1 Moving from physical servers to the "cloud" involves a paradigm shift in thinking.
2 Logs should be handled via syslog (or similar) and sent to a remote store.
3 Your master account should most definitely have this, but it's also worth enabling it for normal IAM users too.
