AWS Resource Access Manager (AWS RAM) can now be used for workloads subject to Service Organization Control (SOC) compliance and International Organization for Standardization (ISO) ISO 9001, ISO 27001, ISO 27017, ISO 27018 and ISO 27701 standards. Now, customers in finance, healthcare, and other regulated sectors can get insights into the security processes and controls that protect customer data which can be found in the SOC reports, AWS ISO and CSA STAR certificates in AWS Artifact. AWS’ alignment with these standards in addition to the independent third-party assessment of these internationally recognized code of practices demonstrates AWS’ commitment to the privacy and protection of customers’ content.
AWS AppSync simplifies GraphQL API development with expanded GraphQL Utility Helper Library
AWS AppSync is a fully managed service that makes it easy to create and manage GraphQL and Real-time APIs, allowing developers to securely access, manipulate, and combine data from one or more data sources via a single API endpoint. With GraphQL, special functions called Resolvers are used to implement business logic linking or “resolving” types, fields, or operations defined in the GraphQL schema with the data in data sources such as Amazon DynamoDB, AWS Lambda, HTTP APIs, and more.
AWS IAM now supports WebAuthn and Safari browser for multi-factor authentication with security keys
AWS Identity and Access Management (IAM) now supports the Web Authentication (WebAuthn) standard for strong and phishing-resistant authentication across all supported browsers. WebAuthn is part of the FIDO2 set of specifications that succeed FIDO U2F API, enabling secure multi-factor authentication with security keys based on public key cryptography.
AWS Marketplace introduces free trials for SaaS contracts
AWS Marketplace introduces free trials for SaaS contracts so you can try products before you buy them. Previously, customers would either need to commit to a contract before trying the product, or go to third-party websites for free trials offered by software vendors directly.
AWS DataSync adds support for Amazon EFS security features
AWS DataSync now provides additional security options when moving data to and from Amazon Elastic File System (Amazon EFS). AWS DataSync is an online data movement service that simplifies, automates, and accelerates moving data between on-premises, edge, or cloud storage and AWS Storage services. Amazon EFS is a serverless, fully elastic file system that makes it easy to set up, scale, and cost-optimize file storage in the AWS Cloud. With this launch, DataSync can now access your file systems using EFS Access Points , enabling you to copy data to and from specific datasets. You can also configure DataSync to connect to your EFS file systems using TLS encryption, giving you greater protection of your data in-flight when copying to and from EFS. Additionally, you can configure DataSync with an IAM role for use with your EFS file system policies , giving you greater control over how DataSync accesses your file systems.
AWS WAF and AWS Shield Advanced are now available in the Asia Pacific (Jakarta) Region
AWS WAF and AWS Shield Advanced are now available in the Asia Pacific (Jakarta) Region.
Access the AWS re:Post community from the AWS Well-Architected Tool
AWS Well-Architected Tool now features direct access to AWS re:Post, a community-driven, questions-and-answers service designed to help AWS customers remove technical roadblocks, accelerate innovation, and enhance operation. AWS re:Post has 40+ topics including a community specific to AWS Well-Architected.
Amazon Cognito improves risk evaluation for Advanced Security Features
Amazon Cognito now enables application developers to propagate IP address as part of the caller context data in unauthenticated calls to Amazon Cognito. When Amazon Cognito’s Advanced Security Features (ASF) are enabled, this feature improves risk calculation and resulting authentication decisions performed in flows such as sign-up, account confirmation, and password change. Prior to this change, the end user IP address was not available in unauthenticated calls if these calls were initiated behind a proxy. With this new feature, developers who build identity micro-services, authentication modules or identity proxies can now leverage APIs to gain visibility into the client’s IP address and utilize them in other security applications to better understand the risk of a particular user activity.
Announcing Athena connector for Amazon Lookout for Metrics
AWS Lookout for Metrics announces the launch of the Athena connector , a new connector in Lookout for Metrics that allows you to query data from various data sources such as Data Lake on AWS, Amazon S3, Amazon Redshift to ingest into Amazon Lookout for Metrics for anomaly detection. The Athena connector reduces the need to setup complex ETL jobs and data preparation time for anomaly detection. You can query large datasets using standard SQL and analyze it before ingesting in an anomaly detector . The Athena connector supports data formatted in CSV, JSON, ORC (Optimized Row Columnar), Parquet, XML, plain text and AVRO.
Amazon Timestream achieves FedRAMP Moderate compliance
Amazon Timestream is now in scope for FedRAMP Moderate in the following AWS Regions: US East (Ohio), US East (N. Virginia), US West (Oregon). You can now use Amazon Timestream to collect, store, query, and visualize time series data in various applications within your Amazon Virtual Private Clouds (Amazon VPC) to help you meet FedRAMP Moderate controls.