An enterprise client in the financial sector is undergoing an annual Payment Card Industry Data Security Standard (PCI DSS) compliance audit. The external auditors require official proof of compliance for the physical and environmental security controls of the AWS data centers where the client's applications are hosted. Which AWS service should the security team use to obtain the necessary reports, and how is the responsibility for physical security partitioned in this context?
- AWS Artifact is used to retrieve the PCI DSS Attestation of Compliance (AoC); AWS is solely responsible for managing the physical security and environmental controls of its data centers.Cevap
- BAWS Config is used to retrieve the PCI DSS Attestation of Compliance (AoC); the customer is responsible for auditing the physical access controls of the data centers.
- CAWS CloudTrail is used to retrieve the PCI DSS Attestation of Compliance (AoC); AWS is solely responsible for managing the physical security and environmental controls of its data centers.
- DAWS Artifact is used to retrieve the PCI DSS Attestation of Compliance (AoC); the customer is responsible for implementing physical and environmental controls within their virtual private cloud (VPC).
Cevap
AWS Artifact is used to retrieve the PCI DSS Attestation of Compliance (AoC); AWS is solely responsible for managing the physical security and environmental controls of its data centers.
The correct option correctly identifies AWS Artifact as the service for downloading compliance documents and accurately maps data center physical security as the sole responsibility of AWS under the Shared Responsibility Model.
Adım Adım Çözüm
Anahtar Kavram
AWS compliance report retrieval and the division of physical security under the Shared Responsibility Model.