Enable AWS Artifact for Compliance Reports
Specification & Description
Use AWS Artifact to access AWS-issued security and compliance reports (SOC 2, ISO 27001, PCI DSS, FedRAMP) and attach them as evidence to AWS Audit Manager, a GRC or audit tool, providing auditors with a unified view of both AWS-managed and customer-managed controls under the Shared Responsibility Model.
Technical Specifications
AWS Artifact provides on-demand, NDA-gated access to AWS's own third-party audit reports. These documents serve as evidence for the 'Security of the Cloud' layer in the Shared Responsibility Model - i.e., the physical, network, and hypervisor controls that AWS operates on the customer's behalf. Linking these reports AWS Audit Manager, a GRC or audit tool ensures that internal and external auditors have a complete and traceable evidence package. AWS typically publishes updated SOC 1 and SOC 2 reports every six months; ISO and PCI reports are updated on their respective certification cycles. Organizations should establish a tracking mechanism to detect when new report versions are published and refresh their evidence accordingly.
Security Rationale
Auditors require documented proof that the underlying cloud infrastructure meets applicable compliance standards. Without current AWS Artifact reports, organizations cannot demonstrate the 'Security of the Cloud' component of their compliance posture, which can result in audit findings or certification failures regardless of the quality of customer-managed controls.