To satisfy these strict boundaries while still being able to gain meaningful data insights for the customer, the solution is heavily built around AWS’ infrastructure, services and automation tools.
The requirements have been translated into security measures based on extensive audit logging (CloudWatch, CloudTrail and application logs are sent to a logging service based on OpenSearch and Kibana), account and zone separation, strict security groups and an fully automated CI/CD pipeline.
Working with the most sensitive data has been restricted to specially configured remote clients. Thanks to the move to a cloud environment data engineers are able to do meaningful work in those secured environments from anywhere around the world.
Without the consequent enforcement of the technical and organizational guidelines, enabled by AWS’ services, they have never been realized due to security and privacy concerns.