Amazon Updates Guidance on AWS and FERPA

More than two years after issuing guidance on FERPA compliance and Amazon Web Services, Amazon has updated the whitepaper to lay out the company's "shared responsibility model" and give specific guidance on 24 different AWS services.

The Family Educational Rights and Privacy Act, in general, calls for schools and agencies to "reasonably safeguard student education records from improper use or disclosure," the report stated. However, Amazon asserted, that's a shared responsibility between AWS and the customer. While Amazon is responsible for security "of" the cloud, as it noted, the customer is responsible for security "in" the cloud.

In general, Amazon's purview covers operation, management and control of the components "from the host operating system and virtualization layer down to the physical security of the facilities in which the service operates." The customer, on the other hand, must assume responsibility for patching the guest operating system and applications. Those duties will vary depending on the AWS cloud services being used.

The report runs through each of its many services and includes guidance related to protection of personally-identifiable information. For example, districts using Amazon's Simple Storage Service should "configure their S3 buckets for least privilege and ensure buckets and objects are not world accessible, unless by design." The PII recommendation also suggested that S3 logging and server-side encryption be enabled or the data itself encrypted before being stored.

The FERPA-related AWS guidance is available on AWS.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • laptop displaying a glowing digital brain and data charts sits on a metal shelf in a well-lit server room with organized network cables and active servers

    Cisco Unveils AI-First Approach to IT Operations

    At its recent Cisco Live 2025 event, Cisco introduced AgenticOps, a transformative approach to IT operations that integrates advanced AI capabilities to enhance efficiency and collaboration across network, security, and application domains.

  • cloud icon with a padlock overlay set against a digital background featuring binary code and network nodes

    Cloud Security Auditing Tool Uses AI to Validate Providers' Security Assessments

    The Cloud Security Alliance has unveiled a new artificial intelligence-powered system that automates the validation of cloud service providers' (CSPs) security assessments, aiming to improve transparency and trust across the cloud computing landscape.

  • robot brain with various technology and business icons

    Google Cloud Study: Early Agentic AI Adopters See Better ROI

    Google Cloud has released its second annual ROI of AI study, finding that 52% of enterprise organizations now deploy AI agents in production environments. The comprehensive survey of 3,466 senior leaders across 24 countries highlights the emergence of a distinct group of "agentic AI early adopters" who are achieving measurably higher returns on their AI investments.

  • laptop with AI symbol on screen

    Google Launches Lightweight Gemma 3n, Expanding Emphasis on Edge AI

    Google DeepMind has officially launched Gemma 3n, the latest version of its lightweight generative AI model designed specifically for mobile and edge devices — a move that reinforces the company's focus on on-device computing.