What is AWS Audit Manager?
AWS Audit Manager automates the collection of audit evidence from your AWS environment. The service automatically maps collected data to the controls of a compliance framework and generates audit-ready reports. Instead of manually compiling screenshots and logs, Audit Manager delivers continuously updated evidence.
The service supports common compliance frameworks such as GDPR, SOC 2, PCI DSS, and ISO 27001. Custom frameworks allow mapping of internal policies and industry-specific requirements.
Core Features
- Automatic Evidence Collection: Continuous capture from CloudTrail, Config, Security Hub, and other AWS services
- Pre-Built Frameworks: Ready-to-use assessments for GDPR, SOC 2, PCI DSS, ISO 27001, and more
- Custom Frameworks: Create your own frameworks with individual controls
- Delegation: Assign controls to departments for decentralized evidence collection
- Assessment Reports: Automatic generation of audit-ready reports with all collected evidence
Typical Use Cases
SOC 2 Audit Preparation: Organizations use Audit Manager to continuously collect evidence for SOC 2 Type II audits. Automatic mapping to SOC 2 controls reduces preparation time from weeks to days.
GDPR Compliance: European companies document technical and organizational measures for data protection. Audit Manager automatically provides evidence of encryption, access controls, and logging.
Multi-Framework Compliance: Organizations that need to comply with multiple standards simultaneously use Audit Manager to collect evidence once and map it to multiple frameworks.
Benefits
- Drastic reduction of manual effort for audit preparation
- Continuous instead of point-in-time compliance evidence
- Reuse of evidence across multiple frameworks
- Central overview of compliance status for all controls
Integration with innFactory
As an AWS Reseller, innFactory supports you with AWS Audit Manager: framework selection and customization, assessment configuration, integration with existing GRC processes, and audit preparation.
Typical Use Cases
Frequently Asked Questions
What is AWS Audit Manager?
AWS Audit Manager is a service that continuously collects evidence from your AWS environment to demonstrate compliance with frameworks like GDPR, SOC 2, PCI DSS, and ISO 27001. Evidence collection is fully automated.
Which compliance frameworks are supported?
Audit Manager provides pre-built frameworks for SOC 2, PCI DSS, GDPR, HIPAA, ISO 27001, GxP, and more. Custom frameworks can also be created to match specific requirements.
How is evidence collected?
Audit Manager automatically collects evidence from AWS CloudTrail, AWS Config, Security Hub, and other AWS services. Evidence is mapped to the respective controls of a framework and compiled into an assessment report.