AWS Public Sector Blog

Category: AWS Identity and Access Management (IAM)

How eduroam empowers its community through real-time analytics with Amazon Quick Sight

How eduroam empowers its community through real-time analytics with Amazon Quick Sight

For the more than 2,800 administrators across approximately 1,200 participating institutions in the US, that means access to near daily provided to them through Amazon Quick Sight on Amazon Web Services (AWS) by the eduroam team at Internet2. However, this wasn’t always the case. This post walks through how the eduroam team modernized their data reporting pipeline, the architecture behind it, and the impact it’s had on institutional engagement.

TOLAP: Closing the data-object security gap in AI agent architectures

TOLAP: Closing the data-object security gap in AI agent architectures

Every major agent framework has a security model for this. Amazon Web Services (AWS), Microsoft, and Google each ship agent solutions with authentication and credential management built in. Amazon Bedrock Agents, for example, enforces AWS Identity and Access Management (IAM)-based authorization on which AWS Lambda functions, Amazon Simple Storage Service (Amazon S3) buckets, and Amazon Bedrock Knowledge Bases an agent might invoke.

Accelerate IRAP readiness with AWS and Wiz

Accelerate IRAP readiness with AWS and Wiz

As organisations modernise to meet the evolving expectations of the Australian Government, delivering secure, cloud-based services has become a commercial and operational necessity. This transformation brings a critical challenge: maintaining a hardened security posture while aligning to the Information Security Registered Assessors Program (IRAP) assessment requirements and priorities.

Validating infrastructure as code against FedRAMP 20x Shift-left compliance

Validating infrastructure as code against FedRAMP 20x: Shift-left compliance

Catching a compliance violation in production is expensive. Catching it in a pull request is nearly free. In this post, we demonstrate how to build a multi-tool infrastructure as code (IaC) validation pipeline that checks AWS CloudFormation templates and Terraform configurations against Federal Risk and Authorization Management Program (FedRAMP) 20x Key Security Indicators (KSIs) before deployment. Combined with the preventive controls from Preventive controls for FedRAMP 20x: Using SCPs and guardrails to enforce KSIs and the methods to be described in future blog posts, this creates a full-lifecycle compliance architecture.

MARS-E to ARC-AMPE: Guide for state Medicaid agencies on AWS

MARS-E to ARC-AMPE: Guide for state Medicaid agencies on AWS

This post is for two audiences. The first is agencies already running MARS-E-compliant workloads on AWS that are looking to map their existing posture onto the new framework. The second is agencies planning a migration from on-premises infrastructure where ARC-AMPE will be in scope from the first day.

How the University of São Paulo is transforming how researchers access greenhouse gas data for the Amazon rainforest with AWS

How the University of São Paulo is transforming how researchers access greenhouse gas data for the Amazon rainforest with AWS

Learn how researchers in the University of São Paulo Research Center in Greenhouse Gas Innovation (RCGI) greenhouse gas (GHG) program saw an opportunity to develop a system that enabled close monitoring of the forest using data systems and data spaces in the cloud. They created Digital Amazon, a distributed data space network with open access that integrates CO2 and greenhouse gas emissions data collected by the university with other data sources to support critical and timely climate action and intervention in the Amazon Forest.

Prepare for your GovRAMP Progressing Snapshot with AWS

Prepare for your GovRAMP Progressing Snapshot with AWS

In this post, we explain what the Progressing Snapshot program is, what the program is for, who it is for, and how Amazon Web Services (AWS) helps you lay the foundation to address many of the 40 snapshot controls.

Why the location of your AI agent is a security decision

Why the location of your AI agent is a security decision

Learn how Amazon Web Services (AWS) operates inside a scoped compute environment with an AWS Identity and Access Management (IAM) execution role, network segmentation, and defense-in-depth security meeting FISMA, FedRAMP, and DoD CCSRG standards.

A governance framework for building trustworthy agentic AI for public sector and regulated organizations

A governance framework for building trustworthy agentic AI for public sector and regulated organizations

This post outlines a practical governance framework for agentic AI systems, with a focus on public sector and other highly regulated environments. It introduces a scope-based model for classifying agent autonomy, identifies core security dimensions, and describes how organizations can align agentic AI governance with existing risk, compliance, and assurance programs.

Supporting GSA CUI protection requirements with AWS

Supporting GSA CUI protection requirements with AWS

In this blog, we will discuss how federal contractors handling Controlled Unclassified Information (CUI) for the General Services Administration (GSA) face a critical reality when the updated security requirements are required to maintain your contracts. The stakes extend beyond business; inadequate CUI protection compromises sensitive government operations and US national interests. The recently updated GSA IT Security Procedural Guide CIO-IT Security-21-112 Revision 1 (January 2026) aligns with NIST SP 800-171 Revision 3 and sets the bar for protecting CUI in nonfederal systems. Learn how Amazon Web Services (AWS) provides security services specifically designed to help you address these requirements efficiently.