Glossary

    AWS Artifact

    Compliance & Governance

    AWS Artifact is a self-service portal that provides on-demand access to AWS's compliance documentation and agreements.

    Available Reports

    • SOC Reports: SOC 1, SOC 2, SOC 3 (Service Organization Control)
    • PCI DSS: Attestation of Compliance (AOC) and Responsibility Summary
    • ISO Certifications: ISO 27001, 27017, 27018, 9001
    • FedRAMP: FedRAMP security package
    • HIPAA: documentation supporting HIPAA compliance
    • Pen Test Reports: third-party penetration test reports on AWS infrastructure

    Agreements

    • Business Associate Agreement (BAA): required for HIPAA compliance
    • Non-Disclosure Agreement (NDA): for accessing sensitive compliance documents
    • Data Processing Addendum (DPA): for GDPR compliance

    Use Cases

    • Provide AWS compliance evidence to your auditors
    • Demonstrate that AWS infrastructure meets specific regulatory requirements
    • Accept agreements required for handling regulated data

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.