AWS Public Sector Blog

Category: Amazon VPC

Continuous monitoring under FedRAMP 20x: Replacing annual assessments with persistent validation

Continuous monitoring under FedRAMP 20x: Replacing annual assessments with persistent validation

Under legacy Federal Risk and Authorization Management Program (FedRAMP) Rev5, continuous monitoring meant monthly deliverables and annual assessments. Under FedRAMP 20x, it means persistent, automated validation where the status of your security posture is always known. In this post, we operationalize that model using AWS Security Hub, AWS Config conformance packs, Amazon GuardDuty, Amazon Inspector, and Sigma detection rules to build an always-on monitoring architecture.

From Amazon RDS Custom for Oracle to what’s next: A technical guide to Oracle migration paths on AWS

From Amazon RDS Custom for Oracle to what’s next: A technical guide to Oracle migration paths on AWS

This post provides a decision framework and technical guidance to help database administrators and architects navigate the transition facing Amazon Web Services (AWS) customers who run workloads on Amazon Relational Database Service (Amazon RDS) Custom for Oracle.

State of Kansas modernizes mainframe file transfer using AWS Transfer Family

State of Kansas modernizes mainframe file transfer using AWS Transfer Family

In this post, we walk through how OSM partnered with Sierra-Cedar, an AWS Premier Consulting Partner, to design, build, and deploy FileVault—a secure file transfer solution powered by AWS Transfer Family and Amazon Simple Storage Service (Amazon S3)—while preserving the user experience that state employees already knew and trusted.

Building machine-readable FedRAMP 20x evidence on AWS

In this post, we walk through the evidence pipeline, from Amazon Web Services (AWS) Config evaluations and AWS Security Hub findings through transformation and storage, to producing the dual-format output that satisfies FedRAMP 20x Phase 2 completeness requirements.

Transforming Public Sector Procurement with Agentic AI on AWS

Transforming Public Sector Procurement with Agentic AI on AWS

This post explores how an agentic AI architecture on Amazon Web Services (AWS) modernizes the procurement lifecycle from solicitation to proposal evaluation while maintaining compliance with government regulations including United States of America FAR (Federal Acquisition Regulation),United States of America DFARS (Defense Federal Acquisition Regulation), and Canadian procurement frameworks (Public Service Procurement Canada (PSPC) /Shared Services Canada (SSC).

MARS-E to ARC-AMPE: Guide for state Medicaid agencies on AWS

MARS-E to ARC-AMPE: Guide for state Medicaid agencies on AWS

This post is for two audiences. The first is agencies already running MARS-E-compliant workloads on AWS that are looking to map their existing posture onto the new framework. The second is agencies planning a migration from on-premises infrastructure where ARC-AMPE will be in scope from the first day.

Deep dive into FedRAMP 20x Key Security Indicators: Decoding the 63 KSIs

Deep dive into FedRAMP 20x Key Security Indicators: Decoding the 63 KSIs

In this post, we break down every KSI theme, categorize each indicator by validation approach, and provide a practical gap analysis framework so you can begin preparing your cloud service offering (CSO) for FedRAMP 20x authorization on Amazon Web Services (AWS).

Domino Data Lab secures container supply chains at scale using Chainguard on AWS

Domino Data Lab secures container supply chains at scale using Chainguard on AWS

Ivanti’s 2025 State of Cybersecurity Report revealed that only one in three organizations feel prepared to protect themselves from software supply chain threats. According to Cowbell’s Cyber Roundup Report 2024, with respect to supply chain threats, operating systems pose the greatest immediate threat as “they form the foundational layer of an organization’s entire IT infrastructure.” […]

AWS Branded Background with text "Customizing isolated JupyterLab environments in Amazon SageMaker Studio"

Customizing isolated JupyterLab environments in Amazon SageMaker Studio

This post demonstrates how to enhance security and compliance in an isolated SageMaker JupyterLab environment by implementing two key customizations: configuring download restrictions and implementing secure Python package installation through AWS CodeArtifact.

AWS branded background design with text overlay that says "AWS accelerates digital public infrastructure adoption with automation"

AWS accelerates digital public infrastructure adoption with automation

In this post, we explore how AWS enables the automation of deploying a DPI-based solution stack. We highlight Sunbird RC (Registry and Credentials) as a real-world digital public goods (DPG) building block. The following example provides an overview and execution of the packaging available in the Sunbird community GitHub repository for provisioning required AWS services and deploying Sunbird RC services.