mod06 Flashcards
shared responsability model
customer: security in the cloud
aws: security of the cloud
IAM
allows you to manage access to aws services and resources
MFA
Multi Factor Authentication
IAM
Identity Access Management
IAM users
it represents a person or app that interacts with aws
best practice: create an IAM user for every person in the organization
due IAM process
create root account
create another IAM account
with the IAM account create the users
IAM group
collection of users
IAM policies
to groups, then members of the group inherits those policies
IAM Policy
A document that grants or denies access to aws services or resources
best practice: principle of least privilege
IAM role
identity that a user can assume to gain temporary access to specific permissions
AWS Organizations
it helps aws users to consolidate and manage multiple AWS accounts
Service Control Policies for AWS Organizations
Centrally control permissions for the accounts in the organization
SCP applies to
AWS accounts
and
Organizational Units
AWS Artifact
provides on demand access to security and compliance reports and select online agreements
AWS Artifacts
Access AWS compliance reports on demand
Review accept and manage agreements with AWS
Access compliance reports from third party auditors