AWS Certified Security – SpecialtyDomain 5: Data ProtectionHard

A global enterprise collects and processes customer data from various regions worldwide. Due to stringent data sovereignty regulations in Europe, all personal data originating from EU citizens must be stored and processed exclusively within the EU. The enterprise uses Amazon S3 for data storage and AWS Lambda for processing. How can the enterprise enforce this data sovereignty requirement effectively?

  1. AConfigure Amazon CloudFront to geo-restrict access to S3 buckets based on the user's origin country.
  2. BImplement an S3 bucket policy that denies PutObject operations if the 'aws:RequestedRegion' condition key does not match an EU region.
  3. CUse AWS Organizations Service Control Policies (SCPs) to restrict S3 bucket and Lambda function creation to EU regions for specific OUs.
  4. DEncrypt all EU-originating data with KMS keys provisioned in a non-EU region and replicate it to an EU S3 bucket.
Show answer & explanation

Correct answer: C. Use AWS Organizations Service Control Policies (SCPs) to restrict S3 bucket and Lambda function creation to EU regions for specific OUs.

SCPs within AWS Organizations can enforce region restrictions at the account level, preventing the creation of S3 buckets and Lambda functions outside designated EU regions, thereby enforcing data sovereignty across all accounts in specific OUs.

Why the other options are wrong

  • A. CloudFront geo-restriction controls *access* to content based on user location, not where the data is *stored or processed*, and it doesn't prevent resources from being created elsewhere.
  • B. An S3 bucket policy can restrict object uploads, but it doesn't prevent the creation of the bucket itself or other resources (like Lambda) in non-EU regions, which is necessary for full data sovereignty.
  • D. Encrypting data with keys from a non-EU region and then replicating it to an EU S3 bucket violates the principle of data sovereignty, as the key material (and potentially the encryption operation) would originate outside the EU.

AWS Data Sovereignty Enforcement with SCPs

AWS Organizations Service Control Policies (SCPs) are used to centrally manage permissions across multiple AWS accounts, enabling preventative controls to enforce data sovereignty by restricting resource provisioning to specific geographic regions.

  • SCPs apply to all accounts in an Organizational Unit (OU) or the entire organization.
  • They can deny actions like resource creation (e.g., S3 buckets, EC2 instances, Lambda functions) in specified AWS Regions.
  • SCPs are preventative controls, ensuring compliance from the outset by preventing non-compliant actions.

Memory trick: SCPs Secure Sovereignty, Preventing Prohibited Provisioning.

More Domain 5: Data Protection questions