A multinational corporation is expanding its operations into a new region with stringent data residency regulations. All customer data originating from this region must be stored and processed exclusively within the region's geographical boundaries. The company uses Amazon S3 for data storage and AWS Lambda for data processing. How can the company ensure strict data residency for its S3 buckets and associated Lambda functions?
- AImplement client-side encryption for all data uploaded to S3 and define Lambda function permissions to restrict regional access.
- BConfigure S3 bucket policies to deny access from outside the specified region and use Lambda VPC configurations.
- CUse Amazon Macie to identify and quarantine any data that is stored outside the specified region.
- DUtilize AWS Organizations Service Control Policies (SCPs) to restrict S3 bucket and Lambda function creation to the specified region.
Show answer & explanationAnswer & explanation
Correct answer: D. Utilize AWS Organizations Service Control Policies (SCPs) to restrict S3 bucket and Lambda function creation to the specified region.
Service Control Policies (SCPs) in AWS Organizations are the most effective way to enforce strict data residency across an entire AWS account or OU. By restricting the creation of S3 buckets and Lambda functions to a specific region, SCPs prevent any accidental or malicious deployment of resources outside the required geographical boundaries, thus enforcing data residency at the control plane level.
Why the other options are wrong
- A. Client-side encryption encrypts data but does not enforce where the data is physically stored. Lambda permissions restrict who can invoke, not where the function runs.
- B. Bucket policies deny access but don't prevent bucket creation in other regions. Lambda VPC configurations are for network access, not region restriction.
- C. Amazon Macie is a data discovery and classification service; it can identify data locations but does not prevent data from being stored in unauthorized regions.
AWS SCP for Data Residency
Service Control Policies (SCPs) in AWS Organizations enforce maximum permissions for AWS accounts, allowing organizations to restrict resource creation to specific AWS regions to ensure data residency.
- Part of AWS Organizations
- Enforces guardrails at the account/OU level
- Can deny actions like 's3:CreateBucket' or 'lambda:CreateFunction' in unauthorized regions
- Effective for enforcing data residency and sovereignty
Memory trick: SCPs Keep Regions Securely Controlled.