Security foundations
| DRHCSEC01: Have you updated and validated your control objectives to address data residency compliance requirements? |
|---|
Based on your requirements and risks identified from your data residency compliance requirements, update and validate the control objectives and controls that apply to the workload. Ongoing validation of control objectives and controls help you measure the effectiveness of risk mitigation.
| DRHCSEC02: Does your account management strategy separate workloads that have different data residency requirements? |
|---|
Separating workloads at the AWS account level is recommended, as it provides a strong separation boundary and simplifies the implementation of preventative controls, such as Identity and Access Management (IAM) policies and service control policies (SCPs), as well as detective controls.
Best practices
DRHCSEC01-BP01 Update your control objectives to address your data residency compliance requirements
DRHCSEC01-BP02 Document any differences in the treatment of log data into the control objectives
DRHCSEC02-BP01 Separate workloads that have different data residency requirements
DRHCSEC02-BP02 Manage workloads with similar data residency requirements efficiently