Security, Privacy & Data Protection
IAM, network isolation, encryption, PII และการ log ให้ตรวจสอบได้
| โจทย์บอกว่า… | คำตอบ |
|---|---|
ห้ามให้ traffic ผ่าน public internet | Interface VPC endpoint (PrivateLink) สำหรับ Bedrock + endpoint policy |
จำกัดให้ใช้ได้เฉพาะบางโมเดล | IAM policy ระบุ |
หา PII ในข้อมูลใน S3 ก่อนนำไปทำ RAG | Amazon Macie |
ตรวจ/ลบ PII ในข้อความแบบ real-time | Amazon Comprehend (PII detection / redaction), Comprehend Medical สำหรับ PHI |
ซ่อน PII ในคำตอบของโมเดล | Guardrails sensitive information filter |
ควบคุมสิทธิ์ข้อมูลระดับ table/column/row | AWS Lake Formation |
เก็บ prompt/response ไว้ audit | Model invocation logging (ปิดเป็นค่าเริ่มต้น) → CloudWatch Logs / S3 |
ใครเรียก API อะไรเมื่อไหร่ | AWS CloudTrail |
ลบข้อมูลตามนโยบาย retention | S3 Lifecycle configuration |
เข้ารหัส custom model / KB / logs ด้วย key ของเรา | AWS KMS customer managed key |
ทีม compliance ต้องการเก็บ prompt และ response ทั้งหมดของ Bedrock ไว้ตรวจสอบย้อนหลัง ควรเปิดอะไร?
การดึงความรู้ออกมาใช้ทันทีหลังอ่าน (retrieval practice) ช่วยให้จำได้นานขึ้นมาก