AWS Public Sector Blog
Building machine-readable FedRAMP 20x evidence on AWS
In this post, we walk through the evidence pipeline, from Amazon Web Services (AWS) Config evaluations and AWS Security Hub findings through transformation and storage, to producing the dual-format output that satisfies FedRAMP 20x Phase 2 completeness requirements.
Validating infrastructure as code against FedRAMP 20x: Shift-left compliance
Catching a compliance violation in production is expensive. Catching it in a pull request is nearly free. In this post, we demonstrate how to build a multi-tool infrastructure as code (IaC) validation pipeline that checks AWS CloudFormation templates and Terraform configurations against Federal Risk and Authorization Management Program (FedRAMP) 20x Key Security Indicators (KSIs) before deployment. Combined with the preventive controls from Preventive controls for FedRAMP 20x: Using SCPs and guardrails to enforce KSIs and the methods to be described in future blog posts, this creates a full-lifecycle compliance architecture.
Preventive controls for FedRAMP 20x: Using SCPs and guardrails to enforce KSIs
Why preventive controls matter for FedRAMP 20x Organizations strengthen their security posture when Amazon Web Services (AWS) cloud resources consistently align with security and regulatory requirements. Preventive security controls, which are designed to minimize or avoid threat events, help enforce these requirements before misconfigurations are deployed. In this post, we show how service control policies […]


