Auditing generative AI workloads with AWS CloudTrail
AWS Cloud Operations Blog
This article discusses how to audit generative AI workloads on AWS using AWS CloudTrail data events and CloudTrail Lake. It covers common scenarios for auditing services like Amazon Bedrock, Amazon SageMaker, Amazon Q Developer, and Amazon Q Business.
Specifically, the article covers:
- Setting up CloudTrail Lake for storing and querying CloudTrail events
- Using CloudTrail data events to audit Amazon Q Business application activities such as document deletions, sync jobs, and unauthorized S3 access
- Using CloudTrail data events to identify users running code analyses with Amazon Q Developer and their source IP addresses
- Using CloudTrail data events to audit invocation of Amazon Bedrock agents, knowledge bases, and related request/response parameters
- Cleaning up by deleting the event data stores created
- Conclusion and additional resources on CloudTrail data events for generative AI services
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Jun 11
2024
2024
AWS Audit Manager extends generative AI best practices framework to Amazon SageMaker
Jun 11
2024
2024
AWS Audit Manager generative AI best practices framework now includes Amazon SageMaker
Jun 6
2024
2024
Unlocking generative AI opportunities with AWS
Jun 28
2024
2024
Neurons Lab – Transforming Cybersecurity Audits with Generative AI on AWS
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.