View a markdown version of this page

Security foundations - Data Residency and Hybrid Cloud Lens

Security foundations

DRHCSEC01: Have you updated and validated your control objectives to address data residency compliance requirements?

Based on your requirements and risks identified from your data residency compliance requirements, update and validate the control objectives and controls that apply to the workload. Ongoing validation of control objectives and controls help you measure the effectiveness of risk mitigation.

DRHCSEC02: Does your account management strategy separate workloads that have different data residency requirements?

Separating workloads at the AWS account level is recommended, as it provides a strong separation boundary and simplifies the implementation of preventative controls, such as Identity and Access Management (IAM) policies and service control policies (SCPs), as well as detective controls.