AWS Public Sector Blog

Category: AWS Config

An incident response playbook for satellite operations on AWS (Part-1): Detection and forensic readiness

An incident response playbook for satellite operations on AWS (Part-1): Detection and forensic readiness

In this post, the first in a two-part series, we focus on the detection and forensic readiness side of satellite IR. This post walks through instrumenting your ground segment with Amazon Web Services (AWS) security services and AWS Ground Station so that threats surface before they cause damage, and forensic data is already flowing when an incident occurs.

An incident response playbook for satellite operations on AWS (Part-2): Automated response and recovery

An incident response playbook for satellite operations on AWS (Part-2): Automated response and recovery

This blog covers what to do when those detections fire. Satellite incident response (IR) must account for constraints that ground-based systems never face: containment actions that wait for the next orbital pass, decisions that trade mission continuity against security, and recovery procedures where the compromised endpoint cannot be physically accessed. It walks through containment, eradication, recovery, automated runbooks, and tabletop exercises designed for satellite operations teams.

Deep dive into FedRAMP 20x Key Security Indicators: Decoding the 63 KSIs

Deep dive into FedRAMP 20x Key Security Indicators: Decoding the 63 KSIs

In this post, we break down every KSI theme, categorize each indicator by validation approach, and provide a practical gap analysis framework so you can begin preparing your cloud service offering (CSO) for FedRAMP 20x authorization on Amazon Web Services (AWS).

AWS Branded Background with text "Build a secure AWS foundation in under 60 minutes: A guide for public sector organizations"

Build a secure AWS foundation in under 60 minutes: A guide for public sector organizations

In this blog, we will guide you through the process of setting up a secure multi-account AWS environment using AWS Control Tower, AWS IAM Identity Center, AWS Organizations and will show you how to secure your environment using AWS Config, AWS Security Hub, and Amazon GuardDuty.

AWS Branded Background with text "5 ways AWS empowers GovTech innovation in 2025"

5 ways AWS empowers GovTech innovation in 2025

Amazon Web Services (AWS) has been a trusted collaborator and advisor to GovTechs for years, providing the tools, expertise, and support they need to build and grow their solutions effectively. In this blog post, we discuss five key ways AWS supports GovTechs in their mission to serve government agencies and citizens.

AWS branded background design with text overlay that says "How to safeguard healthcare data privacy using Amazon Bedrock Guardrails"

How to safeguard healthcare data privacy using Amazon Bedrock Guardrails

As more and more healthcare companies use their data to remain competitive, protecting patient data is as critical than ever. With increasing adoption of AI/ML models in healthcare, making sure that these technologies comply with privacy regulations such as HIPAA and GDPR has become a top priority. Amazon Bedrock is a fully managed service that provides unified access to a diverse selection of high-performance foundation models from industry-leading AI companies. In this post, we walk you through the importance of healthcare data privacy and how to use Amazon Bedrock Guardrails to safeguard sensitive information in AI-driven healthcare solutions.

AWS branded background design with text overlay that says "Allies can share data and technologies and remain compliant with international regulations using AWS"

Allies can share data and technologies and remain compliant with international regulations using AWS

National security and defense depend upon close collaboration between international allies. To protect sensitive data and promote robust cybersecurity frameworks, organizations must consider one another’s compliance requirements. One such requirement is the United States International Traffic in Arms Regulations (ITAR), which restricts and controls the export of defense and military-related technologies in order to safeguard US national security. Here, we set out how an innovation called Trusted Secure Enclaves (TSE) on Amazon Web Services (AWS) allows non-US national organizations who want to use the most modern and innovative technology to deliver defense and security missions using the cloud can do this and be compliant.

AWS branded background design with text overlay that says "Securing the future of healthcare in the age of generative AI and connected care"

Securing the future of healthcare in the age of generative AI and connected care

The healthcare industry is undergoing a profound transformation, driven by the adoption of generative artificial intelligence (AI), cloud computing, and connected care devices. This digital revolution promises to improve patient outcomes, reduce costs, and enhance the overall healthcare experience. However, it also introduces new challenges in terms of cybersecurity, privacy, and regulatory compliance. To navigate this complex landscape, healthcare organizations are turning to scalable, affordable, and highly available cloud infrastructures such as Amazon Web Services (AWS) to build resilient, secure, and innovative solutions.

AWS branded background design with text overlay that says "Continuous monitoring and governance: AWS best practices for keeping your data secure during the holidays and beyond"

Continuous monitoring and governance: AWS best practices for keeping your data secure during the holidays and beyond

As we look ahead to 2025, it’s crucial to maintain vigilance, especially during the holiday season, when cybersecurity risks tend to escalate. Many organizations use Amazon Web Services (AWS) to enhance their security posture and improve resilience. In this post, we discuss the AWS best practices for securing your data during the holiday season.