View a markdown version of this page

LSOPS03-BP02 Limit available services to improve regulatory adherence - Life Sciences Lens

LSOPS03-BP02 Limit available services to improve regulatory adherence

Use infrastructure tooling to allow only services that fit into required regulatory frameworks.

Desired outcome: Only approved services will be available for use.

Level of risk exposed if this best practice is not established: Medium

Implementation guidance

Verify components and services used as available to comply with identified frameworks. Check vendor documentation to confirm that the products you use are approved at the vendor level.

Implementation steps

  1. Identify the available services by referring to AWS Compliance Programs.

  2. Review audit guides for the available services.

  3. Setup an AWS Organization to be able to centrally manage policies and controls.

  4. Implement service control policies (SCP) limiting access to only the available services.

Resources

Related guides, videos, and documentation:

Related tools: