AWS Public Sector Blog

Dr. Tommy Kromer

Author: Dr. Tommy Kromer

Dr. Tommy Kromer is a Practice Manager with AWS Security Assurance Services (SAS), focusing on public sector compliance and security operations. He has spent his career helping government contractors navigate complex regulatory landscapes, from the early days of DIACAP through some of the first RMF accreditations to today's CMMC requirements. Leveraging his experience across the Department of Defense and intelligence community, along with expertise in security operations center management and threat hunting, Tommy works closely with customers to align security and compliance as complementary forces that achieve mission-critical objectives.

Continuous monitoring under FedRAMP 20x: Replacing annual assessments with persistent validation

Continuous monitoring under FedRAMP 20x: Replacing annual assessments with persistent validation

Under legacy Federal Risk and Authorization Management Program (FedRAMP) Rev5, continuous monitoring meant monthly deliverables and annual assessments. Under FedRAMP 20x, it means persistent, automated validation where the status of your security posture is always known. In this post, we operationalize that model using AWS Security Hub, AWS Config conformance packs, Amazon GuardDuty, Amazon Inspector, and Sigma detection rules to build an always-on monitoring architecture.

Building machine-readable FedRAMP 20x evidence on AWS

In this post, we walk through the evidence pipeline, from Amazon Web Services (AWS) Config evaluations and AWS Security Hub findings through transformation and storage, to producing the dual-format output that satisfies FedRAMP 20x Phase 2 completeness requirements.

Validating infrastructure as code against FedRAMP 20x Shift-left compliance

Validating infrastructure as code against FedRAMP 20x: Shift-left compliance

Catching a compliance violation in production is expensive. Catching it in a pull request is nearly free. In this post, we demonstrate how to build a multi-tool infrastructure as code (IaC) validation pipeline that checks AWS CloudFormation templates and Terraform configurations against Federal Risk and Authorization Management Program (FedRAMP) 20x Key Security Indicators (KSIs) before deployment. Combined with the preventive controls from Preventive controls for FedRAMP 20x: Using SCPs and guardrails to enforce KSIs and the methods to be described in future blog posts, this creates a full-lifecycle compliance architecture.

https://app.asana.com/1/8442528107068/project/1207199896111772/task/1214439772201800?focus=true

Preventive controls for FedRAMP 20x: Using SCPs and guardrails to enforce KSIs

Why preventive controls matter for FedRAMP 20x Organizations strengthen their security posture when Amazon Web Services (AWS) cloud resources consistently align with security and regulatory requirements. Preventive security controls, which are designed to minimize or avoid threat events, help enforce these requirements before misconfigurations are deployed. In this post, we show how service control policies […]