Ultimate access to all questions.
A company utilizes AWS Organizations for managing a multi-account structure, encompassing hundreds of AWS accounts with expectations of further growth. The company is developing a new application that relies on Docker images, which will be pushed to Amazon Elastic Container Registry (Amazon ECR). Access to these images should be restricted to accounts within the company's AWS Organization. The company maintains a frequent CI/CD process and wishes to retain all tagged images, but only the five most recent untagged images. What solution offers the least operational overhead to meet these requirements?