A healthcare startup must verify that AWS infrastructure meets compliance regulations for HIPAA and obtain SOC 2 reports for its investors. Which two tasks can the startup perform directly within AWS Artifact?
- Download AWS security and compliance documents, such as SOC and PCI reportsAnswer
- Review and accept AWS agreements, such as the HIPAA Business Associate Addendum (BAA)Answer
- COpen a technical support ticket to request copies of AWS compliance certificates
- DScan Amazon EC2 instances for software vulnerabilities and regulatory compliance issues
- ETrack and log API calls across AWS resources for auditing purposes
Answer
Downloading AWS compliance documents (such as SOC and PCI reports) and reviewing/accepting AWS agreements (such as the HIPAA Business Associate Addendum)
AWS Artifact is the primary self-service portal for on-demand access to AWS compliance reports, such as SOC and PCI reports, and is also used to review and accept AWS agreements like the HIPAA Business Associate Addendum (BAA) for individual accounts or entire organizations.
Step-by-Step Solution
Key Concept
AWS Artifact provides self-service access to AWS compliance reports and agreements.