Lesson 183 · AWS Learning Path

AWS 183: AWS Artifact, Audit Manager and compliance

· Published · 8 min read

Labelled process diagram for AWS 183: Framework control to AWS report or collected evidence to Customer control-owner review to Assessment, exception, and auditor decision, with decision, proof and rejection evidence.

Why this lesson matters

Distinguish downloaded AWS compliance reports, continuous audit evidence collection, customer control operation, and the shared responsibility model.

What you will be able to do

By the end, you can:

  • explain aws artifact, audit manager and compliance in plain language;
  • locate the current service controls in the AWS Management Console;
  • run the matching CloudShell or AWS CLI queries and explain every important field;
  • draw the identity, network, data, failure, and monitoring path;
  • choose the service from requirements and reject it when those requirements are absent;
  • diagnose a failed or misleading result from evidence;
  • state the cost owner and prove cleanup or a no-create result.

Before you start

  • Use a personal AWS account only when its owner has approved the lesson. Do not use the root user for daily work.
  • CloudShell is the default command environment. AWS028 explains CloudShell; AWS029 and AWS030 explain local AWS CLI installation and profiles.
  • The course example Region is ap-south-1. Global services and services with a required control Region are called out in their commands.
  • Run aws sts get-caller-identity privately. Redact the account number before sharing evidence.
  • Never paste access keys, passwords, secret values, private object data, presigned URLs, or full account-specific ARNs into a submission.
  • This is a no-create lesson. Every Console action and AWS CLI command is read-only. Create the practical artifact locally.
  • Console wording can change. Use the Console service search if a menu label has moved, then confirm the current field in the official documentation.

The core model

QuestionWhat it means in this lesson
PurposeDistinguish downloaded AWS compliance reports, continuous audit evidence collection, customer control operation, and the shared responsibility model.
Scope and boundaryThe learner must identify the account and Region scope, resource boundary, identity path, data or network path, failure behavior, observability, and cleanup ownership for AWS Artifact, Audit Manager, and compliance.
Evidence of successSuccess means the Console fields, CLI result, workload behavior, monitoring evidence, and architecture claim agree. An available state alone is not enough for AWS Artifact, Audit Manager, and compliance.
Cost modelRequests, running capacity, storage, logs, data transfer, retained state, and optional features must be priced for the exact design.
Safe rejection ruleAvoid publishing confidential reports, claiming AWS compliance makes the workload compliant, or treating automated evidence as complete.

How the request flows

+----------------------+
|  Framework control   |
+----------------------+
           |
           v
+------------------------------------+
|  AWS report or collected evidence  |
+------------------------------------+
                  |
                  v
+---------------------------------+
|  Customer control-owner review  |
+---------------------------------+
                |
                v
+-----------------------------------------------+
|  Assessment, exception, and auditor decision  |
+-----------------------------------------------+

Separate provider assurance from customer evidence

AWS Artifact is a portal for AWS compliance reports and selected agreements. A SOC report can support assurance about AWS-operated controls for the stated service, scope and period; it does not certify the customer's workload. Read report date, auditor opinion, covered services/Regions, complementary user-entity controls and exceptions. Restrict downloads because reports can be confidential, record who accepted agreements, and review renewal/termination requirements.

Audit Manager helps collect and organize evidence for customer assessments. It does not decide legal compliance, design controls, remediate failures or replace an auditor. Compliance remains a business/legal determination under the shared responsibility model.

Audit Manager evidence chain

ObjectPurposeRequired question
FrameworkGroups control sets and controls; standard or customDoes it map to the exact regulation/version and customer applicability?
AssessmentDefines framework, accounts, services, owners and evidence destinationAre scope, Regions, period and owners complete?
Automated evidenceConfiguration/API/activity records from supported AWS sourcesIs the source authoritative, current and collecting in every scope?
Manual evidenceCustomer-uploaded policy, ticket, test or external recordWho approved it, what period does it cover, and is integrity protected?
Assessment reportCurated package of selected evidenceSelection is intentional; newly collected evidence is not included automatically.

Config or Security Hub CSPM evidence may report compliant/noncompliant/inconclusive. CloudTrail/API/manual evidence is commonly inconclusive because collection alone cannot judge control effectiveness. An assessment report packages evidence but explicitly does not assess compliance.

Evidence Finder uses a CloudTrail Lake event data store and can search organization evidence when used by a delegated administrator. Enabling it creates storage/query cost and governance obligations and can backfill historical Audit Manager evidence. Define retention, KMS/S3 access, query roles and deletion ownership before activation.

Build an auditable control record

For each control, record control objective, threat/requirement, owner/operator/reviewer, preventive or detective mechanism, account/Region/resource scope, frequency, evidence source, expected result, exception process, remediation SLA and retention. Map one technical check to all applicable frameworks instead of duplicating operations, while preserving framework-specific interpretation.

Evidence must be sufficient, relevant, reliable, time-bound and tamper-resistant. Screenshots without identity, timestamp, scope or source query are weak. Prefer exported API/configuration records, immutable logs, pipeline attestations, tickets with approvals and restore/test results. Redact secrets and personal data without removing fields necessary to prove the claim.

Delegated administration centralizes collection, but member-account enrollment, enabled Regions, role permissions and source coverage still require verification. Store reports in a restricted evidence account/bucket rather than an application account, and test auditor read-only access before the audit window.

Architecture decision table

SituationDirectionReason
Requirement matchesUse Artifact for AWS assurance documents and Audit Manager to organize supported evidence against chosen frameworks.Select only after scope, behavior, security, recovery, operations, and price evidence agree.
Requirement does not matchAvoid publishing confidential reports, claiming AWS compliance makes the workload compliant, or treating automated evidence as complete.Rejecting an attractive service is a valid architecture result.
No create permission or cost approvalUse supplied evidence and local design workLearning does not depend on creating an hourly resource.
Existing resource is unknown or unownedInspect only, then stopNever change or delete a resource merely because it resembles a course example.

AWS Management Console, step by step

Sign in with the normal non-root learning identity. Write the expected starting state before opening the service.

  1. Use the Console service search and open AWS Artifact Agreements and Reports, then Audit Manager Assessments and Framework library; confirm the account and Region before reading the page.
  2. Inspect the supplied or owned resource's status, configuration, permissions, networking, encryption, monitoring, tags, and dependencies without changing it.
  3. Open the related metrics, logs, events, or history view and record one timestamped signal that would prove or disprove the expected behavior.
  4. Return to the resource list, clear filters, and record the final inventory. On the read-only track, do not choose Create, Save, or Delete.

CloudShell and AWS CLI, step by step

Start with a known caller and Region:

export AWS_DEFAULT_REGION="ap-south-1"
aws sts get-caller-identity --query Arn --output text
aws configure list

Redact the account part of the ARN in shared evidence. Now run the topic queries:

aws auditmanager get-account-status --output json
aws auditmanager list-assessments --query 'assessmentMetadata[].{Name:name,Status:status,Framework:framework.name}' --output table
aws auditmanager list-assessment-frameworks --framework-type Standard --max-results 20 --output table

Expected interpretation

AWS Artifact is primarily a Console workflow for reports and agreements. Audit Manager evidence assists assessment; it does not certify the customer or replace auditor judgment.

Practical work

Build an evidence map for encryption, access review, logging, backup test, incident handling, and supplier assurance. Assign AWS evidence, customer evidence, control owner, frequency, retention, and exception process.

Diagnose this topic from its own evidence

  • Missing evidence: inspect assessment scope, service/Region, source mapping, delegated membership and collection permissions.
  • INCONCLUSIVE: determine whether the evidence type can evaluate compliance; add reviewer procedure rather than relabeling it.
  • Report omits recent evidence: selected evidence is not automatically refreshed; review and add the intended folders/items before regeneration.
  • Framework looks complete but workload is not: compare legal applicability and customer controls against framework mappings and Artifact report scope.
  • Evidence Finder cost or access surprise: inspect its CloudTrail Lake event data store, retention, query activity and delegated permissions.

Cost and cleanup

Requests, running capacity, storage, logs, data transfer, retained state, and optional features must be priced for the exact design.

Knowledge check

  1. What operational purpose is this lesson solving?

Expected direction: Distinguish downloaded AWS compliance reports, continuous audit evidence collection, customer control operation, and the shared responsibility model.

  1. Which scope or ownership boundary must be proved first?

Expected direction: The learner must identify the account and Region scope, resource boundary, identity path, data or network path, failure behavior, observability, and cleanup ownership for AWS Artifact, Audit Manager, and compliance.

  1. What evidence is strong enough to accept the result?

Expected direction: Success means the Console fields, CLI result, workload behavior, monitoring evidence, and architecture claim agree. An available state alone is not enough for AWS Artifact, Audit Manager, and compliance.

  1. Which tempting design or shortcut must be rejected?

Expected direction: Avoid publishing confidential reports, claiming AWS compliance makes the workload compliant, or treating automated evidence as complete.

  1. Which cost dimensions and retained resources need an owner?

Expected direction: Requests, running capacity, storage, logs, data transfer, retained state, and optional features must be priced for the exact design.

Lesson acceptance

  • Explain what Artifact reports/agreements prove and what they cannot prove.
  • Build framework → assessment → control → evidence → reviewer → report traceability.
  • Distinguish automated, manual, compliant/noncompliant and inconclusive evidence.
  • Validate scope across accounts, Regions, resources and audit period.
  • Design confidential report storage, evidence retention, delegated access and Evidence Finder cost ownership.

Official sources

Advertisement