Se ha denunciado esta presentación.
Utilizamos tu perfil de LinkedIn y tus datos de actividad para personalizar los anuncios y mostrarte publicidad más relevante. Puedes cambiar tus preferencias de publicidad en cualquier momento.
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS GovCloud (US): A path to high compliance in
t...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS global infrastructure
21
Regions
66
Availabil...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
How can public sector and highly-regulated custom...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS GovCloud (US)
Isolated AWS infrastructure and...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS GovCloud (US) distinguishing features
Unique ...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
Defense Federal Acquisition Regulation
Supplement...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
Export Administration Regulation
(EAR)
… to inclu...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
Fit for all types of controlled unclassified info...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
US Government
Federal, state, and local
Consultin...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
Web applications
and websites
Backup, recovery
an...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
Tools and resources to
accelerate time to
complia...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
How do I get started with architecting and migrat...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
Understanding the shared responsibility of compli...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
Security control inheritance delineates responsib...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS gets customers at least 60% along their compl...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
ITAR: Securing export - controlled data in the Cl...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
ITAR: Securing export-controlled data in the Clou...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
ITAR: Securing export-controlled data in the Clou...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
FedRAMP: Meeting FISMA requirementsin the Cloud
A...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
FedRAMP: Meeting FISMA requirementsin the Cloud
A...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
FedRAMP: Meeting FISMA requirementsin the Cloud
A...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
CJIS: Safeguarding criminal justice data in the C...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
CJIS: Safeguarding criminal justice data in the C...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
DFARS: Protectingdefense industry data in the Clo...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
DFARS: Protectingdefense industry data in the Clo...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
DFARS: Protectingdefense industry data in the Clo...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
DFARS: Protectingdefense industry data in the Clo...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
DFARS: Protectingdefense industry data in the Clo...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
Tools and resources for compliance in the Cloud
C...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
Authority to Operate (ATO) on AWS
Automating and ...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
Security & compliance acceleration program
Helps ...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
Amazon partner driven process
Includes:
✓ Trainin...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
Why ATO on AWS?
Security & compliance frameworks:...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
Benefits
Reduce effort to deploy security configu...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
Visibility and marketing for ISVs
ISV ATO’s for s...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
Accelerated from no presence in AWS GovCloud (US)...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
Built FedRAMP-compliant platform in less than six...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
Deployment of CJIS audit-ready RedFlex solution a...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
ATO on AWS Program
Automation leverages Infrastru...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
Goal
Verifiable compliance control solution for r...
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS GovCloud (US) Information
Homepage: https://a...
Thank you!
© 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
Keith Brooks
brookskl@amazon.com
Tim S...
Próxima SlideShare
Cargando en…5
×

AWS GovCloud (US): A path to high compliance in the cloud - GRC344 - AWS re:Inforce 2019

178 visualizaciones

Publicado el

AWS GovCloud (US) is an offering of isolated AWS infrastructure and services that address stringent US regulatory and compliance requirements. Government agencies and private sector enterprises in regulated industries leverage AWS GovCloud to run mission-critical and sensitive workloads on the cloud. This session details AWS GovCloud and the use cases and workloads that are fit for it, including how it can help address ITAR, FedRAMP, DOD SRG, CJIS, DFARS, and other requirements. We cover the Authority to Operate on AWS program and how it helps speed up the time to compliance for workloads in AWS GovCloud. Come learn about AWS GovCloud and the benefits of automating security and compliance.

  • DOWNLOAD FULL BOOKS, INTO AVAILABLE FORMAT ......................................................................................................................... ......................................................................................................................... 1.DOWNLOAD FULL. PDF EBOOK here { https://tinyurl.com/y6a5rkg5 } ......................................................................................................................... 1.DOWNLOAD FULL. EPUB Ebook here { https://tinyurl.com/y6a5rkg5 } ......................................................................................................................... 1.DOWNLOAD FULL. doc Ebook here { https://tinyurl.com/y6a5rkg5 } ......................................................................................................................... 1.DOWNLOAD FULL. PDF EBOOK here { https://tinyurl.com/y6a5rkg5 } ......................................................................................................................... 1.DOWNLOAD FULL. EPUB Ebook here { https://tinyurl.com/y6a5rkg5 } ......................................................................................................................... 1.DOWNLOAD FULL. doc Ebook here { https://tinyurl.com/y6a5rkg5 } ......................................................................................................................... ......................................................................................................................... ......................................................................................................................... .............. Browse by Genre Available eBooks ......................................................................................................................... Art, Biography, Business, Chick Lit, Children's, Christian, Classics, Comics, Contemporary, Cookbooks, Crime, Ebooks, Fantasy, Fiction, Graphic Novels, Historical Fiction, History, Horror, Humor And Comedy, Manga, Memoir, Music, Mystery, Non Fiction, Paranormal, Philosophy, Poetry, Psychology, Religion, Romance, Science, Science Fiction, Self Help, Suspense, Spirituality, Sports, Thriller, Travel, Young Adult,
       Responder 
    ¿Estás seguro?    No
    Tu mensaje aparecerá aquí
  • Sé el primero en recomendar esto

AWS GovCloud (US): A path to high compliance in the cloud - GRC344 - AWS re:Inforce 2019

  1. 1. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS GovCloud (US): A path to high compliance in the cloud Keith Brooks Senior Manager – AWS GovCloud (US) AWS G R C 3 4 4 Tim Sandage Senior Partner Security Strategist AWS
  2. 2. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS global infrastructure 21 Regions 66 Availability zones New Region (coming soon) Bahrain Jakarta Milan Cape Town AWS GovCloud (US) Region
  3. 3. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. How can public sector and highly-regulated customers move their most sensitive workloads to the AWS Cloud?
  4. 4. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS GovCloud (US) Isolated AWS infrastructure and services for customers with strict regulatory and compliance requirements and sensitive data August 2011Launch of AWS GovCloud (US-west) region November 2018Launch of AWS GovCloud (US-east) region Addresses the most stringent US Government regulations, policies and security requirements
  5. 5. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS GovCloud (US) distinguishing features Unique authentication (unique GovCloud credentials) 2 AWS GovCloud regions Bi-coastal infrastructure and services for regulated workloads Data, network, and machine isolation (separate AZs, endpoints) “Community Cloud” with restricted access Managed by U.S. citizens on U.S. soil Dedicated GovCloud AWS management console
  6. 6. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Defense Federal Acquisition Regulation Supplement (DFARS) Criminal Justice Information Service Security Policy (CJIS) AWS GovCloud is all about compliance in the Cloud International Traffic and Arms Regulation (ITAR) DOD Cloud Security Req’s Guide (SRG) IL 4 and 5 SP 800-53 (rev 4) SP 800-171 Federal Information Processing Standard Pub (FIPS) 140-2 IRS – 1075 (Section 6103 (p)) FedRAMP High
  7. 7. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Export Administration Regulation (EAR) … to include broader AWS security and compliance Health Insurance Portability & Accountability Act (HIPAA) Payment Card Industry Data Security Standard (PCI) AICPA Service Organization Control Reports (SOC) Family Educational Rights and Privacy Act (FERPA) International Organization for Standardization (ISO)
  8. 8. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Fit for all types of controlled unclassified information CUI is information that requires safeguarding or dissemination controls pursuant to and consistent with applicable law, regulations, and government-wide policies but is not classified under Executive Order 13526 or the Atomic Energy Act, as amended. Agriculture Copyright Critical infrastructure Export control Financial Immigration Intelligence Law enforcement Legal Nuclear Patent Privacy (PII) Proprietary (IP) Statistical (Census) Tax Transportation
  9. 9. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. US Government Federal, state, and local Consulting firms and systems integrators Technology firms and ISVs Education institutions Research organizations Regulated industries (Aerospace, Defense, Energy, Manufacturing, Healthcare, Finance) Nonprofit organizations Managed service providers Various types of organizations use AWS GovCloud (US)
  10. 10. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Web applications and websites Backup, recovery and archiving Disaster recovery Development and test Big data High-performance computing Enterprise IT Mobile applications Mission critical applications Data center migration and hybrid … for a variety of sensitive workloads and use cases
  11. 11. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Tools and resources to accelerate time to compliance Mission and business critical workload delivery Isolated, secure, and compliant IaaS and services Built for sensitive and regulated data including Controlled Unclassified Information (CUI) … for high compliance and assurance in the Cloud
  12. 12. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. How do I get started with architecting and migrating sensitiveand regulated workloads in the Cloud?
  13. 13. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Understanding the shared responsibility of compliance AWS Foundation Services Compute Storage Database Networking AWS Global Infrastructure Regions Availability Zones Edge Locations Client-side Data Encryption Server-side Data Encryption Network Traffic Protection Platform, Applications, Identity & Access Management Operating System, Network, & Firewall Configuration Customer applications & content Customers Customers choose the configurations for their security in the Cloud AWS is responsible for security of the Cloud
  14. 14. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Security control inheritance delineates responsibility AWS Foundation Services AWS Global Infrastructure Customers Shared/hybrid and customer implemented security controls Full and partially inherited security controls Media Protection (MP) and partial Maintenance (MA) Physical and Environmental (PE) and partial Contingency Planning (CP) Certification, Accreditation and Security Assessment (CA), Awareness & Training (AT), Planning (PL), Personnel Security (PS), Risk Assessment (RA) and System & Services Acquisition (SA) Access Control (AC), Audit & Accountability (AU), Configuration Management (CM), Maintenance (MA), Contingency Planning (CP), Identity and Authentication (IA), Incident Response (IR), Maintenance (MA), System and Communication Protection (SC), System and Information Integrity (SI)
  15. 15. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS gets customers at least 60% along their compliance journey in terms of security controls …
  16. 16. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. ITAR: Securing export - controlled data in the Cloud AWS GovCloud enables technical data identified on the US Munitions List to be stored and processed in an isolated environment physically in the US, managed by US citizens Learn the ITAR Boundary (applies to each AWS service) Example: ITAR boundary for Amazon Elastic Block Store (EBS)
  17. 17. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. ITAR: Securing export-controlled data in the Cloud AWS GovCloud enables technical data identified on the US Munitions List to be stored and processed in an isolated environment physically in the US, managed by US citizens Encryption as standard practice (S3 SSE, AWS CloudHSM, AWS KMS) Architect for visibility (audit-all via Amazon CloudTrail) Access control is cornerstone (AWS IAM, security policies, federation)
  18. 18. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. ITAR: Securing export-controlled data in the Cloud AWS GovCloud supports storage and processing of technical data identified on the US Munitions List in an isolated environment physically in the U.S., managed by U.S. citizens Understand responsibilities Individuals and entities qualify as U.S. Person Valid directorate of trade controls registration Export privileges under U.S. laws and regulations Maintain an effective compliance program
  19. 19. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. FedRAMP: Meeting FISMA requirementsin the Cloud AWS GovCloud enables cloud workloads to address the highest level of U.S. Government FISMA (High) data security requirements at the infrastructure and cloud services layers 417 Security controls at high baseline (NIST 800-53 is foundation)
  20. 20. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. FedRAMP: Meeting FISMA requirementsin the Cloud AWS GovCloud enables cloud workloads to address the highest level of U.S. Government FISMA (High) data security requirements at the infrastructure and cloud services layers Tools no matter starting point (Data/server/app migration, cloud native) Compliant connectivity (AWS VPC/VPN, Amazon Direct Connect) Inheritance from AWS (25+ FedRAMP High services)
  21. 21. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. FedRAMP: Meeting FISMA requirementsin the Cloud AWS GovCloud enables cloud workloads to address the highest level of U.S. Government FISMA (High) data security requirements at the infrastructure and cloud services layers AWS user guide documentation Copies of AWS Authority-to-Operate (ATO) memos Copy of AWS FIPS-199 categorization Copy of AWS E-Authentication Copy of AWS Privacy Impact Assessment (PIA) Copy of AWS Control Implementation Summary (CIS) Copy of AWS Customer Responsibility Matrix (CRM) Copy of AWS SSP template AWS FedRAMP Package
  22. 22. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. CJIS: Safeguarding criminal justice data in the Cloud AWS GovCloud is architected to provide infrastructure and services for law enforcement agencies and solutions providers to securely meet CJIS requirements and responsibilities Criminal Justice Agencies (CJA’s) and Non- Criminal Justice Agencies (NCJA’s) in all 50 states can operate CJI workloads on AWS GovCloud (US)
  23. 23. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. CJIS: Safeguarding criminal justice data in the Cloud AWS GovCloud is architected to provide infrastructure and services for law enforcement agencies and solutions providers to securely meet CJIS requirements and responsibilities Encrypt at rest and in transit (FIPS 140-2 endpoints, SSE features) Customer key management (AWS KMS, AWS CloudHSM) Technical review audit support (CJA/NCJA CJIS responsibilities remain) AWS CJIS Whitepaper and Security templates available to guide CJIS architectures
  24. 24. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. DFARS: Protectingdefense industry data in the Cloud AWS GovCloud facilitates defense contractor compliance with DFARS 252.204-7012 “Safeguarding Covered Defense Information and Cyber Incident Reporting” DFARS 252.204-7012 (b) (2) (i) NIST 800-171 Compliance FedRAMP High authorized based on NIST 800-53 rev 4 controls NIST 800-171 has 110 controls, a subset of NIST 800-53 rev 4 AWS NIST Quick Start automates setup of NIST compliant environment
  25. 25. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. DFARS: Protectingdefense industry data in the Cloud AWS GovCloud facilitates defense contractor compliance with DFARS 252.204-7012 “Safeguarding Covered Defense Information and Cyber Incident Reporting” DFARS 252.204-7012 (b) (2) (ii) (D) FedRAMP Compliance 2 FedRAMP High authorized AWS Regions are available to customers AWS FedRAMP Package documents AWS compliance and controls 25+ FedRAMP High services for customers to leverage for workloads
  26. 26. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. DFARS: Protectingdefense industry data in the Cloud AWS GovCloud facilitates defense contractor compliance with DFARS 252.204-7012 “Safeguarding Covered Defense Information and Cyber Incident Reporting” DFARS 252.204-7012 (c) Incident Reporting FedRAMP High authorized based on NIST 800-53 rev 4 controls Notification of security incident via email within 24 hours Customer submits cyber incidents of which AWS notifies of via DIBnet AWS Enterprise Support for 24x7 support for mission critical workloads
  27. 27. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. DFARS: Protectingdefense industry data in the Cloud AWS GovCloud facilitates defense contractor compliance with DFARS 252.204-7012 “Safeguarding Covered Defense Information and Cyber Incident Reporting” DFARS 252.204-7012 (d) MaliciousSoftware Tools to assistance with customer responsibility for malicious detection AWS response and reporting of malicious software via FedRAMP ATO
  28. 28. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. DFARS: Protectingdefense industry data in the Cloud AWS GovCloud facilitates defense contractor compliance with DFARS 252.204-7012 “Safeguarding Covered Defense Information and Cyber Incident Reporting” DFARS 252.204-7012 (e) Media preservationand protection Instance snapshot, logging and audit capabilities available for customers Ability for customers to preserve evidence to provide to DOD as required
  29. 29. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Tools and resources for compliance in the Cloud Compliance documentation (Packages, whitepapers, control matrix) AWS quick starts (accelerators for compliance) Compliance SMEs (Security specialists, architects)
  30. 30. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Authority to Operate (ATO) on AWS Automating and accelerating security and compliance for workloads on the AWS Cloud
  31. 31. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Security & compliance acceleration program Helps Customers, Partners, Independent Solution Vendors (ISVs) Outcomes Accelerates security & compliance authorization process Reduces cost & time (Average 18-24 months) - FedRAMP Provides reusable artifacts including guidance, templates, tools, and pre- built templates from Amazon Partner Solutions Builds and optimizes DevOps, SecOps, Continuous Integration/Continuous Delivery (CI/CD), Continuous Risk Treatment (CRT) strategies Develops proven Techniques using AWS Security Automation and Orchestration (SAO) methodology What is ATO on AWS?
  32. 32. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Amazon partner driven process Includes: ✓ Training ✓ Tools ✓ Pre-built automated deployment capabilities ✓ Control implementation details ✓ Pre-built artifacts ✓ Direct engagement ✓ Qualified system integrators ✓ Visibility and marketing Breaking it down
  33. 33. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Why ATO on AWS? Security & compliance frameworks: ✓ Average time to FedRAMP ATO: 18 – 24 Months ✓ Average time to a DoD PA ATO (IL4/IL5): 24 – 36 Months ✓ Average time to a IRS-1075 Authorization: 12 – 18 Months ✓ Average time to a PCI-DSS Certifications: 10 – 12 Months ✓ Average time to a CJIS Authorization: 6 – 10 Months ✓ Average time to a HITRUST Certification: 6 – 12 Months
  34. 34. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Benefits Reduce effort to deploy security configurations and collect audit data to meet compliance requirements for solutions on AWS Build an end-to-end automation capability to streamline regulated workload deployments Collaborate in APN Joint Partner Programs supported by AWS to develop and deliver unique capabilities and solutions Works with Qualified System Integrators: ✓ To build and support environments that meet compliance standards and requirements ✓ To minimize and simplify ISV’s area of responsibility by offloadinghosting and compliance management ATO on AWS?
  35. 35. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Visibility and marketing for ISVs ISV ATO’s for solutions published and marketed on the ATO on AWS landing page with the option of a written or video case study ATO on AWS APN designations for the solutions that can be used by the ISV in their marketing artifacts and materials ATO on AWS designation ✓ FedRAMP on AWS ✓ DoD SRG on AWS ✓ CJIS on AWS ✓ PCI on AWS ✓ HITRUST on AWS ✓ IRS-1075 on AWS
  36. 36. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Accelerated from no presence in AWS GovCloud (US) to FedRAMP-ready and compliant in less than 90 days.
  37. 37. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Built FedRAMP-compliant platform in less than six months, was able to attract a new government customer, and reduced costs.
  38. 38. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Deployment of CJIS audit-ready RedFlex solution and environment within 30 days, including documentation.
  39. 39. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. ATO on AWS Program Automation leverages Infrastructure as Code concepts Certification optimizes security processes Validation enables continual tests and monitoring of security configurations Empowerment emboldens informed decision-making and drives change Guiding Tenets for ATO on AWS
  40. 40. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Goal Verifiable compliance control solution for regulated workloads Outcomes Accelerated path-to-production Improved compliance and security posture Reduction in non-compliant findings and re-work Demonstrable controls to support the assessment process Implement security and compliant architectures
  41. 41. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS GovCloud (US) Information Homepage: https://aws.amazon.com/govcloud-us User Guide: docs.aws.amazon.com/govcloud-us/latest/UserGuide/welcome.html Services in Scope: https://aws.amazon.com/compliance/services-in-scope/ ATO on AWS Program Information Partners: https://aws.amazon.com/partners/ato/partners/ Customers: https://aws.amazon.com/partners/ato/ FAQ: https://aws.amazon.com/partners/ato/faqs/
  42. 42. Thank you! © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Keith Brooks brookskl@amazon.com Tim Sandage sandaget@amazon.com Thank you! © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Keith Brooks brookskl@amazon.com Tim Sandage sandaget@amazon.com

×