- To control inbound and outbound traffic for a VPC
- To encrypt data at rest and in transit
- To centrally manage access to multiple AWS accounts
- To monitor and record account activity for compliance auditing