- Newest
- Most votes
- Most comments
For NHS tender requirements regarding AWS cloud server locations, I can provide some guidance based on the UK public sector healthcare context.
When using AWS for NHS-related workloads, you'll need to consider the geographic locations where your data and services are hosted. AWS has multiple regions and availability zones globally, but specific physical addresses of data centers are not typically disclosed for security reasons.
For UK public sector healthcare organizations, the NHS cloud security guidance (published in January 2018 by NHS Digital, Department of Health and Social Care, NHS England, and NHS Improvement) requires organizations to:
- Quantify the information security risks for their workloads
- Ensure their cloud provider implements necessary controls
- Adopt appropriate customer-usable controls
For your NHS tender, you should focus on documenting:
- The AWS regions and availability zones where your services are deployed
- How these locations comply with relevant data sovereignty requirements
- Your risk assessment regarding the geographic placement of data
- The controls implemented to manage those risks
Rather than providing physical addresses of AWS data centers, your tender response should demonstrate how your AWS implementation satisfies the NHS cloud security guidance, which builds on the National Cyber-Security Centre's 14 Cloud Security Principles.
For Amazon GameLift Servers specifically (if you're using this service), you can specify the AWS Regions and Local Zones where your game servers are deployed, as instance availability varies by location.
Sources
Choose compute resources for a managed fleet - Amazon GameLift Servers
Using AWS in the Context of NHS Cloud Security Guidance - Using AWS in the Context of NHS Cloud Security Guidance
Amazon GameLift Servers solutions - Amazon GameLift Servers
answered a year ago
Relevant content
asked 3 years ago
- AWS OFFICIALUpdated 3 years ago
