A biotechnology firm is preparing for an audit to verify compliance with international security standards. The compliance team needs to obtain AWS security reports and establish which security controls are the direct responsibility of the cloud provider. Which TWO actions should the company take to meet these requirements?
- Retrieve the AWS ISO 27001 certification report directly from AWS Artifact to submit to external auditors.Answer
- Confirm that AWS maintains the physical security of the data centers hosting the services under the AWS Shared Responsibility Model.Answer
- CRun Amazon Inspector to scan the physical hardware of AWS data centers and verify compliance with environmental standards.
- DConfigure customer-managed firewall rules in AWS Artifact to protect the physical hypervisors from external intrusion.
- EUse AWS CloudTrail to monitor real-time resource utilization metrics and generate compliance reports on resource efficiency.
Answer
Retrieve the AWS ISO 27001 certification report directly from AWS Artifact and confirm that AWS maintains the physical security of the data centers hosting the services under the AWS Shared Responsibility Model.
AWS Artifact provides on-demand access to AWS's security and compliance reports (such as the ISO 27001 certification) to share with auditors. Under the AWS Shared Responsibility Model, AWS is responsible for security 'of' the cloud, which includes the physical security of data centers and the underlying infrastructure.
Step-by-Step Solution
Key Concept
Compliance and Governance in AWS