Identity and Access Management
It is global (regardless region)

Components

Roles

Used for access policies between AWS resources (e.g. EC2 -> S3)