AWS Public Sector Blog

Category: Amazon CloudWatch

An incident response playbook for satellite operations on AWS (Part-1): Detection and forensic readiness

An incident response playbook for satellite operations on AWS (Part-1): Detection and forensic readiness

In this post, the first in a two-part series, we focus on the detection and forensic readiness side of satellite IR. This post walks through instrumenting your ground segment with Amazon Web Services (AWS) security services and AWS Ground Station so that threats surface before they cause damage, and forensic data is already flowing when an incident occurs.

An incident response playbook for satellite operations on AWS (Part-2): Automated response and recovery

An incident response playbook for satellite operations on AWS (Part-2): Automated response and recovery

This blog covers what to do when those detections fire. Satellite incident response (IR) must account for constraints that ground-based systems never face: containment actions that wait for the next orbital pass, decisions that trade mission continuity against security, and recovery procedures where the compromised endpoint cannot be physically accessed. It walks through containment, eradication, recovery, automated runbooks, and tabletop exercises designed for satellite operations teams.

Prepare for your GovRAMP Progressing Snapshot with AWS

Prepare for your GovRAMP Progressing Snapshot with AWS

In this post, we explain what the Progressing Snapshot program is, what the program is for, who it is for, and how Amazon Web Services (AWS) helps you lay the foundation to address many of the 40 snapshot controls.

Solving federal log retention requirements with AWS account-level subscription filters

Solving federal log retention requirements with AWS account-level subscription filters

Learn how the Login.gov team implemented a robust long-term log retention system that solved multiple architectural challenges while using Amazon Web Services (AWS) account-level subscription filters to provide capabilities that other approaches couldn’t match.

Why the location of your AI agent is a security decision

Why the location of your AI agent is a security decision

Learn how Amazon Web Services (AWS) operates inside a scoped compute environment with an AWS Identity and Access Management (IAM) execution role, network segmentation, and defense-in-depth security meeting FISMA, FedRAMP, and DoD CCSRG standards.

A faster, more resilient digital repository: Migrating DSpace to AWS

A faster, more resilient digital repository: Migrating DSpace to AWS

Learn more about the Digital Research and Curation Center (DRCC), the group within the Sheridan Libraries that builds and manages digital infrastructure for open scholarship, migrated DSpace to the cloud with Amazon Web Services (AWS).

Transforming federal IT with Datadog's FedRAMP Class D (High) solution

Transforming federal IT with Datadog’s FedRAMP Class D (High) solution

In this post, we explore how federal agencies can accelerate modernization, improve cybersecurity incident response, and support continuous compliance monitoring using Datadog’s FedRAMP High authorized observability and security platform.

Building an identity-verified remote assessment platform on AWS

Building an identity-verified remote assessment platform on AWS

Universities across the UK conduct tens of thousands of online interviews and exams each year. During a single admissions intake, over 20,000 video interviews were recorded for international applicants, with 1.3% of sessions showing confirmed fraud, including 0.15% involving deepfakes. A survey by the International Center for Academic Integrity (ICAI) found that 2% of students […]

TIC 3.0 architecture migration for federal agencies using AWS Transit Gateway

TIC 3.0 architecture migration for federal agencies using AWS Transit Gateway

Federal agencies operating in the cloud face a challenge with Trusted Internet Connection 2.0. All internet traffic must backhaul through on-premises infrastructure, creating bottlenecks that limit cloud adoption and degrade performance. The TIC 3.0 initiative addresses this by enabling agencies to implement security controls directly in the cloud, providing secure internet connectivity for federal workloads, […]

Domino Data Lab secures container supply chains at scale using Chainguard on AWS

Domino Data Lab secures container supply chains at scale using Chainguard on AWS

Ivanti’s 2025 State of Cybersecurity Report revealed that only one in three organizations feel prepared to protect themselves from software supply chain threats. According to Cowbell’s Cyber Roundup Report 2024, with respect to supply chain threats, operating systems pose the greatest immediate threat as “they form the foundational layer of an organization’s entire IT infrastructure.” […]