System and Organization Controls 3 (SOC 3) Report
Total Page:16
File Type:pdf, Size:1020Kb
System and Organization Controls 3 (SOC 3) Report Report on the Amazon Web Services System Relevant to Security, Availability, and Confidentiality For the Period October 1, 2020 – March 31, 2021 ©2021 Amazon.com, Inc. or its affiliates Amazon Web Services 410 Terry Avenue North Seattle, WA 98109-5210 Management’s Report of its Assertions on the Effectiveness of Its Controls Over the Amazon Web Services System Based on the Trust Services Criteria for Security, Availability, and Confidentiality We, as management of, Amazon Web Services, Inc. are responsible for: • Identifying the Amazon Web Services System (System) and describing the boundaries of the System, which are presented in Attachment A • Identifying our principal service commitments and system requirements • Identifying the risks that would threaten the achievement of our principal service commitments and service requirements that are the objectives of our system, which are presented in Attachment B • Identifying, designing, implementing, operating, and monitoring effective controls over the System to mitigate risks that threaten the achievement of the principal service commitments and system requirements • Selecting the trust services categories that are the basis of our assertion We assert that the controls over the system were effective throughout the period October 1, 2020 to March 31, 2021, to provide reasonable assurance that the principal service commitments and system requirements were achieved based on the criteria relevant to security, availability, and confidentiality set forth in the AICPA’s TSP section 100, 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy. Very truly yours, Amazon Web Services Management ©2021 Amazon.com, Inc. or its affiliates 4 Attachment A – Amazon Web Services System AWS Background Since 2006, Amazon Web Services (AWS) has provided flexible, scalable and secure IT infrastructure to businesses of all sizes around the world. With AWS, customers can deploy solutions on a cloud computing environment that provides compute power, storage, and other application services over the Internet as their business needs demand. AWS affords businesses the flexibility to employ the operating systems, application programs, and databases of their choice. The scope covered in this report consists of the following services: • AWS Amplify • AWS IoT Device Management • Amazon API Gateway • AWS IoT Events • AWS App Mesh • AWS IoT Greengrass • Amazon AppStream 2.0 • Amazon Kendra • AWS AppSync • AWS Key Management Service (KMS) • Amazon Athena • Amazon Keyspaces (for Apache • Amazon Augmented AI [excludes Public Cassandra) Workforce and Vendor Workforce] • Amazon Kinesis Data Analytics • Amazon EC2 Auto Scaling • Amazon Kinesis Data Firehose • AWS Backup • Amazon Kinesis Data Streams • AWS Batch • Amazon Kinesis Video Streams • AWS Certificate Manager (ACM) • AWS Lambda • Amazon Chime • Amazon Lex • Amazon Cloud Directory • AWS License Manager • AWS Cloud Map • Amazon Macie • AWS CloudFormation • Amazon Macie Classic • Amazon CloudFront • AWS Managed Services • AWS CloudHSM • Amazon Managed Streaming for Apache • AWS CloudTrail Kafka • Amazon CloudWatch • Amazon MQ • Amazon CloudWatch Logs • Amazon Neptune • Amazon CloudWatch SDK Metrics for • AWS OpsWorks Stacks Enterprise Support • AWS OpsWorks for Chef Automate or • AWS CodeBuild AWS OpsWorks for Puppet Enterprise • AWS CodeCommit • AWS Organizations • AWS CodeDeploy • AWS Outposts • AWS CodePipeline • AWS Personal Health Dashboard • Amazon Cognito • Amazon Personalize • Amazon Comprehend • Amazon Pinpoint • Amazon Comprehend Medical • Amazon Polly • AWS Config • Amazon Quantum Ledger Database • Amazon Connect (QLDB) • AWS Control Tower • Amazon QuickSight • AWS Data Exchange • Amazon Redshift ©2021 Amazon.com, Inc. or its affiliates 5 • AWS Database Migration Service (DMS) • Amazon Rekognition • AWS DataSync • Amazon Relational Database Service • Amazon Detective (RDS) • AWS Direct Connect • AWS Resource Groups • AWS Directory Service [excludes Simple AD] • AWS RoboMaker • Amazon DocumentDB [with MongoDB • Amazon Route 53 compatibility] • Amazon SageMaker • Amazon DynamoDB • AWS Secrets Manager • AWS Elastic Beanstalk • AWS Security Hub • Amazon Elastic Block Store (EBS) • AWS Server Migration Service (SMS) • Amazon Elastic Compute Cloud (EC2) • AWS Serverless Application Repository • Amazon Elastic Container Registry (ECR) • AWS Service Catalog • Amazon Elastic Container Service [both • AWS Shield Fargate and EC2 launch types] • Amazon Simple Email Service (SES) • Amazon Elastic Kubernetes Service (EKS) • Amazon Simple Notification Service (SNS) • Amazon Elastic File System (EFS) • Amazon Simple Queue Service (SQS) • Amazon Elasticsearch Service • Amazon Simple Storage Service (S3) • Elastic Load Balancing (ELB) • Amazon Simple Workflow Service (SWF) • Amazon ElastiCache for Redis • Amazon SimpleDB • AWS Elemental MediaConnect • AWS Snowball • AWS Elemental MediaConvert • AWS Snowball Edge • AWS Elemental MediaLive • AWS Snowmobile • Amazon Elastic MapReduce (EMR) • AWS Step Functions • Amazon EventBridge • AWS Storage Gateway • AWS Firewall Manager • AWS Systems Manager • Amazon Forecast • Amazon Textract • Amazon FreeRTOS • Amazon Timestream • Amazon FSx • Amazon Transcribe • Amazon S3 Glacier • AWS Transfer Family • AWS Global Accelerator • Amazon Translate • AWS Glue • Amazon Virtual Private Cloud (VPC) • AWS Glue DataBrew • AWS Web Application Firewall (WAF) • Amazon GuardDuty • Amazon WorkDocs • AWS Identity and Access Management (IAM) • Amazon WorkLink • VM Import/Export • Amazon WorkMail • Amazon Inspector • Amazon WorkSpaces • AWS IoT Core • AWS X-Ray More information about the in scope services, including the namespace1, can be found at https://aws.amazon.com/compliance/services-in-scope/ The scope of locations covered in this report includes the supporting data centers located in: 1 When customers create IAM policies or work with Amazon Resource Names (ARNs), customers identify an AWS service using a namespace. For example, the namespace for Amazon S3 is s3, and the namespace for Amazon EC2 is ec2. Customers use namespaces when identifying actions and resources across AWS. ©2021 Amazon.com, Inc. or its affiliates 6 • Australia: Asia Pacific (Sydney) (ap-southeast-2) • Bahrain: Middle East (Bahrain) (me-south-1) • Brazil: South America (São Paulo) (sa-east-1) • Canada: Canada (Central) (ca-central-1) • England: Europe (London) (eu-west-2) • France: Europe (Paris) (eu-west-3) • Germany: Europe (Frankfurt) (eu-central-1) • Hong Kong: Asia Pacific (ap-east-1) • India: Asia Pacific (Mumbai) (ap-south-1) • Ireland: Europe (Ireland) (eu-west-1) • Italy: Europe (Milan) (eu-south-1) • Japan: Asia Pacific (Tokyo) (ap-northeast-1), Asia Pacific (Osaka) (ap-northeast-3) • Singapore: Asia Pacific (Singapore) (ap-southeast-1) • South Africa: Africa (Cape Town) (af-south-1) • South Korea: Asia Pacific (Seoul) (ap-northeast-2) • Sweden: Europe (Stockholm) (eu-north-1) • United States: US East (Northern Virginia) (us-east-1), US East (Ohio) (us-east-2), US West (Oregon) (us-west-2), US West (Northern California) (us-west-1), AWS GovCloud (US-East) (us-gov-east-1), AWS GovCloud (US-West) (us-gov-west-1) and the following AWS Edge locations: • Buenos Aires, Argentina • Budapest, Hungary • Singapore • Canberra, Australia • Ahmedabad, India • Cape Town, South Africa • Melbourne, Australia • Bengaluru, India • Johannesburg, South Africa • Perth, Australia • Bhubaneswar, India • Madrid, Spain • Sydney, Australia • Chennai, India • Stockholm, Sweden • Vienna, Austria • Hyderabad, India • Zurich, Switzerland • Brussels, Belgium • Jaipur, India • Taipei, Taiwan • Rio de Janeiro, Brazil • Kolkata, India • Bangkok, Thailand • São Paulo, Brazil • Mumbai, India • Dubai, United Arab Emirates • Sofia, Bulgaria • New Delhi, India • Fujairah, United Arab Emirates • Montréal, Canada • Patna, India • Arizona, United States • Toronto, Canada • Jakarta, Indonesia • California, United States • Vancouver, Canada • Dublin, Ireland • Colorado, United States • Santiago, Chile • Tel Aviv, Israel • Florida, United States • Bogota, Colombia • Milan, Italy • Georgia, United States • Prague, Czech Republic • Palermo, Italy • Illinois, United States • Hong Kong, China • Rome, Italy • Indiana, United States • Zagreb, Croatia • Osaka, Japan • Massachusetts, United States • Copenhagen, Denmark • Tokyo, Japan • Michigan, United States • Birmingham, England • Nairobi, Kenya • Minnesota, United States • Bristol, England • Seoul, Korea • Missouri, United States • Hull, England • Kuala Lumpur, Malaysia • Nevada, United States • London, England • Querétaro, Mexico • New Jersey, United States • Manchester, England • Amsterdam, Netherlands • New York, United States ©2021 Amazon.com, Inc. or its affiliates 7 • Helsinki, Finland • Auckland, New Zealand • Ohio, United States • Marseille, France • Christchurch, New Zealand • Oregon, United States • Paris, France • Oslo, Norway • Pennsylvania, United States • Berlin, Germany • Panama City, Panama • Tennessee, United States • Dusseldorf, Germany • Lima, Peru • Texas, United States • Frankfurt, Germany • Manila, Philippines • Utah, United States • Hamburg, Germany • Warsaw, Poland • Virginia, United States • Munich, Germany • Lisbon, Portugal • Washington, United States • Athens, Greece • Bucharest, Romania as well as Wavelength or Local Zones in the following locations: • California, United States • Maryland, United States • Nevada, United States