AWS Public Sector Blog

Category: AWS Config

Continuous monitoring under FedRAMP 20x: Replacing annual assessments with persistent validation

Continuous monitoring under FedRAMP 20x: Replacing annual assessments with persistent validation

Under legacy Federal Risk and Authorization Management Program (FedRAMP) Rev5, continuous monitoring meant monthly deliverables and annual assessments. Under FedRAMP 20x, it means persistent, automated validation where the status of your security posture is always known. In this post, we operationalize that model using AWS Security Hub, AWS Config conformance packs, Amazon GuardDuty, Amazon Inspector, and Sigma detection rules to build an always-on monitoring architecture.

AWS expands its Defending Digital Campaigns offering for the 2026 election cycle

AWS expands its Defending Digital Campaigns offering for the 2026 election cycle

This post describes the program for the 2026 cycle, the services it covers, and how eligible campaigns and committees can enroll. Since AWS first joined DDC in 2020 and expanded the offering in 2022 and again in 2024, eligible campaigns and committees of any size and on either side of the aisle have used these services to protect the data, identities, and applications they rely on through Election Day.

MARS-E to ARC-AMPE: Guide for state Medicaid agencies on AWS

MARS-E to ARC-AMPE: Guide for state Medicaid agencies on AWS

This post is for two audiences. The first is agencies already running MARS-E-compliant workloads on AWS that are looking to map their existing posture onto the new framework. The second is agencies planning a migration from on-premises infrastructure where ARC-AMPE will be in scope from the first day.

An incident response playbook for satellite operations on AWS (Part-1): Detection and forensic readiness

An incident response playbook for satellite operations on AWS (Part-1): Detection and forensic readiness

In this post, the first in a two-part series, we focus on the detection and forensic readiness side of satellite IR. This post walks through instrumenting your ground segment with Amazon Web Services (AWS) security services and AWS Ground Station so that threats surface before they cause damage, and forensic data is already flowing when an incident occurs.

An incident response playbook for satellite operations on AWS (Part-2): Automated response and recovery

An incident response playbook for satellite operations on AWS (Part-2): Automated response and recovery

This blog covers what to do when those detections fire. Satellite incident response (IR) must account for constraints that ground-based systems never face: containment actions that wait for the next orbital pass, decisions that trade mission continuity against security, and recovery procedures where the compromised endpoint cannot be physically accessed. It walks through containment, eradication, recovery, automated runbooks, and tabletop exercises designed for satellite operations teams.

Deep dive into FedRAMP 20x Key Security Indicators: Decoding the 63 KSIs

Deep dive into FedRAMP 20x Key Security Indicators: Decoding the 63 KSIs

In this post, we break down every KSI theme, categorize each indicator by validation approach, and provide a practical gap analysis framework so you can begin preparing your cloud service offering (CSO) for FedRAMP 20x authorization on Amazon Web Services (AWS).

AWS Branded Background with text "Build a secure AWS foundation in under 60 minutes: A guide for public sector organizations"

Build a secure AWS foundation in under 60 minutes: A guide for public sector organizations

In this blog, we will guide you through the process of setting up a secure multi-account AWS environment using AWS Control Tower, AWS IAM Identity Center, AWS Organizations and will show you how to secure your environment using AWS Config, AWS Security Hub, and Amazon GuardDuty.

AWS Branded Background with text "5 ways AWS empowers GovTech innovation in 2025"

5 ways AWS empowers GovTech innovation in 2025

Amazon Web Services (AWS) has been a trusted collaborator and advisor to GovTechs for years, providing the tools, expertise, and support they need to build and grow their solutions effectively. In this blog post, we discuss five key ways AWS supports GovTechs in their mission to serve government agencies and citizens.

AWS branded background design with text overlay that says "How to safeguard healthcare data privacy using Amazon Bedrock Guardrails"

How to safeguard healthcare data privacy using Amazon Bedrock Guardrails

As more and more healthcare companies use their data to remain competitive, protecting patient data is as critical than ever. With increasing adoption of AI/ML models in healthcare, making sure that these technologies comply with privacy regulations such as HIPAA and GDPR has become a top priority. Amazon Bedrock is a fully managed service that provides unified access to a diverse selection of high-performance foundation models from industry-leading AI companies. In this post, we walk you through the importance of healthcare data privacy and how to use Amazon Bedrock Guardrails to safeguard sensitive information in AI-driven healthcare solutions.