An automotive manufacturer is auditing its connected-vehicle telemetry platform hosted on AWS to verify compliance with ISO/IEC 27001 standards. Under the AWS Shared Responsibility Model, which compliance-related activity is the sole responsibility of the customer?
- AMaintaining physical security and environmental controls at the data centers where the vehicle data is stored
- BInstalling security patches on the underlying virtualization hypervisors hosting the compute instances
- Managing access permissions and user roles within the AWS Identity and Access Management (IAM) serviceAnswer
- DDisposing of decommissioned storage drives and hardware components in compliance with industry standards
Answer
Managing access permissions and user roles within the AWS Identity and Access Management (IAM) service
Under the AWS Shared Responsibility Model, the customer is responsible for security 'in' the cloud. This includes configuring identity and access management (IAM) to control access to AWS resources. Managing access permissions and user roles is a customer task, while AWS is responsible for physical security of data centers, hypervisor patching, and hardware disposal.
Step-by-Step Solution
Key Concept
AWS Shared Responsibility Model for Compliance