Deck 3 Flashcards
Compliance of AWS
PCI DSS Level l (QSA Audit Still Required) ISO 9001 ISo 27001 SOC 1,2,3 FISMA/DIACAP and FEDRAMP
Industry specific standards
HIPAA
Cloud Security Alliance (CSA)
Motion Picture Association of America (MPAA)
Areas of AWS you are responsible for
EC2 patching VPC setup S3 Account management Users access
What is used to monitor API access
CloudTrail is recommended to be enabled
How storage decommissioned at Amazon
- DoD 5220.22-M or NIST 800-88 Guidelines
- All storage devices are wiped and physically destroyed
Network security components
HTTPS using SSL/TLS
VPC
IpSec VPN
Is the Amazon Corporate network segregated from the corporate network
Yes
Network monitoring provided by Amazon
DDos blocks Man in the middle IP Spoofing Port Scanning Sniffing
AWS password requirements
6 characters minimum, up to 128.
You can also require mixed case, numbers and special characters
Keypair security
Required by EC2 instances - 2048-bit SSH-2 RSA keys
Keys used by S3, API, REST, AWS SDK
Access Keys (comprised of Key ID and Secret
Use of X509 Certs
Used to sign SOAP based requests (S3). You can used Amazon based certs or generate your own.
AWS Trusted Adviser can make recommendations on:
Open Ports No internal IAM accounts Public S3 access CloudTrail logging not enabled for Not using MFA for root account
How is virtual machine data protected
VDs are zeroed out
Memory is scrubbed
Does Amazon have access to VM’s
No