Amazon Releases New Guidance on AWS and FERPA

More than two years after issuing guidance on FERPA compliance and Amazon Web Services, Amazon has updated the whitepaper to lay out the company's "shared responsibility model" and provide specific guidance on 24 different AWS services.

The Family Educational Rights and Privacy Act, in general, calls for schools and agencies to "reasonably safeguard student education records from improper use or disclosure," the report stated. However, Amazon asserted, that's a shared responsibility between AWS and the customer. While Amazon is responsible for security "of" the cloud, as it noted, the customer is responsible for security "in" the cloud.

In general, Amazon's purview covers operation, management and control of the components "from the host operating system and virtualization layer down to the physical security of the facilities in which the service operates." The customer, on the other hand, must assume responsibility for patching the guest operating system and applications. Those duties will vary depending on the AWS cloud services being used.

The report runs through each of its many services and includes guidance related to protection of personally-identifiable information. For example, institutions using Amazon's Simple Storage Service should "configure their S3 buckets for least privilege and ensure buckets and objects are not world accessible, unless by design." The PII recommendation also suggested that S3 logging and server-side encryption be enabled or the data itself encrypted before being stored.

The FERPA-related AWS guidance is available on the AWS site.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • A panel discussion from SXSW EDU 2025

    12 Ways to Dive into AI at SXSW EDU

    This March 9-12, the SXSW EDU Conference & Festival returns to Austin, TX, to celebrate innovation, experimentation, and learning across every stage of education.

  • abstract cybersecurity data protection

    Rubrik Intros Google Workspace Data Protection

    Rubrik has announced the launch of Rubrik Data Protection for Google Workspace, a product the company said is designed to help enterprise customers protect data and restore operations across Google Workspace environments.

  • Educational path and career development growth with neon icons for study, idea, graduation, and success

    How to Embrace Lifelong Learning as a Non-negotiable for Career Growth

    In a world shaped by rapid technological change and shifting economic forces, staying curious and committed to learning is the most powerful way to stay prepared.

  • SXSW EDU

    SXSW EDU 2026: Discover How to Incorporate Technology with Impact

    With the proliferation of AI and advanced technology, education leaders have an opportunity to find and implement the right solutions to make a difference for learners. This March 9-12, SXSW EDU 2026 is your chance to discover innovative edtech, connect with trailblazing peers, and find strategies that make an impact.