Soru

Zorluk: OrtaCompliance and Governance

A biotechnology firm is preparing for an audit to verify compliance with international security standards. The compliance team needs to obtain AWS security reports and establish which security controls are the direct responsibility of the cloud provider. Which TWO actions should the company take to meet these requirements?

  1. Retrieve the AWS ISO 27001 certification report directly from AWS Artifact to submit to external auditors.Cevap
  2. Confirm that AWS maintains the physical security of the data centers hosting the services under the AWS Shared Responsibility Model.Cevap
  3. C
    Run Amazon Inspector to scan the physical hardware of AWS data centers and verify compliance with environmental standards.
  4. D
    Configure customer-managed firewall rules in AWS Artifact to protect the physical hypervisors from external intrusion.
  5. E
    Use AWS CloudTrail to monitor real-time resource utilization metrics and generate compliance reports on resource efficiency.

Cevap

Retrieve the AWS ISO 27001 certification report directly from AWS Artifact and confirm that AWS maintains the physical security of the data centers hosting the services under the AWS Shared Responsibility Model.
AWS Artifact provides on-demand access to AWS's security and compliance reports (such as the ISO 27001 certification) to share with auditors. Under the AWS Shared Responsibility Model, AWS is responsible for security 'of' the cloud, which includes the physical security of data centers and the underlying infrastructure.

Adım Adım Çözüm

1
Determine the source for AWS compliance documentation.
Identify AWS Artifact as the self-service portal where customers can download AWS compliance documents, including SOC and ISO reports.
Auditors require official documentation of AWS's infrastructure compliance.
2
Apply the AWS Shared Responsibility Model to identify boundary responsibilities.
Verify that security 'of' the cloud, such as physical data center security and host virtualization software security, is AWS's responsibility.
This establishes which controls the customer does not need to implement or manage themselves.

Anahtar Kavram

Compliance and Governance in AWS
Bu soruyu puanla