AWS CloudHSM | Compliance Flashcards

1
Q

Which events are not logged in CloudTrail?

Compliance

AWS CloudHSM | Security, Identity & Compliance

A

CloudTrail does not include any of the HSM device or access logs. These are provided directly to your AWS account via CloudWatch Logs. See the CloudHSM User Guide for more details.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which AWS compliance initiatives include CloudHSM?

Compliance

AWS CloudHSM | Security, Identity & Compliance

A

Please refer to the AWS Compliance site for more information about which compliance programs cover CloudHSM. Unlike other AWS services, compliance requirements regarding CloudHSM are often met directly by the FIPS 140-2 Level 3 validation of the hardware itself, rather than as part of a separate audit program.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Why is FIPS 140-2 Level 3 important?

Compliance

AWS CloudHSM | Security, Identity & Compliance

A

FIPS 140-2 Level 3 is a requirement of certain use cases, including document signing, payments, or operating as a public Certificate Authority for SSL certificates.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly