AWS Public Sector Blog

Category: Security, Identity, & Compliance

Validating infrastructure as code against FedRAMP 20x Shift-left compliance

Validating infrastructure as code against FedRAMP 20x: Shift-left compliance

Catching a compliance violation in production is expensive. Catching it in a pull request is nearly free. In this post, we demonstrate how to build a multi-tool infrastructure as code (IaC) validation pipeline that checks AWS CloudFormation templates and Terraform configurations against Federal Risk and Authorization Management Program (FedRAMP) 20x Key Security Indicators (KSIs) before deployment. Combined with the preventive controls from Preventive controls for FedRAMP 20x: Using SCPs and guardrails to enforce KSIs and the methods to be described in future blog posts, this creates a full-lifecycle compliance architecture.

MARS-E to ARC-AMPE: Guide for state Medicaid agencies on AWS

MARS-E to ARC-AMPE: Guide for state Medicaid agencies on AWS

This post is for two audiences. The first is agencies already running MARS-E-compliant workloads on AWS that are looking to map their existing posture onto the new framework. The second is agencies planning a migration from on-premises infrastructure where ARC-AMPE will be in scope from the first day.

Modernizing border control with digital arrival cards on AWS Cloud

Modernizing border control with digital arrival cards on AWS Cloud

Learn how Somapa Information Technology PCL (SomapaIT), an AWS Partner, chooses Amazon Web Services (AWS) Cloud to implement DAC systems because of its global footprint, security, high availability, and scalability.

How the University of São Paulo is transforming how researchers access greenhouse gas data for the Amazon rainforest with AWS

How the University of São Paulo is transforming how researchers access greenhouse gas data for the Amazon rainforest with AWS

Learn how researchers in the University of São Paulo Research Center in Greenhouse Gas Innovation (RCGI) greenhouse gas (GHG) program saw an opportunity to develop a system that enabled close monitoring of the forest using data systems and data spaces in the cloud. They created Digital Amazon, a distributed data space network with open access that integrates CO2 and greenhouse gas emissions data collected by the university with other data sources to support critical and timely climate action and intervention in the Amazon Forest.

How NTU FRESH is using AWS to build predictive food safety at scale

How NTU FRESH is using AWS to build predictive food safety at scale

In this post, we walk you through how FRESH is translating cloud-enabled analytics into practical tools that support resilient, trusted food systems, starting with a deep dive into dynamic shelf-life modeling. Specifically, we detail how AWS services such as Amazon Simple Storage Service (Amazon S3), AWS Glue, and Amazon SageMaker AI are used to build and train predictive models.

How healthcare organizations are advancing innovation while meeting digital sovereignty requirements with AWS

How healthcare organizations are advancing innovation while meeting digital sovereignty requirements with AWS

Healthcare is entering a new era. Advances in AI, data analytics, and cloud computing are creating opportunities ranging from accelerating drug discovery and enabling precision medicine to helping clinicians detect disease earlier and spend more time with patients. As healthcare organizations embrace these technologies, they face an equally important responsibility: safeguarding some of the world’s […]

An incident response playbook for satellite operations on AWS (Part-1): Detection and forensic readiness

An incident response playbook for satellite operations on AWS (Part-1): Detection and forensic readiness

In this post, the first in a two-part series, we focus on the detection and forensic readiness side of satellite IR. This post walks through instrumenting your ground segment with Amazon Web Services (AWS) security services and AWS Ground Station so that threats surface before they cause damage, and forensic data is already flowing when an incident occurs.

An incident response playbook for satellite operations on AWS (Part-2): Automated response and recovery

An incident response playbook for satellite operations on AWS (Part-2): Automated response and recovery

This blog covers what to do when those detections fire. Satellite incident response (IR) must account for constraints that ground-based systems never face: containment actions that wait for the next orbital pass, decisions that trade mission continuity against security, and recovery procedures where the compromised endpoint cannot be physically accessed. It walks through containment, eradication, recovery, automated runbooks, and tabletop exercises designed for satellite operations teams.

Prepare for your GovRAMP Progressing Snapshot with AWS

Prepare for your GovRAMP Progressing Snapshot with AWS

In this post, we explain what the Progressing Snapshot program is, what the program is for, who it is for, and how Amazon Web Services (AWS) helps you lay the foundation to address many of the 40 snapshot controls.

Build an AI-powered form filling assistant with Strands Agents

Build an AI-powered form filling assistant with Strands Agents

This post explains how to build exactly that using Strands Agents and Amazon Bedrock. The entire solution runs in about 200 lines of Python code, and you can have it working on your computer after completing the pre-requisite steps.