-Ultimate Edition-Monthly (Medium-Scale)

After the delivery and implementation of the eight basic scenarios of the Landing Zone, the system provides governance detection and repair for the eight scenarios, including organizational structure, identity permission, network management, security management, compliance audit, financial management, O&M management, and data boundary and provides historical detection record query.

Landing Zone Governance Optimization-Ultimate Edition-Monthly (Large-scale)

Landing Zone Governance Optimization-Ultimate Edition-Monthly (Ultra-Large Scale)

Landing Zone Governance Optimization - Ultimate Edition - Yearly (Medium Scale)

After the delivery and implementation of the eight basic scenarios of the Landing Zone, the system provides governance detection and repair for the eight scenarios, including organizational structure, identity permission, network management, security management, compliance audit, financial management, O&M management, and data boundary and provides historical detection record query. Provides automatic IaC script development and O&M for users with no more than 5 person-days.

Landing Zone Governance Optimization - Ultimate Edition - Yearly (Large-scale)

After the delivery and implementation of the eight basic scenarios of the Landing Zone, the system provides governance detection and repair for the eight scenarios, including organizational structure, identity permission, network management, security management, compliance audit, financial management, O&M management, and data boundary and provides historical detection record query. Provides automatic IaC script development and O&M for users with no more than 10 person-days.

Landing Zone Governance Optimization - Ultimate Edition - Yearly (Ultra-Large Scale)

After the delivery and implementation of the eight basic scenarios of the Landing Zone, the system provides governance detection and repair for the eight scenarios, including organizational structure, identity permission, network management, security management, compliance audit, financial management, O&M management, and data boundary and provides historical detection record query. Provides automatic IaC script development and O&M for users with no more than 15 person-days.

Enterprise Scale Description :

  • Medium-scale (Landing Zone basic scenario design and implementation): Number of accounts ≤ 10, <= 3 VPC, and no cross-region scenario.
  • Large-scale (Landing Zone basic scenario design and implementation): If the requirements are not met in medium-scale scenarios, <= 100 accounts, <=10 VPC subnets.
  • Ultra-large scale (Landing Zone basic scenario design and implementation): If the requirements are not met in large-scale scenarios, > 100 accounts, > 10 VPC subnets.
  • Medium-scale (Landing Zone governance optimization): Number of accounts ≤ 10.
  • Large-scale (Landing Zone governance optimization): If the requirements are not met in medium-scale scenarios, <= 100 accounts.
  • Ultra-large scale (Landing Zone governance optimization): If the requirements are not met in large-scale scenarios, 100 accounts <accounts number<= 200 accounts.