[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"cheat-sheet---en":3,"domain-info---en":3,"topic-info----en":3,"lesson-aws-certified-cloud-practitioner-security-and-compliance-shared-responsibility-model-responsibility-shifts-by-service-en":4,"next-aws-certified-cloud-practitioner-security-and-compliance-shared-responsibility-model-responsibility-shifts-by-service-en":18,"prev-aws-certified-cloud-practitioner-security-and-compliance-shared-responsibility-model-responsibility-shifts-by-service-en":260},null,{"locked":5,"reason":6,"meta":7,"item":3},true,"paywall",{"title":8,"description":9,"isFree":10,"estimatedMinutes":11,"difficulty":12,"learningObjectives":13},"How Responsibility Shifts by Service","Understand why your share of the security work changes with the service, from infrastructure services like EC2 to fully abstracted services like S3, and what always stays with you.",false,16,"intermediate",[14,15,16,17],"Explain why the responsibility boundary shifts with the service type","Compare customer duties across infrastructure, container, and abstracted services","Identify which responsibilities always stay with the customer","Match a service like EC2, RDS, or S3 to the customer's security tasks",{"locked":10,"reason":3,"meta":19,"item":29},{"title":20,"description":21,"isFree":5,"estimatedMinutes":22,"difficulty":23,"learningObjectives":24},"AWS Compliance and AWS Artifact","Learn how AWS proves it meets security standards, which compliance programs it holds, and how AWS Artifact gives you on-demand access to audit reports and agreements.",14,"beginner",[25,26,27,28],"Explain what cloud compliance means and how it ties to the shared responsibility model","Identify the main compliance programs and certifications AWS holds","Describe what AWS Artifact is and the documents it provides","Explain who can access AWS Artifact and the rules for handling its reports",{"id":30,"title":20,"body":31,"description":21,"difficulty":23,"estimatedMinutes":22,"extension":209,"infographics":210,"isFree":5,"learningObjectives":211,"meta":212,"navigation":5,"path":213,"quiz":214,"seo":257,"stem":258,"__hash__":259},"courses/courses/aws-certified-cloud-practitioner/en/domains/02-security-and-compliance/02-compliance-and-governance/01-aws-compliance-and-artifact.md",{"type":32,"value":33,"toc":197},"minimark",[34,39,43,46,50,53,56,60,63,131,134,138,141,144,151,157,161,164,167,171,174,178],[35,36,38],"h2",{"id":37},"why-compliance-matters-in-the-cloud","Why compliance matters in the cloud",[40,41,42],"p",{},"Many organizations have to follow rules about how they handle data. A hospital must protect patient records, an online store that takes card payments must meet payment-card rules, and a government supplier must meet government security standards. These rules come from laws, industry bodies, and regulators, and breaking them can mean fines or losing the right to operate.",[40,44,45],{},"When you run everything in your own data center, you have to prove you meet every rule yourself, top to bottom. Moving to AWS changes that. AWS already meets a long list of standards for the infrastructure it runs, and it gives you the paperwork to prove it. You still have to handle compliance for what you build, but you inherit a strong, audited foundation underneath.",[35,47,49],{"id":48},"how-aws-proves-its-compliance","How AWS proves its compliance",[40,51,52],{},"AWS does not just claim to be secure. Independent auditors and accreditation bodies test its controls and issue formal reports and certifications. AWS environments are audited on an ongoing basis, and the results are published so customers can rely on them.",[40,54,55],{},"These audits cover the parts of the system AWS owns: the physical data centers, the hardware, and the software that runs AWS services. This is the \"security of the cloud\" side of the shared responsibility model. Because AWS proves these controls once, every customer benefits from them instead of each company auditing the same data centers separately.",[35,57,59],{"id":58},"aws-compliance-programs","AWS compliance programs",[40,61,62],{},"AWS takes part in many compliance programs that span different regions and industries. You do not need to memorize the full list for the exam, but you should recognize the common ones and what they relate to.",[64,65,66,79],"table",{},[67,68,69],"thead",{},[70,71,72,76],"tr",{},[73,74,75],"th",{},"Program",[73,77,78],{},"What it covers",[80,81,82,91,99,107,115,123],"tbody",{},[70,83,84,88],{},[85,86,87],"td",{},"SOC 1, 2, 3",[85,89,90],{},"System and Organization Controls reports on AWS's security and operational controls",[70,92,93,96],{},[85,94,95],{},"PCI DSS Level 1",[85,97,98],{},"Payment Card Industry Data Security Standard for handling card data",[70,100,101,104],{},[85,102,103],{},"ISO 27001, 27017, 27018",[85,105,106],{},"International standards for information security and cloud privacy",[70,108,109,112],{},[85,110,111],{},"HIPAA",[85,113,114],{},"US healthcare data protection (AWS offers HIPAA-eligible services)",[70,116,117,120],{},[85,118,119],{},"FedRAMP",[85,121,122],{},"US government cloud security authorization",[70,124,125,128],{},[85,126,127],{},"GDPR",[85,129,130],{},"European Union data protection regulation",[40,132,133],{},"One detail to keep straight: AWS being certified or \"eligible\" for a standard does not make your workload compliant by itself. If you run a healthcare app, AWS offering HIPAA-eligible services is a starting point, but you still have to configure and use those services correctly. Compliance of what you build stays your job.",[35,135,137],{"id":136},"what-is-aws-artifact","What is AWS Artifact?",[40,139,140],{},"AWS Artifact is a self-service portal that gives you on-demand access to AWS's security and compliance documents. Instead of opening a support ticket and waiting, you sign in, find the report you need, and download it in minutes. The service is free.",[40,142,143],{},"Artifact has two main kinds of content:",[40,145,146,150],{},[147,148,149],"strong",{},"Reports."," These are AWS's audit artifacts, such as SOC 1, 2, and 3, PCI DSS, and ISO certifications. You hand these to your auditors or regulators to show that the AWS infrastructure under your application meets a given standard. New reports are added as they become available.",[40,152,153,156],{},[147,154,155],{},"Agreements."," Artifact also lets you review, accept, and track the status of legal agreements with AWS, such as a Business Associate Addendum for HIPAA. You can manage these for one account or across many accounts in your organization.",[35,158,160],{"id":159},"who-can-access-artifact-and-the-rules-for-using-it","Who can access Artifact, and the rules for using it",[40,162,163],{},"Every AWS account has access to AWS Artifact. The root user and IAM users with the right permissions can download the available documents after agreeing to the terms attached to each one.",[40,165,166],{},"These reports are confidential. Each download carries a unique, traceable watermark tied to your account. You are allowed to share them inside your company and with your regulators and auditors, but you must not post them publicly or hand them to your own customers. Treat them as sensitive legal documents, because that is what they are.",[35,168,170],{"id":169},"how-artifact-fits-the-bigger-picture","How Artifact fits the bigger picture",[40,172,173],{},"Think of AWS Artifact as the evidence locker for the \"of the cloud\" side of security. When someone needs proof that AWS itself is compliant, Artifact is where that proof lives. When the question is about your data, your access settings, or your application, that is the \"in the cloud\" side, and the evidence for it comes from you, not Artifact.",[35,175,177],{"id":176},"exam-tips","Exam tips",[179,180,181,185,188,191,194],"ul",{},[182,183,184],"li",{},"AWS Artifact is the go-to service for downloading AWS compliance reports (SOC, PCI DSS, ISO) and managing agreements. It is free and self-service.",[182,186,187],{},"If a question asks where to get AWS's audit reports for an auditor, the answer is AWS Artifact.",[182,189,190],{},"AWS holds many compliance certifications, but its certifications do not make your own workload compliant. Compliance in the cloud is your responsibility.",[182,192,193],{},"Artifact reports are confidential and watermarked. Share them with auditors and regulators, not the public.",[182,195,196],{},"Recognize common programs by name: SOC, PCI DSS, ISO 27001, HIPAA, FedRAMP, and GDPR.",{"title":198,"searchDepth":199,"depth":199,"links":200},"",3,[201,203,204,205,206,207,208],{"id":37,"depth":202,"text":38},2,{"id":48,"depth":202,"text":49},{"id":58,"depth":202,"text":59},{"id":136,"depth":202,"text":137},{"id":159,"depth":202,"text":160},{"id":169,"depth":202,"text":170},{"id":176,"depth":202,"text":177},"md",[],[25,26,27,28],{},"/courses/aws-certified-cloud-practitioner/en/domains/02-security-and-compliance/02-compliance-and-governance/01-aws-compliance-and-artifact",{"passingScore":215,"questions":216},70,[217,226,234,240,249],{"question":218,"type":219,"options":220,"correctAnswer":223,"explanation":225},"An external auditor asks your company to prove that the AWS data centers running your workload meet SOC 2 controls. What is the fastest way to get the official report?","single",[221,222,223,224],"Email AWS Support and wait for a signed PDF","Recreate the controls yourself and document them","Download the SOC 2 report from AWS Artifact","Schedule your auditor to tour an AWS data center","AWS Artifact gives you on-demand downloads of AWS audit reports like SOC 1, 2, and 3. You do not need to contact Support or visit a facility, and you cannot audit AWS's physical controls yourself because AWS owns that layer.",{"question":227,"type":219,"options":228,"correctAnswer":229,"explanation":233},"What does AWS Artifact mainly provide?",[229,230,231,232],"On-demand access to AWS security and compliance reports and agreements","A firewall that blocks malicious traffic to your applications","A tool that automatically makes your account compliant with any standard","A backup service for your S3 buckets","AWS Artifact is a self-service portal for downloading AWS compliance documents, such as ISO, PCI, and SOC reports, and for reviewing and accepting agreements. It does not filter traffic, back up data, or make your own workloads compliant for you.",{"question":235,"type":219,"options":236,"correctAnswer":237,"explanation":239},"AWS Artifact reports are available at no extra cost to AWS customers.",[237,238],"True","False","AWS provides Artifact documents and agreements free of charge. Every AWS account can access them, subject to the confidentiality terms you accept before downloading.",{"question":241,"type":242,"options":243,"correctAnswers":247,"explanation":248},"Which of the following are compliance programs or certifications that AWS holds? (Select all that apply.)","multiple",[244,95,245,246],"SOC 1, 2, and 3","ISO 27001","A guarantee that any application you deploy is automatically HIPAA compliant",[244,95,245],"AWS is independently audited against many programs, including SOC, PCI DSS, and ISO 27001. AWS being HIPAA eligible does not make your application compliant on its own, because compliance of what you build on top is your responsibility.",{"question":250,"type":219,"options":251,"correctAnswer":255,"explanation":256},"Under the shared responsibility model, who is responsible for the compliance of the application and data you run on AWS?",[252,253,254,255],"AWS, because it owns the data centers","The auditor who reviews your account","No one, since AWS is already certified","You, the customer","AWS is responsible for the compliance of the cloud infrastructure, and you are responsible for compliance in the cloud, meaning your data, configuration, and how you use AWS services. AWS certifications give you a head start but do not cover what you build.",{"title":20,"description":21},"courses/aws-certified-cloud-practitioner/en/domains/02-security-and-compliance/02-compliance-and-governance/01-aws-compliance-and-artifact","eWNRFFlK4a49puj9Zvk7boXhzbRLcGIIvKkDKsIBhwE",{"locked":5,"reason":6,"meta":261,"item":3},{"title":262,"description":263,"isFree":10,"estimatedMinutes":264,"difficulty":23,"learningObjectives":265},"Customer vs AWS Responsibilities","See exactly what AWS secures and what you secure, layer by layer, plus the three types of controls AWS uses to describe inherited, shared, and customer-only duties.",15,[266,267,268,269],"List the responsibilities AWS owns under security of the cloud","List the responsibilities the customer owns under security in the cloud","Compare AWS and customer duties across the stack","Describe inherited, shared, and customer-specific controls"]