AWS Risk and Compliance Whitepaper Flashcards
Describe shared model
shared model helps relieve customers workload since AWS operates physical infrastructure
Customers responsible for guest OS and application software
Describe AWS Risk identification
AWS performs risk identification and controls to mitigate risks.
AWS re-evaluates it at least every 6 months
AWS Scanning
AWS scans all internet facing IP addresses but not customer instances, and remediates identified vulnerabilities.
Independent security firms also perform assessments
These scans are for AWS infrastructure, not to replace customers need to do their own
Customer scanning
Customers can ask for permission to scan their infrastructure
Compliances
SOC1 / SSAE 16 / ISAE 3402 SOC2 SOC3 FISMA, DIACAP, FedRAMP PCI / DSS Level 1 ISO 27001 ISO 9001 FIPS 140-2
Industry standard compliances
HIPAA
Cloud Security Alliance
MPAA