AWS Public Sector Blog

Category: AWS Security Hub

Building machine-readable FedRAMP 20x evidence on AWS

In this post, we walk through the evidence pipeline, from Amazon Web Services (AWS) Config evaluations and AWS Security Hub findings through transformation and storage, to producing the dual-format output that satisfies FedRAMP 20x Phase 2 completeness requirements.

Architecting HIPAA-compliant AI agents to safeguard health data with AWS

Architecting HIPAA-compliant AI agents to safeguard health data with AWS

In this post, we share a reference AWS architecture that healthcare organizations, health plans, and state agencies can use to deploy AI agents while maintaining HIPAA compliance.

Run SAP workloads at DoD Impact Level 5 with SAP NS2 on AWS GovCloud (US)

Run SAP workloads at DoD Impact Level 5 with SAP NS2 on AWS GovCloud (US)

In this post, we explain what IL5 requires, how AWS GovCloud (US) and SAP NS2 meet those requirements together, and how defense organizations can get started.

Accelerate IRAP readiness with AWS and Wiz

Accelerate IRAP readiness with AWS and Wiz

As organisations modernise to meet the evolving expectations of the Australian Government, delivering secure, cloud-based services has become a commercial and operational necessity. This transformation brings a critical challenge: maintaining a hardened security posture while aligning to the Information Security Registered Assessors Program (IRAP) assessment requirements and priorities.

MARS-E to ARC-AMPE: Guide for state Medicaid agencies on AWS

MARS-E to ARC-AMPE: Guide for state Medicaid agencies on AWS

This post is for two audiences. The first is agencies already running MARS-E-compliant workloads on AWS that are looking to map their existing posture onto the new framework. The second is agencies planning a migration from on-premises infrastructure where ARC-AMPE will be in scope from the first day.

https://app.asana.com/1/8442528107068/project/1207199896111772/task/1214439772201800?focus=true

Preventive controls for FedRAMP 20x: Using SCPs and guardrails to enforce KSIs

Why preventive controls matter for FedRAMP 20x Organizations strengthen their security posture when Amazon Web Services (AWS) cloud resources consistently align with security and regulatory requirements. Preventive security controls, which are designed to minimize or avoid threat events, help enforce these requirements before misconfigurations are deployed. In this post, we show how service control policies […]

Transforming federal IT with Datadog's FedRAMP Class D (High) solution

Transforming federal IT with Datadog’s FedRAMP Class D (High) solution

In this post, we explore how federal agencies can accelerate modernization, improve cybersecurity incident response, and support continuous compliance monitoring using Datadog’s FedRAMP High authorized observability and security platform.

CMMC Level 2 compliance on AWS: Why control ownership is where organizations struggle

CMMC Level 2 compliance on AWS: Why control ownership is where organizations struggle

This post brings guidance on Customer Responsibility Matrices (CRMs), authorization boundary definitions, and multi-provider control ownership into a single actionable framework for defense contractors preparing for third-party assessment.

Deep dive into FedRAMP 20x Key Security Indicators: Decoding the 63 KSIs

Deep dive into FedRAMP 20x Key Security Indicators: Decoding the 63 KSIs

In this post, we break down every KSI theme, categorize each indicator by validation approach, and provide a practical gap analysis framework so you can begin preparing your cloud service offering (CSO) for FedRAMP 20x authorization on Amazon Web Services (AWS).