Security and Compliance in AL2027
Important
If you want to report a vulnerability or have a security concern
regarding AWS cloud services or open source projects, contact
AWS Security using the
Vulnerability Reporting page
AL2027 Preview
AL2027 is currently available for preview. It is intended for evaluation and testing only and is not recommended for production workloads.
Cloud security at AWS is the highest priority. As an AWS customer, you benefit from a data center and network architecture that is built to meet the requirements of the most security-sensitive organizations.
Security is a shared responsibility between AWS and you. The shared responsibility model
-
Security of the cloud – AWS is responsible for protecting the infrastructure that runs AWS services in the AWS Cloud. AWS also provides you with services that you can use securely. Third-party auditors regularly test and verify the effectiveness of our security as part of the AWS Compliance Programs
. To learn about the compliance programs that apply to Amazon Linux, see AWS Services in Scope by Compliance Program . -
Security in the cloud – Your responsibility is determined by the AWS service that you use. You are also responsible for other factors including the sensitivity of your data, your company's requirements, and applicable laws and regulations.
AL2027 includes several security enhancements over AL2023, see: Security updates and features
Topics
Security patching during preview
During the preview period, there is no guarantee that open CVEs for AL2027 packages will be patched in preview artifacts. AL2027 preview artifacts may have unpatched CVEs.
All CVE patching mechanisms and fixes will be in place before any public release.
FIPS validation
FIPS-validated kernel and crypto modules are not available in the preview. They will be available before GA.