An educational technology company hosting student record databases on AWS must prepare for an audit by its university customers. The customers require verification of the physical security controls of the AWS data centers, and the company must accept the AWS non-disclosure agreements (NDAs) to access these documents. Which TWO actions should the company take to meet these compliance requirements? (Select TWO.)
- Download AWS compliance documents such as SOC and ISO reports directly from the AWS Artifact consoleAnswer
- BDeploy Amazon Inspector to audit and certify the physical security controls of the AWS data centers
- Accept the required AWS agreements, such as non-disclosure agreements, directly within AWS ArtifactAnswer
- DSubmit a request to AWS Support to obtain physical security logs of AWS data center buildings
- ERequest AWS to provide a signed statement verifying that AWS patches the guest operating system of the company's EC2 instances
Answer
Download AWS compliance documents such as SOC and ISO reports directly from the AWS Artifact console, and accept the required AWS agreements, such as non-disclosure agreements, directly within AWS Artifact.
To verify AWS physical security controls, the customer must access AWS compliance documents (such as Service Organization Control (SOC) and ISO reports) which are available on-demand in AWS Artifact. To access these documents, the customer must accept the associated AWS agreements and non-disclosure terms, which can be done directly through the AWS Artifact portal.
Step-by-Step Solution
Key Concept
AWS compliance reports retrieval and agreements acceptance under the Shared Responsibility Model.