Security
AWS Artifact
Compliance Reports (SOC, PCI, ISO), Agreements (HIPAA BAA, GDPR DPA)
Tổng quan
AWS Artifact = Compliance document portal - Nơi download các tài liệu compliance và security của AWS.
Hai thành phần chính
1. AWS Artifact Reports
Reports = Tài liệu chứng nhận compliance của AWS từ third-party auditors.
2. AWS Artifact Agreements
Agreements = Các thỏa thuận pháp lý giữa bạn và AWS.
Compliance Reports
Các reports phổ biến
| Report | Mô tả | Ai cần? |
|---|---|---|
| SOC 1 | Financial controls | Auditors, Finance teams |
| SOC 2 | Security, Availability, Confidentiality | Security teams, Customers |
| SOC 3 | Public summary of SOC 2 | Marketing, Public disclosure |
| PCI DSS | Payment card security | E-commerce, Payment processing |
| ISO 27001 | Information security management | Enterprise compliance |
| HIPAA | Healthcare data protection | Healthcare organizations |
| FedRAMP | US Government cloud security | Government contractors |
Agreements
HIPAA BAA (Business Associate Addendum)
Cách sử dụng
So sánh với các services khác
| Câu hỏi | Service | Giải thích |
|---|---|---|
| "Download AWS compliance documents" | AWS Artifact | Download reports từ AWS |
| "Check if MY resources comply" | AWS Config | Evaluate YOUR config rules |
| "Get best practice recommendations" | AWS Trusted Advisor | Recommendations, không phải docs |
| "Scan for vulnerabilities" | AWS Inspector | Vulnerability scanning |
| "View audit logs" | AWS CloudTrail | API activity logs |
Exam Tips
[!IMPORTANT] AWS Artifact = Download AWS compliance documents. Nhớ keyword: "compliance reports", "certifications", "agreements", "HIPAA BAA"
Câu hỏi thường gặp
| Keyword trong câu hỏi | Đáp án |
|---|---|
| "Download compliance reports" | AWS Artifact |
| "Review AWS certifications" | AWS Artifact |
| "HIPAA BAA agreement" | AWS Artifact |
| "SOC reports" | AWS Artifact |
| "PCI DSS attestation" | AWS Artifact |
Key Points
- FREE - Included with AWS account
- Self-service - Download anytime
- Two components: Reports (download) + Agreements (accept)
- Organization-wide - Can accept agreements for all accounts
- Third-party audited - Reports from independent auditors