Apply to the Root Node: An Organization is the root node of the Google Cloud hierarchy of resources. When you apply the Root Node to the organization policy, you can define settings, permissions, and policies for all projects, folders, resources, and Cloud Billing accounts it parents, etc to ensure that any current or future Virtual Machine has no external internet access.
You can set an IAM policy at the organization level, the folder level, the project level, or (in some cases) the resource level. Resources inherit the policies of the parent node. If you set a policy at the Organization level, it is inherited by all its child folders and projects, and if you set a policy at the project level, it is inherited by all its child resources.
Source: The Organization resource
