AWS Public Sector Blog

Paul Keastead

Author: Paul Keastead

Paul Keastead is a Senior Security Engineer with AWS Global Professional Services Security, where he builds the operational security mechanisms that govern how ProServe delivers to customers worldwide. His work spans engagement security automation, AI-powered provider risk assessments, and GenAI governance for a global delivery organization across 24 countries. He designs assessment frameworks and tooling that enable providers to demonstrate security posture across complex control environments including CMMC, FedRAMP, and critical infrastructure protection. He brings over a decade of security leadership across the Marine Corps, federal research, and private sector technology compliance.

Prepare for your GovRAMP Progressing Snapshot with AWS

Prepare for your GovRAMP Progressing Snapshot with AWS

In this post, we explain what the Progressing Snapshot program is, what the program is for, who it is for, and how Amazon Web Services (AWS) helps you lay the foundation to address many of the 40 snapshot controls.

A governance framework for building trustworthy agentic AI for public sector and regulated organizations

A governance framework for building trustworthy agentic AI for public sector and regulated organizations

This post outlines a practical governance framework for agentic AI systems, with a focus on public sector and other highly regulated environments. It introduces a scope-based model for classifying agent autonomy, identifies core security dimensions, and describes how organizations can align agentic AI governance with existing risk, compliance, and assurance programs.

Deep dive into FedRAMP 20x Key Security Indicators: Decoding the 63 KSIs

Deep dive into FedRAMP 20x Key Security Indicators: Decoding the 63 KSIs

In this post, we break down every KSI theme, categorize each indicator by validation approach, and provide a practical gap analysis framework so you can begin preparing your cloud service offering (CSO) for FedRAMP 20x authorization on Amazon Web Services (AWS).

Supporting GSA CUI protection requirements with AWS

Supporting GSA CUI protection requirements with AWS

In this blog, we will discuss how federal contractors handling Controlled Unclassified Information (CUI) for the General Services Administration (GSA) face a critical reality when the updated security requirements are required to maintain your contracts. The stakes extend beyond business; inadequate CUI protection compromises sensitive government operations and US national interests. The recently updated GSA IT Security Procedural Guide CIO-IT Security-21-112 Revision 1 (January 2026) aligns with NIST SP 800-171 Revision 3 and sets the bar for protecting CUI in nonfederal systems. Learn how Amazon Web Services (AWS) provides security services specifically designed to help you address these requirements efficiently.

Prepare for FedRAMP 20x with AWS automation and validation

Prepare for FedRAMP 20x with AWS automation and validation

This post shows you how to use Amazon Web Services (AWS) services to meet Federal Risk and Authorization Management Program (FedRAMP) 20x requirements, reducing authorization time from months to weeks through automated compliance pipelines and continuous validation. You’ll learn how to build a trust center, automate vulnerability detection, generate Key Security Indicators (KSIs), and implement […]