AWS Penetration Testing

1

I was asked by a customer how often does AWS perform penetration testing as part of their compliance for SOC and ISO27001. I couldn't find this in the SOC compliance report. Can you share this information ?

dannyb
질문됨 4달 전167회 조회
2개 답변
2

Hi,

Did you check the reports available in https://aws.amazon.com/artifact/ ?

That's probably where you have the best chance to find this kind of information.

Best,

Didier

profile pictureAWS
전문가
답변함 4달 전
profile picture
전문가
검토됨 4달 전
1

I often get questions like this from customers: "How [often] does AWS do <insert thing here> to comply with <insert compliance program here>".

The answer is that we do those things in a way and as often as is required to be compliant with the program. There is no specific answer that we can provide to either the "how" or "how often" or even "what" question - that's up to use and our auditors to ensure that we are compliant.

The best place to find information about this is to look at the compliance program documentation - in there you'll find the answer to "how can you be compliant with this program" and that's what we do.

This sounds a bit evasive and isn't intended that way - but it's how organisations reach a state of compliance - by proving to their auditors that they have met the requirements of the program.

profile pictureAWS
전문가
답변함 4달 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠