A media broadcasting company is preparing for an annual governance review of its cloud-based video archiving system. The governance team needs to acquire official AWS ISO 27001 certification documents and clarify how the security of AWS's physical infrastructure is validated. Which two of the following options represent correct actions or concepts that meet these requirements? (Select TWO.)
- Retrieve the AWS ISO 27001 certification report directly from AWS Artifact.Cevap
- Rely on AWS compliance reports for physical infrastructure security, as AWS is responsible for security of the cloud.Cevap
- CRun Amazon Inspector to scan and generate official AWS compliance certifications for the physical host servers.
- DCoordinate with AWS Support to perform an on-site physical security audit of the AWS data centers.
- EEnable Amazon CloudWatch to automatically download AWS compliance audits and service agreements.
Cevap
To meet the governance requirements, the company should retrieve the AWS ISO 27001 certification report directly from AWS Artifact, and rely on AWS compliance reports for physical infrastructure security, as AWS is responsible for security of the cloud.
Retrieving the AWS ISO 27001 certification report directly from AWS Artifact is correct because AWS Artifact is the self-service portal that provides on-demand access to AWS security and compliance reports. Relying on AWS compliance reports for physical infrastructure security is correct because, under the Shared Responsibility Model, AWS is responsible for security of the cloud (the physical infrastructure), and customers verify this inheritance through these reports.
Adım Adım Çözüm
Anahtar Kavram
AWS compliance reports retrieval via AWS Artifact and boundaries of physical security under the Shared Responsibility Model.