Regulatory compliance
IBM® watsonx Orchestrate® is designed with enterprise-grade security and compliance in mind. It aligns with a broad range of industry standards and regulatory frameworks to help organizations meet their governance, risk, and compliance (GRC) obligations.
While IBM watsonx Orchestrate provides the tools and infrastructure to support compliance, customers remain responsible for:
Identifying the laws and regulations applicable to their specific use cases and jurisdictions.
Interpreting how those regulations apply to their data, users, and AI workflows.
Taking appropriate actions to ensure their users and systems need to take to comply with these laws and regulations.
AWS GovCloud (US): compliance overview
AWS GovCloud (US) is a cloud-based environment built to support U.S. government agencies and other organizations dealing with sensitive and regulated data. It provides a secure and compliant infrastructure for meeting stringent federal requirements.
Compliance controls
AWS GovCloud (US) inherits the robust compliance controls of AWS, helping customers align with critical standards such as:
FedRAMP (Federal Risk and Authorization Management Program)
Data sovereignty and security
To maintain the highest level of security and compliance, AWS GovCloud (US) operates in logically and physically isolated regions. These regions are managed exclusively by U.S. citizens, ensuring data sovereignty and adherence to government regulations.
What to do next
For detailed guidance on security principles, see Security and Privacy by Design (SPbD).