A county must show auditors HIPAA- and CJIS-aligned control evidence for workloads on AWS, including access to official compliance reports, while the architecture itself uses encryption and tight access controls. Which combination best aligns technologies to that compliance-evidence need?
Select an answer to reveal the explanation.
Short Explanation
Artifact is the county’s filing cabinet of AWS compliance paperwork; KMS and least privilege are how you actually build locks the paperwork describes. Renaming security groups “HIPAA-ready” without controls is theater.
Full Explanation
AWS Artifact provides on-demand access to AWS compliance reports and agreements that auditors often request. Architecture still must implement encryption (KMS) and access controls appropriate to HIPAA/CJIS-aligned designs. Artifact alone without technical controls—or public exposure of sensitive data—does not satisfy compliance alignment.