Module 4
Compliance as Engineering Evidence
Compliance means proving that your system follows required rules, policies, and controls.
Common student misunderstanding
Compliance is not only documentation. Compliance depends on engineering practices that produce evidence.
Compliance question → Engineering evidence → AWS concept
| Compliance question | Engineering evidence | AWS concept |
|---|---|---|
| Who accessed what? | CloudTrail | Audit trail |
| Are permissions restricted? | IAM policy | Access control |
| Are secrets protected? | Secrets Manager | Secret protection |
| Can failures be investigated? | CloudWatch Logs | Observability |
| Are configurations monitored? | AWS Config | Compliance checks |
| Are deployments traceable? | CI/CD logs | Change evidence |
| Is data protected in transit and at rest? | TLS + KMS encryption | Data protection |
Configuration drift
Drift happens when a system slowly moves away from its approved secure state — an S3 bucket becomes public, encryption is disabled, an IAM policy becomes too broad, or log retention is removed.
Key idea
Good engineering reduces compliance pain. Poor engineering creates compliance stress.