AWS Public Sector Blog
Continuous monitoring under FedRAMP 20x: Replacing annual assessments with persistent validation
Under legacy Federal Risk and Authorization Management Program (FedRAMP) Rev5, continuous monitoring meant monthly deliverables and annual assessments. Under FedRAMP 20x, it means persistent, automated validation where the status of your security posture is always known. In this post, we operationalize that model using AWS Security Hub, AWS Config conformance packs, Amazon GuardDuty, Amazon Inspector, and Sigma detection rules to build an always-on monitoring architecture.
Building machine-readable FedRAMP 20x evidence on AWS
In this post, we walk through the evidence pipeline, from Amazon Web Services (AWS) Config evaluations and AWS Security Hub findings through transformation and storage, to producing the dual-format output that satisfies FedRAMP 20x Phase 2 completeness requirements.
Validating infrastructure as code against FedRAMP 20x: Shift-left compliance
Catching a compliance violation in production is expensive. Catching it in a pull request is nearly free. In this post, we demonstrate how to build a multi-tool infrastructure as code (IaC) validation pipeline that checks AWS CloudFormation templates and Terraform configurations against Federal Risk and Authorization Management Program (FedRAMP) 20x Key Security Indicators (KSIs) before deployment. Combined with the preventive controls from Preventive controls for FedRAMP 20x: Using SCPs and guardrails to enforce KSIs and the methods to be described in future blog posts, this creates a full-lifecycle compliance architecture.
Preventive controls for FedRAMP 20x: Using SCPs and guardrails to enforce KSIs
Why preventive controls matter for FedRAMP 20x Organizations strengthen their security posture when Amazon Web Services (AWS) cloud resources consistently align with security and regulatory requirements. Preventive security controls, which are designed to minimize or avoid threat events, help enforce these requirements before misconfigurations are deployed. In this post, we show how service control policies […]



