> ## Documentation Index
> Fetch the complete documentation index at: https://cloud-architect.ipoint-labs.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Introduction to Amazon Artifact

> Hands-on lab · 45m

Launch this lab in the IP Lab Portal, then follow the steps below in the AWS console.

<a className="ip-lab-portal-btn" href="https://labs.intellectualpoint.com/labs/introduction-to-amazon-artifact" target="_blank" rel="noreferrer">
  Open IP Lab Portal
</a>

## Overview

#### Lab details

1. This lab provides a step-by-step walkthrough on accessing and downloading security and compliance reports within AWS Artifact.
2. Duration: **1 hour**
3. AWS Region: **US East (N. Virginia) us-east-1**.

#### Introduction

#### What is AWS Artifact agreements?

* AWS Artifact Agreements constitute a cornerstone of the contractual relationship between AWS (Amazon Web Services) and its customers. These agreements encompass a variety of legal documents and terms that define the rights, responsibilities, and obligations of both parties concerning the use of AWS services.
* As organizations increasingly rely on cloud computing services to drive innovation, enhance operational efficiency, and scale their infrastructure, understanding and complying with AWS Artifact Agreements is paramount. These agreements provide the legal framework that governs the usage of AWS services and establishes the terms under which customers can leverage AWS's cloud offerings securely and effectively.

#### What is AWS Artifact Report?

* AWS Artifact Reports serve as essential documents that provide valuable insights into the security and compliance status of your AWS (Amazon Web Services) environment. These reports are accessible through the AWS Artifact platform, offering users a centralized hub for managing and obtaining critical documentation related to security, privacy, and regulatory compliance
* As organizations increasingly migrate their operations to the cloud, ensuring the security and compliance of cloud-based infrastructure becomes paramount. AWS Artifact Reports play a vital role in this context by providing comprehensive documentation that demonstrates adherence to industry standards, regulatory requirements, and best practices for information security.

#### Prerequisite

1. Make sure to have Laptop or Desktop Computer
2. Web Browser
3. PDF Viewer:
4. Adobe Acrobat Reader or Built-in PDF Viewer

#### Architecture diagram

<img src="https://mintcdn.com/ip-cloud-architect-pathway/S7TRbFaK099mvCQ6/images/labs/introduction-to-amazon-artifact/001.png?fit=max&auto=format&n=S7TRbFaK099mvCQ6&q=85&s=ceb000fff8944328f2732a010cb64405" alt="" width="851" height="1000" data-path="images/labs/introduction-to-amazon-artifact/001.png" />

#### Task details

1. Sign in to AWS Management Console
2. Downloading Artifact report and agreements.
3. Reading the terms and conditions on the agreement
4. Deleting AWS resource

#### Launching the lab environment

1. To Launch The Project Environment, Click On The **Launch lab** Button.
2. Please Wait Until The Cloud Environment Is Provisioned. It Will Take Less Than A Minute To Provision.
3. Once The Project Is Started, You Will Be Provided With **IAM User Name, Password, Access Key,** And **Secret Access Key**.

<Note>
  You can only start one Project at any given time
</Note>

## Lab guide

#### Lab steps

#### Task 1: Sign in to AWS Management Console

1. Click On The **Open console** Button, And You Will Get Redirected To AWS Console In A New Browser Tab.
2. On The AWS Sign-In Page,

   * Leave The Account ID As Default. Never Edit/Remove The 12 Digit Account ID Present In The AWS Console. Otherwise, You Cannot Proceed With The Lab.
   * Now Copy Your **User Name** And **Password** In The Lab Console To The **IAM Username And Password** In AWS Console And Click On The **Sign In** Button.
3. Once Signed In To The AWS Management Console, Make The Default AWS Region As **US East (N. Virginia) Us-East-1**.

#### Task 2: Creating AWS Artifact report

1. In the "Find Services" search bar, type "**AWS Artifact**" and select it from the dropdown.

2. You'll be redirected to the **AWS Artifact** dashboard.

3. On the Artifact dashboard see in the left-hand menu and click on "**Reports**" to view the AWS artifact reports

<img src="https://mintcdn.com/ip-cloud-architect-pathway/S7TRbFaK099mvCQ6/images/labs/introduction-to-amazon-artifact/002.png?fit=max&auto=format&n=S7TRbFaK099mvCQ6&q=85&s=ef35ec6bf2ae1deb3607c7d672a874f5" alt="" width="348" height="238" data-path="images/labs/introduction-to-amazon-artifact/002.png" />

#### Task 3: Download and Review the PCI DSS Attestation of Compliance (AOC)

1. In the AWS Artifact console, navigate to the "**Reports**" section.

2. Locate the "**PCI DSS Attestation of Compliance (AOC)**" report in the list.

3. Select the desired version of the report and click "**Download Report**" to download the document.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/S7TRbFaK099mvCQ6/images/labs/introduction-to-amazon-artifact/003.png?fit=max&auto=format&n=S7TRbFaK099mvCQ6&q=85&s=699e4ace106a1b0ed76cdcc2342d6a3c" alt="" width="1403" height="435" data-path="images/labs/introduction-to-amazon-artifact/003.png" />

4. Open the downloaded report and review its contents. Pay attention to the sections that describe AWS' compliance with the PCI DSS standard and the scope of the assessment.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/S7TRbFaK099mvCQ6/images/labs/introduction-to-amazon-artifact/004.png?fit=max&auto=format&n=S7TRbFaK099mvCQ6&q=85&s=44ac58b4667c86852f456865ad025d97" alt="" width="1501" height="96" data-path="images/labs/introduction-to-amazon-artifact/004.png" />

FYI: **PCI DSS Attestation of Compliance (AOC):** This report attests to AWS's compliance with the Payment Card Industry Data Security Standard (PCI DSS), which is a set of security standards designed to ensure that companies that process, store, or transmit credit card information maintain a secure environment.

#### Task 4: Download and review the ISO 27001 certificates

1. Search "ISO 27001:2022 Certification" in the list

2. Select the desired version of the certificate and click "**Download report"** to download the document.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/S7TRbFaK099mvCQ6/images/labs/introduction-to-amazon-artifact/005.png?fit=max&auto=format&n=S7TRbFaK099mvCQ6&q=85&s=2b884883133c67358ea4e4137fc5f981" alt="" width="1409" height="348" data-path="images/labs/introduction-to-amazon-artifact/005.png" />

3. Open the downloaded certificate and review its contents. Verify the scope and validity of the certificate, as well as the certification body that issued it.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/S7TRbFaK099mvCQ6/images/labs/introduction-to-amazon-artifact/006.png?fit=max&auto=format&n=S7TRbFaK099mvCQ6&q=85&s=271949495dd938f882a1d2b465c82c18" alt="" width="1504" height="92" data-path="images/labs/introduction-to-amazon-artifact/006.png" />

FYI: **ISO 27001 Certificates:** ISO 27001 certificates are tangible evidence of an organization's commitment to robust information security practices. Accredited certification bodies issue these certificates following thorough audits, confirming compliance with international standards. The scope defines the ISMS boundaries, and the certification period indicates validity, requiring regular audits for renewal. ISO 27001 certification enhances credibility, builds trust, improves security, and aids regulatory compliance, making it vital for modern cybersecurity.

#### Task 5: Download and review the SOC Continued Operations Letter

1. Search "**SOC Continued Operations Letter**" in the list of reports.

2. Click the radio button and click on download report

3. It will pop up a page and read all the terms and conditions and then click the checkbox and **Accept terms to download report**.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/S7TRbFaK099mvCQ6/images/labs/introduction-to-amazon-artifact/007.png?fit=max&auto=format&n=S7TRbFaK099mvCQ6&q=85&s=12a74ca4d96fa2683342643e749c4531" alt="" width="1024" height="802" data-path="images/labs/introduction-to-amazon-artifact/007.png" />

<img src="https://mintcdn.com/ip-cloud-architect-pathway/S7TRbFaK099mvCQ6/images/labs/introduction-to-amazon-artifact/008.png?fit=max&auto=format&n=S7TRbFaK099mvCQ6&q=85&s=00f3d0bd8e3f00c3a755b1729f05c2be" alt="" width="1501" height="90" data-path="images/labs/introduction-to-amazon-artifact/008.png" />

4. Open the downloaded letter document (typically in PDF format).

Review the contents of the letter, paying attention to the following sections:

* Introduction and purpose of the letter
* Time period covered by the letter
* Auditor's assessment of AWS's continued operations and control environment
* Any changes or updates to AWS's control environment or services covered

**FYI:** The SOC Continued Operations Letter provides crucial assurance that AWS has maintained an effective control environment since the last SOC 1 Type 2 audit. Key points: review the auditor's assessment of AWS's continued operations for the specified time period after the prior audit, note any changes to the covered services and regions, and understand its importance for ongoing compliance with regulations like SOX. Configure notifications in AWS Artifact for the latest versions, as this letter bridges the gap between SOC 1 audits.

#### Task 6: Download and review the AWS Business Associate Addendum

1. Navigate to the "**Agreements**" section on the left side of the AWS Artifact console.

2. Search BAA "**Business Associate Addendum (BAA)**" in the list of agreements.

3. Click on the BAA name to see more details.

4. Click "Download" to save the BAA document.

5. Before that review the terms and conditions

* Artifact Confidential Information
* Exclusions
* Use of Artifact Confidential Information
* Company Personnel
* Disclosures to Governmental Entities
* Ownership of Artifact Confidential Information
* Notice of Unauthorized Use
* Return of Artifact Confidential Information
* Injunctive Relief
* Term; Termination
* Scope
* Miscellaneous
* Service Auditors

<img src="https://mintcdn.com/ip-cloud-architect-pathway/S7TRbFaK099mvCQ6/images/labs/introduction-to-amazon-artifact/009.gif?s=03714c4aa864e9f39ab372f9056345ce" alt="" width="1000" height="394" data-path="images/labs/introduction-to-amazon-artifact/009.gif" />

6. And the click on the checkbox : I have read and agree to the all the terms of the NDA And then click on Accept NDA and download.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/S7TRbFaK099mvCQ6/images/labs/introduction-to-amazon-artifact/010.png?fit=max&auto=format&n=S7TRbFaK099mvCQ6&q=85&s=c8c6dd2730ac853ba967e02ee5969b93" alt="" width="1025" height="159" data-path="images/labs/introduction-to-amazon-artifact/010.png" />

<img src="https://mintcdn.com/ip-cloud-architect-pathway/S7TRbFaK099mvCQ6/images/labs/introduction-to-amazon-artifact/011.png?fit=max&auto=format&n=S7TRbFaK099mvCQ6&q=85&s=6bd08b59b5957bfbb4769f30725f75a8" alt="" width="1496" height="90" data-path="images/labs/introduction-to-amazon-artifact/011.png" />

Open the downloaded BAA (usually a PDF).

7. And the click on Accept agreement.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/S7TRbFaK099mvCQ6/images/labs/introduction-to-amazon-artifact/012.png?fit=max&auto=format&n=S7TRbFaK099mvCQ6&q=85&s=4e359d8b71fd90541e7b1aff26217ff5" alt="" width="1404" height="622" data-path="images/labs/introduction-to-amazon-artifact/012.png" />

8. Check the checkbox and click on accept agreement.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/S7TRbFaK099mvCQ6/images/labs/introduction-to-amazon-artifact/013.png?fit=max&auto=format&n=S7TRbFaK099mvCQ6&q=85&s=059fa3a4e798743e536694629515fc78" alt="" width="751" height="561" data-path="images/labs/introduction-to-amazon-artifact/013.png" />

9. And then status will be changed to active status.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/S7TRbFaK099mvCQ6/images/labs/introduction-to-amazon-artifact/014.png?fit=max&auto=format&n=S7TRbFaK099mvCQ6&q=85&s=aee362c376531a35324832d6d95c6d38" alt="" width="1400" height="616" data-path="images/labs/introduction-to-amazon-artifact/014.png" />

**Optional:** Consult if Needed: If unsure, consult legal or compliance teams. In healthcare, protecting patient data is crucial. That's where the Business Associate Addendum (BAA) in Amazon Web Services (AWS) comes in. It's a contract that ensures AWS follows strict rules when handling sensitive health information stored in their cloud. By signing a BAA with AWS, healthcare providers can trust that their patients' data remains secure. Let's dive into what this means and why it's essential.

#### Task 7: Validation Test

1. Once the lab steps are completed, please click on the **Check my work** button on the Right side panel.

2. This will validate the resources in the AWS account and displays whether you have completed this lab successfully or not.

3. Sample output :

<img src="https://mintcdn.com/ip-cloud-architect-pathway/S7TRbFaK099mvCQ6/images/labs/introduction-to-amazon-artifact/015.gif?s=5ac980c9fcdc0552d0e2d536a7b1953f" alt="" width="1000" height="500" data-path="images/labs/introduction-to-amazon-artifact/015.gif" />

<Tip>
  **Do you know?**

  AWS Artifact is a crucial yet lesser-known service, offering a repository of legal documents including compliance reports and certifications essential for regulatory adherence. It provides varied compliance reports tailored to specific industries and regions, alongside insights into AWS's own security practices. Users can sign NDAs electronically, access third-party auditor reports, and manage granular document permissions. Integration with AWS Organizations streamlines compliance management across accounts, and the repository is continuously updated to reflect evolving standards and regulations globally.
</Tip>

#### Completion and conclusion

1. You Have Successfully logged into AWS console.
2. You Have Successfully downloaded artifacts reports.
3. You Have Successfully downloaded artifacts agreement.
4. You Have Successfully read the terms and condition for both report and agreements.

#### End lab

1. Sign Out Of AWS Account.
2. You Have Successfully Completed The Lab.
3. Once You Have Completed The Steps, Click On **End lab** in the IP Lab Portal And Wait Till The Process Gets Completed.

## What gets checked

When you press **Check my work**, the platform verifies each of these:

* **Login to AWS Management Console** — Check whether the user has logged in to the AWS Management Console.

## Related help

* [FAQs and Troubleshooting](/aws-cp/support/faqs-and-troubleshooting)
