A Beginner’s Guide to Security and Regulatory Compliance in AWS

HomeInsightsBlogs | Last Updated June 28, 2023 - by brett crawford under data science & analytics

Published onFebruary 24, 2021

The accelerating migration of enterprise applications to the Cloud promises to bring individual business units greater control and flexibility over their computing resources and data. But with great power also comes great responsibility. Aspects of regulatory compliance and network security that were once exclusively the domain of IT will become more relevant to individuals across the organization. HIPPA, PCI 3DS, GDPR, CCPA, PDPO, PDPA-the alphabet soup of industry- and geography-specific regulatory regimes can quickly become mind-numbing. And how do you even begin to ensure that your application and networks that it operates on are secure, resilient, and resistant to attack?

The AWS Shared Responsibility Model

Fortunately, with Amazon Web Service’s (AWS) Shared Responsibility Model, only part of this load falls on your shoulders. The Shared Responsibility Model creates a distinction between the security and regulatory compliance responsibilities of AWS and your role in configuring and managing the AWS services used by your application. It is summarized by AWS as “security of the Cloud” versus “security in the Cloud.”

AWS is responsible for ensuring the security and regulatory compliance of all their global infrastructure. This includes both hardware (physical data centers and servers) and software (computing, networking, storage, and database services).  AWS regularly undergoes independent audits that verify the security of their physical infrastructure and obtains certifications from specific regulatory agencies for individual services and solutions. More details on AWS’s compliance programs can be found here.

However, you are responsible for making sure that services used by your application are configured in a way that is secure and compliant with applicable regulations. The level of responsibility depends on the individual services used by your application. For example, services that provide low-level computing resources such as Elastic Compute Cloud (EC2) require that you manage all aspects of your security configuration, which can include installing patches to the operating system. This contrasts with an abstracted service like Simple Storage Service (S3), which only requires that you manage the data that you store in the Cloud. More information on the Shared Responsibility Model can be found here.

To assist you in managing the security and compliance of your Cloud resources, AWS provides a comprehensive set of tools and technical guides. Included are solutions that address data protection, threat detection, monitoring, access management, and data privacy. A full list of these tools can be found here.

Subscribe to our newsletter

Next Steps

You now know that only parts of security and regulatory compliance are the responsibility of users and that AWS provides tools that help you configure and manage your Cloud resources. But what exactly are these tools? And how do you use these tools to address the industry-specific regulations of your business? These questions will be the subject of the next post in this series as I explore the self-service security and compliance tools provided by AWS.

Brett Crawford

Brett is a consultant in our Data Science and Analytics practice. He enjoys applied mathematics and using data to solve real-world problems.

Contact Us

We're not around right now. But you can send us an email and we'll get back to you, asap.

Not readable? Change text. captcha txt

Start typing and press Enter to search