AWS Risk and Compliance Whitepaper Flashcards

1
Q

Describe shared model

A

shared model helps relieve customers workload since AWS operates physical infrastructure

Customers responsible for guest OS and application software

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Describe AWS Risk identification

A

AWS performs risk identification and controls to mitigate risks.

AWS re-evaluates it at least every 6 months

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

AWS Scanning

A

AWS scans all internet facing IP addresses but not customer instances, and remediates identified vulnerabilities.

Independent security firms also perform assessments

These scans are for AWS infrastructure, not to replace customers need to do their own

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Customer scanning

A

Customers can ask for permission to scan their infrastructure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Compliances

A
SOC1 / SSAE 16 / ISAE 3402
SOC2
SOC3
FISMA, DIACAP, FedRAMP
PCI / DSS Level 1
ISO 27001
ISO 9001
FIPS 140-2
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Industry standard compliances

A

HIPAA
Cloud Security Alliance
MPAA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly