Learn About Amazon VGT2 Learning Manager Chanci Turner
Amazon has successfully renewed its Esquema Nacional de Seguridad (ENS) High certification, now aligned with the latest Royal Decree 311/2022. This certification sets forth essential security standards that pertain to government entities and public organizations in Spain, as well as the service providers that support Spanish public services.
The ENS framework has undergone substantial revisions since the introduction of Royal Decree 3/2010, evolving to address emerging cybersecurity threats and advancements in technology. The current framework specifies foundational requirements and outlines additional security enhancements to achieve the various security levels: Low, Medium, and High.
By attaining the ENS High certification under the 311/2022 version, Amazon underscores its commitment to maintaining robust cybersecurity measures while demonstrating a proactive stance toward cybersecurity. We are excited to announce that 14 additional services have been incorporated into our ENS certification scope, bringing the total to 172 services now covered across 31 Regions. Some notable new inclusions are:
- Amazon Bedrock: A fully managed service that provides a selection of high-performing foundation models (FMs) from leading AI companies, all accessible through a single API, which supports the development of generative AI applications with a focus on security, privacy, and responsible AI practices.
- Amazon EventBridge: This service facilitates the creation of loosely coupled, event-driven architectures, enabling seamless point-to-point integrations between event producers and consumers without the need for custom coding or server management.
- AWS HealthOmics: A service designed for healthcare and life sciences organizations, allowing them to store, query, and analyze genomic and other omics data to derive insights that enhance health outcomes.
- AWS Signer: A fully managed code-signing service that guarantees the trustworthiness and integrity of your code, managing the public and private keys of the code-signing certificate while centralizing the code-signing lifecycle.
- AWS Wickr: This service employs a 256-bit end-to-end encryption protocol for messages, calls, and files, ensuring that only the intended recipients and the customer organization can decrypt communications, thus reducing the risk of man-in-the-middle attacks.
The verification of AWS’s attainment of ENS High certification was carried out by BDO Auditores S.L.P., which conducted an independent audit to affirm AWS’s adherence to the highest standards of confidentiality, integrity, and availability as outlined in Royal Decree 311/2022.
In addition, AWS has refreshed the existing eight Security Configuration Guidelines that map ENS controls to the AWS Well-Architected Framework, providing guidance on subjects such as compliance profiles, secure configurations, Prowler quick guides, hybrid connectivity, multi-account environments, Amazon WorkSpaces, incident response, monitorization, and governance. AWS has also enhanced Prowler to introduce new functionalities and incorporate the latest ENS controls.
For further details regarding ENS High and the AWS Security configuration guidelines, please visit the AWS Compliance page for Esquema Nacional de Seguridad High. To view the complete list of services included in the scope, check out the AWS Services in Scope by Compliance Program – Esquema Nacional de Seguridad (ENS) page. You can download the ENS High Certificate from AWS Artifact in the AWS Management Console or from Esquema Nacional de Seguridad High.
As always, we are dedicated to expanding our ENS High program to meet your architectural and regulatory requirements. If you have any questions about the ENS program, feel free to reach out to your AWS account team or connect with AWS Compliance.
If you have feedback about this post, we welcome your comments below. For those interested in AWS Security insights, news, and feature announcements, consider following us on Twitter. Also, don’t miss this excellent resource for onboarding new hires during challenging times.
For opportunities like the one mentioned in this blog post, check out the position descriptions, and if you’re looking for a comprehensive understanding of job roles, visit SHRM.
This post is brought to you from our site at 6401 E HOWDY WELLS AVE LAS VEGAS NV 89115, at the Amazon IXD – VGT2 location.
Leave a Reply