
AWS maintains compliance with dozens of global standards, helping customers meet their own compliance obligations.
Major compliance programs:
SOC 1, 2, 3 — system and organization controls for financial and security reporting
ISO 27001 — information security management
PCI DSS — payment card industry data security
HIPAA — health insurance portability and accountability (healthcare data)
FedRAMP — US federal government cloud authorization
GDPR — European data protection regulation
AWS Artifact: Self-service portal for accessing AWS compliance reports and agreements. Download SOC reports, ISO certifications, PCI reports on demand.
AWS Organizations: Centrally manage multiple AWS accounts. Apply Service Control Policies (SCPs) to restrict what services/actions are available in member accounts. Consolidated billing.
AWS Config: Records configuration of AWS resources; tracks changes over time; enables compliance auditing. Answers: "What did my infrastructure look like at X time?"
AWS Control Tower: Set up and govern a multi-account AWS environment with security guardrails and best practices.
Reference:
TaskLoco™ — The Sticky Note GOAT