Audited for accuracy as of May, 2023.
Security and compliance are shared responsibilities between AWS, FinalForms, and the School District (Customer). This model helps relieve FinalForms’ operational burden as AWS operates, manages and controls the components from the host operating system and virtualization layer down to the physical security of the facilities in which the service operates. In turn, FinalForms has responsibility and management of the operating system (including updates and security patches), other associated application software as well as the configuration of the AWS provided security group firewall. As shown in the chart below, this differentiation of responsibility is commonly referred to as Security “of” the Cloud versus Security “in” the Cloud. FinalForms carefully considers the services provisioned as responsibilities vary depending on the nature of the services, the integration of those services into the IT environment, and applicable laws and regulations. The Shared Responsibility Model is designed to provide FinalForms with flexibility and control over technology and the School District with flexibility and control over authorized user access.
There is no FERPA certification for a service provider such as FinalForms. In order to meet the FERPA requirements applicable to our operating model, FinalForms aligns our FERPA risk management program, detailed below.
For more on this subject, please visit: https://d0.awsstatic.com/whitepapers/compliance/AWS_FERPA_Whitepaper.pdf
