AWS Public Sector Blog

Nikhil Khare

Author: Nikhil Khare

Nikhil Khare is a senior cloud consultant for the Amazon Web Services (AWS) worldwide public sector (WWPS) professional services team, and his focus area is Department of Defense (DoD). He supports DoD customers to design, build, and secure scalable applications on AWS. Prior, Nikhil worked as a network development engineer for AWS. Outside of work, he enjoys reading fiction, hiking, and spending time with his cat and family.

How to implement CNAP for federal and defense customers in AWS

In July 2021, the U.S. Department of Defense (DoD) released a cloud native access point (CNAP) reference design that follows zero trust architecture (ZTA) principles and provides a new approach to access mission owner (MO) applications. The DoD’s reference design discusses four core capabilities of CNAP: authenticated and authorized entities (C1), authorized ingress (C2), authorized egress (C3), and security monitoring and compliance enforcement (C4). In this blog post, we walk through how to establish the C2 component via a virtual internet access point (vIAP) with AWS. The proposed architectures can reduce operational cost and management overhead, while improving the accessibility, resiliency, and security of mission owner applications.