We are a 7-person healthtech software company operating in the US market. We're at the contract signing stage with an enterprise client for an annual value of $45,000. However, the client's third-party auditing firm has requested that we configure an AWS security audit role in our root/primary cloud account for compliance checks.
Our systems store sensitive patient data and proprietary algorithms. They sent over a doc requesting a specific role template, but we aren't completely sure which exact permissions to open up. We don't want to over-privilege and risk our data and infrastructure, but we're also worried about failing the audit if we lock it down too much.
What is the standard, secure procedure for this kind of external audit? Which built-in permission policies should be used how should the auditor's access duration be limited, and how should their actions be audited/logged?