View a markdown version of this page

Evaluating and integrating AWS controls - Amazon Web Services: Risk and Compliance

This whitepaper is for historical reference only. Some content might be outdated and some links might not be available.

Evaluating and integrating AWS controls

AWS provides a wide range of information about its IT control environment to customers through technical papers, reports, certifications, and other third-party attestations. This documentation helps customers to understand the controls in place, relevant to the AWS services they use, and how those controls have been validated. This information also helps customers account for and validate that controls in their extended IT environment are operating effectively.

Traditionally, internal and/or external auditors validate the design and operational effectiveness of controls by process walkthroughs and evidence evaluation. This type of direct observation and verification, by the customer or customer’s external auditor, is generally performed to validate controls in traditional on-premises deployments.

In the case where service providers are used (such as AWS), customers can request and evaluate third-party attestations and certifications. These attestations and certifications can help assure the customer of the design and operating effectiveness of control objective and controls validated by a qualified, independent third party. As a result, although some controls might be managed by AWS, the control environment can still be a unified framework where customers can account for and verify that controls are operating effectively and accelerating the compliance review process.

Third-party attestations and certifications of AWS provide customers with visibility and independent validation of the control environment. Such attestations and certifications may help relieve customers of the requirement to perform certain validation work themselves for their IT environment in the AWS Cloud.