View a markdown version of this page

Compliance validation for Amazon Quick - Amazon Quick

Compliance validation for Amazon Quick

Third-party auditors assess the security and compliance of Amazon Quick as part of multiple AWS compliance programs. Amazon Quick, across its web, desktop, and mobile clients, is in scope for the following programs:

  • Federal Risk and Authorization Management Program (FedRAMP)

  • Health Insurance Portability and Accountability Act (HIPAA)

  • Payment Card Industry Data Security Standard (PCI DSS)

  • System and Organization Controls (SOC) 1, SOC 2, and SOC 3

  • International Organization for Standardization (ISO) 9001, ISO 27001, ISO 27018, and ISO 27019

  • Cloud Computing Compliance Criteria Catalogue (C5) from the German Federal Office for Information Security (BSI)

  • Health Information Trust Alliance Common Security Framework (HITRUST CSF)

When a program lists Quick as in scope, the audits and assessments for that program include the service. In-scope status does not make your own workloads compliant. Under the shared responsibility model, you configure Quick and manage your data to meet the requirements that apply to you.

Compliance programs that include Quick

The following programs include Quick. For each program, use the linked AWS page to confirm the current status, the authorized AWS Regions, and any program details before you rely on the program for your own workloads.

FedRAMP

Quick is in scope for the FedRAMP program. To confirm the current authorization status and the authorized AWS Regions, see AWS services in scope for FedRAMP. You remain responsible for meeting the FedRAMP requirements that apply to your workloads.

HIPAA eligibility

Quick is a HIPAA Eligible Service. This eligibility applies across the Quick web, desktop, and mobile clients, subject to the shared responsibility model and your configuration. To process, store, or transmit protected health information (PHI), you must have an AWS Business Associate Addendum (BAA) in place. You must also configure the service according to your obligations. To confirm current eligibility, see the HIPAA Eligible Services Reference. For more information about using AWS to build HIPAA workloads, see HIPAA Overview.

PCI DSS

Quick is in scope for the Payment Card Industry Data Security Standard (PCI DSS). To confirm the current status, see AWS services in scope for PCI DSS. You are responsible for the security of the cardholder data that you handle in the service.

SOC reports

Quick is in scope for the AWS System and Organization Controls (SOC) reports, including SOC 1, SOC 2, and SOC 3. To confirm the current status and download the reports that describe the AWS controls, see AWS services in scope for SOC.

ISO 9001, ISO 27001, ISO 27018, and ISO 27019

Quick is in scope for the ISO 9001, ISO 27001, ISO 27018, and ISO 27019 standards. ISO 27018 is the code of practice for protecting personal data in the cloud. To confirm the current status and review the certifications, see ISO 27001 Overview and the AWS services in scope by compliance program page.

BSI C5

Quick is in scope for the AWS Cloud Computing Compliance Criteria Catalogue (BSI C5). To confirm the current status, see AWS services in scope for BSI C5.

HITRUST CSF

Quick is in scope for the HITRUST Common Security Framework (CSF). To confirm the current status, see AWS services in scope for HITRUST CSF.

Verifying current reports and scope

Program scope and audit reports change over time. To confirm the status that applies to you, use the following AWS resources.

Your compliance responsibilities

Your compliance responsibility when you use Amazon Quick depends on the sensitivity of your data, your company's compliance objectives, and applicable laws and regulations. Use the following AWS resources to help you meet your obligations:

  • Security and compliance quick start guides – These deployment guides discuss architectural considerations and provide steps for deploying security- and compliance-focused baseline environments on AWS.

  • AWS compliance resources – This collection of workbooks and guides might apply to your industry and location.

  • AWS Config – This AWS service assesses how well your resource configurations comply with internal practices, industry guidelines, and regulations.

  • AWS Security Hub CSPM – This AWS service provides a comprehensive view of your security state within AWS that helps you check your compliance with security industry standards and best practices.