QuestionQ46

Data Protection

A company runs its application on AWS. It uses a multi-environment arrangement in which each environment is isolated in its own AWS account. The company uses an AWS Organizations organization to manage these accounts, with one dedicated security account for the organization.

The company needs to create an inventory of all sensitive data stored in Amazon S3 buckets across the organization’s accounts. The findings must be available from one central location.

Which solution meets these requirements?

Explanation

Amazon Macie discovers and reports sensitive data in Amazon S3. When integrated with AWS Organizations, a delegated Macie administrator can centrally manage member accounts and discover sensitive data in their S3 buckets. Macie can publish sensitive-data findings to AWS Security Hub, whose delegated administrator provides a centralized view of member-account findings.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!