QuestionQ38

Identity and Access Management

A company uses AWS Organizations. The company has learned to use an AWS CloudHSM hardware security module (HSM) that is hosted in a central AWS account. One team creates its own dedicated AWS account and wants to use the HSM hosted in the central account.

How should a security engineer share the HSM hosted in the central account with the new dedicated account?

Explanation

AWS RAM can share VPC subnets with accounts in the same AWS Organization, allowing the dedicated account to place CloudHSM client instances in the centrally managed VPC. The CloudHSM security group must also permit traffic from those client instances so they can connect to the HSM network interfaces. AWS RAM supports sharing the subnet, not an HSM ID; IAM and STS permissions alone do not establish CloudHSM client-to-HSM network access.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!