How should a security engineer share the HSM that is hosted in the central account with the new dedicated account?

1 Comment

  1. Larry
    Author

    As far as I’m aware, the answer is:
    Use AWS Resource Access Manager (AWS RAM) to share the VPC subnet ID of the HSM that is hosted in the central account with the new dedicated account. Configure the CloudHSM security group to accept inbound traffic from the private IP addresses of client instances in the new dedicated account.

Leave a Reply to Larry Cancel reply

Your email address will not be published. Required fields are marked *

four × two =