AWS Artifact
AWS Artifact is a self-service portal of Amazon Web Services that provides on-demand access to security and compliance reports.
AI Practitioner focus
- Artifact supplies AWS compliance reports/certifications and agreements for due diligence. It does not assess a customer’s AI workload or collect evidence about the customer’s configuration.
- AWS Audit Manager organizes evidence about customer AWS usage; Amazon Config evaluates resource configuration; compliance still depends on the complete workload and applicable obligations.
Key points
- Provides an enterprise with access to security and compliance reports about the AWS public cloud, including ISO certifications, PCI DSS reports, and SOC (Service Organization Control) reports.
- Also provides agreements for download, such as the Business Associate Addendum (BAA) for HIPAA and a Nondisclosure Agreement (NDA).
- Supports security and compliance review processes for the organization.
- Complements AWS Security Hub’s compliance-standard checks (PCI DSS, CIS) by supplying the underlying audit reports on demand.
- Distinct from Amazon Config, which continuously monitors and records actual AWS resource configurations — Artifact only provides static, on-demand third-party audit reports and agreements, not live resource compliance data.
- The console is organized into two sections: Artifact Reports — on-demand download of AWS’s compliance and security reports (SOC, PCI DSS, ISO certifications, and similar) — and Artifact Agreements — reviewing, accepting, and tracking the status of agreements with AWS, such as the Business Associate Addendum (BAA) for HIPAA workloads or a Nondisclosure Agreement (NDA), for a single account or across multiple accounts in an organization.
- Any AWS customer can access Artifact through their AWS account at no extra cost; some agreements can only be accepted by the account owner or another individual explicitly authorized to accept agreements on the account’s behalf.
- It is free — AWS provides Artifact reports and agreements at no charge.
- Fits the AWS Shared Responsibility Model: Artifact is how a customer obtains evidence of AWS’s side of the shared responsibility split (AWS’s compliance with security standards and certifications) — it does not produce or certify evidence about the customer’s own configuration of their workload.