this post was submitted on 07 Apr 2024
483 points (95.3% liked)
Security
5005 readers
1 users here now
Confidentiality Integrity Availability
founded 4 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Yeah I hate Amazon as much as the next person, but this is a people/process problem, not an Amazon problem. Amazon doesn't know or care what you put into an AWS bucket (within reason, data tracking, etc, blah blah blah). People taking classified documents and uploading it to an Internet-connected cloud service is procedurally wrong on so many levels.
It could be both. In the absence of more data, I'm reserving my judgement.
No, it literally cannot be both, full stop. There should rigorous, well defined procedures and processes for handling classified data, and chiefly among those should be something along the lines of "don't upload classified documents to a publicly-available internet-connected location/service/filestore/etc". If it's not, a security officer has not done their job.
The north east US is dotted with high (physical) security Amazon data centers . I promise those aren't hosting files you can search Google for, if you know what I mean.