Security And Compliance Flashcards
AWS shared responsibility model
Customer (security in the cloud)
> Customer data
platform, applications, Identity and Access management.
Operating systems, Network & Firewall configurations
Client side data encryption and data integrity authentication , Sever side encryption ( files systems and data), Network traffic protection (encryption, integrity, identity)
AWS (Security of the cloud)
> Software
Compute, Storage, Database, Networking
Hardware/AWS Global infrastructure
Regions, AZ, Edge locations
AWS Artifacts
On demand security and compliance report.
AWS Artifact is your go-to, central resource for compliance-related information that matters to you. It provides on-demand access to AWS’ security and compliance reports and select online agreements. Reports available in AWS Artifact include our Service Organization Control (SOC) reports, Payment Card Industry (PCI) reports, and certifications from accreditation bodies across geographies and compliance verticals that validate the implementation and operating effectiveness of AWS security controls. Agreements available in AWS Artifact include the Business Associate Addendum (BAA) and the Nondisclosure Agreement (NDA).
AWS Config
Access, audit and evaluate the «» of AWS resources.
> > > added to show that its for configuration.
AWS Cloudtrail
risk auditing by continuous monitoring
Logs API Calls
AWS Cloud watch
AWS inspector
Runs security inspections on AWS EC2 instances
AWS WAF
web application firewall is a firewall which can filter the requests any parts such as
IP address
IP headers
HTTP Body
URI strings (which prevents sqi injection)
AWS Trusted advisors
AWS Marketplace
Third-party security softwires for AWS
Security, Identity, and Compliance on AWS
https://aws.amazon.com/products/security/?nc=sn&loc=2