Glossary

    AWS Audit Manager

    Compliance & Governance

    AWS Audit Manager helps you continuously audit your AWS usage to simplify how you assess risk and compliance with regulations and industry standards.

    Key Features

    • Pre-built Frameworks: PCI DSS, HIPAA, SOC 2, GDPR, NIST 800-53, NIST CSF, CIS Benchmarks, ISO 27001, FedRAMP
    • Custom Frameworks: build your own compliance frameworks with custom controls
    • Automated Evidence Collection: automatically collects evidence from Config, CloudTrail, Security Hub, and manual sources
    • Assessment Reports: generate auditor-ready reports with evidence mapped to controls
    • Delegation: assign control owners to collect manual evidence

    How It Works

    1. Select a framework (e.g., PCI DSS v4.0)
    2. Audit Manager maps framework controls to AWS data sources
    3. Evidence is automatically collected and organized by control
    4. Review evidence, add manual evidence, generate assessment report
    5. Share report with external auditors

    Related AWS Services

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.