A software-as-a-service (SaaS) provider is preparing for an ISO 27001 certification audit of its order management application. To satisfy the auditors, the company must verify that the underlying AWS physical infrastructure is certified and identify which specific AWS services in their deployment are covered under this compliance standard. Which of the following actions should the company take to meet these requirements? (Select TWO.)
- Access AWS Artifact to retrieve the AWS ISO 27001 compliance report.Cevap
- Refer to the AWS Services in Scope by Compliance Program documentation.Cevap
- CRequest a physical audit of the AWS data center hosting the services through the AWS Support Center.
- DRun an Amazon Inspector scan on the database instances to generate the physical security certificate.
- EAnalyze AWS CloudTrail logs to verify physical security access events for the data centers hosting the infrastructure.
Cevap
The company should access AWS Artifact to retrieve the AWS ISO 27001 compliance report and refer to the AWS Services in Scope by Compliance Program documentation to confirm which services are certified.
The correct options involve retrieving compliance documents from AWS Artifact and checking service certification scope. AWS Artifact is the self-service portal for AWS compliance reports, such as ISO 27001 certificates. Since not all AWS services are in scope for every standard, verifying the service-specific compliance status via the AWS Services in Scope documentation is required to confirm that the architecture meets audit criteria.
Adım Adım Çözüm
Anahtar Kavram
AWS Compliance and Governance via AWS Artifact and Services in Scope documentation