GOVCLOUD
/

Compliance Posture

Per-control status computed live from AWS Config + Security Hub findings, mapped to each framework through a curated Control Crosswalk. Status is never hand-authored — the screen shows the truth, including partial and customer-owned controls.

fedramp-high-rev5
Enabled Frameworks·set by Platform Admin · evidence is collected only for these 8
FedRAMP High Coverage
90%
36/40 satisfied
36 satisfied
1 partial (shared)
3 customer-owned
US Federal Agencies, SaaS vendors serving federal
NIST 800-53 Rev 5 High baseline for federal cloud systems. Required for Level 4/5 CUI and national-security-adjacent workloads.

Control Families

Click a row to filter the control list below.

Controls

40 of 40 shown

ControlTitleStatusLayersEvidence
AC-2Account ManagementSatisfied
FoundationApp
identity.yaml (deploy roles); IAM Identity Center
AC-3Access EnforcementSatisfied
FoundationAgentStampApp
Permission boundary (identity.yaml); agent-stamp IAM roles
AC-4Information Flow EnforcementSatisfied
FoundationAgentStamp
VPC endpoints + endpoint policies (networking.yaml); SG rules
AC-6Least PrivilegeSatisfied
FoundationAgentStampApp
Permission boundary (identity.yaml); per-tool IAM scoping
AC-17Remote AccessSatisfied
AWSFoundation
TLS 1.2+ enforced via S3 bucket policies and endpoint policies
AU-2Event LoggingSatisfied
FoundationAgentStampApp
CloudTrail (audit.yaml); Bedrock invocation logs; agent structured logs
AU-3Content of Audit RecordsSatisfied
FoundationApp
CloudTrail event content (AWS-defined); custom event content (app)
AU-4Audit Storage CapacitySatisfied
Foundation
S3 audit bucket (audit.yaml) — virtually unbounded
AU-9Protection of Audit InformationSatisfied
AWSFoundation
S3 Object Lock Compliance Mode (audit.yaml); CMK encryption (security.yaml)
AU-11Audit Record RetentionSatisfied
Foundation
365-day Object Lock + Glacier Deep Archive (audit.yaml)
AU-12Audit Record GenerationSatisfied
FoundationAgentStampApp
Service-level AWS logging; agent structured logs to CloudWatch
CM-2Baseline ConfigurationSatisfied
FoundationAgentStamp
This repo + parameters/<env>.json
CM-3Configuration Change ControlSatisfied
FoundationAgentStamp
Change-set review (bin/deploy.sh); CodePipeline manual approval (ci.yaml)
CM-5Access Restrictions for ChangeSatisfied
Foundation
Deploy roles scoped (identity.yaml); permission boundary blocks IAM tampering
CM-6Configuration SettingsSatisfied
FoundationAgentStamp
CloudFormation Guard rules (shared/guard-rules/); cfn_nag scan
CM-7Least FunctionalitySatisfied
FoundationAgentStampApp
No public networking (network-no-public.guard); per-tool IAM
CM-8System Component InventorySatisfied
FoundationAgentStamp
AWS Config (observability.yaml)
IA-2Identification and AuthenticationSatisfied
AWSFoundation
IAM + IAM Identity Center
IA-5Authenticator ManagementSatisfied
Foundation
Account password policy (identity.yaml custom resource)
IR-4Incident HandlingSatisfied
AWSFoundationAgentStampApp
GuardDuty + Security Hub (observability.yaml); operational runbooks
IR-5Incident MonitoringSatisfied
Foundation
Security Hub (observability.yaml)
IR-6Incident ReportingCustomer
Customer
Customer responsibility — FedRAMP PMO reporting procedures
SC-7Boundary ProtectionSatisfied
AWSFoundation
VPC + endpoint policies (networking.yaml); no IGW/NAT
SC-8Transmission ConfidentialitySatisfied
FoundationAgentStampApp
TLS 1.2+ enforced; RequireSecureTransport deny statement
SC-12Cryptographic Key EstablishmentSatisfied
AWSFoundation
KMS key creation + rotation (security.yaml)
SC-13Cryptographic ProtectionSatisfied
AWS
FIPS 140-3 Level 3 KMS HSMs (AWS-LC FIPS module)
SC-28Protection of Information at RestSatisfied
FoundationAgentStamp
CMK encryption on every storage resource (security.yaml, agent-stamp)
SI-2Flaw RemediationSatisfied
AWSFoundationAgentStamp
AWS-managed for service infra; Inspector for container/Lambda (observability.yaml)
SI-3Malicious Code ProtectionSatisfied
AWSFoundation
GuardDuty Malware Protection
SI-4System MonitoringSatisfied
AWSFoundationAgentStampApp
CloudTrail; GuardDuty; CloudWatch alarms; agent-level metrics
SI-7Software/Firmware IntegritySatisfied
FoundationAgentStamp
CloudTrail log file validation; ECR immutability + scanning (registry.yaml)
SI-10Information Input ValidationCustomer
App
Bedrock Guardrails + Pydantic schemas (app responsibility)
RA-5Vulnerability MonitoringSatisfied
FoundationAgentStamp
Inspector (observability.yaml) for ECR images, Lambda runtimes
CP-7Alternate Processing SiteSatisfied
AWSFoundation
Multi-AZ private subnets (networking.yaml); cross-region foundation deploy
CP-9System BackupSatisfied
AWSFoundationAgentStamp
DynamoDB PITR (agent-stamp); S3 versioning + Object Lock; AWS Backup
CP-10System Recovery and ReconstitutionSatisfied
FoundationAgentStamp
Infrastructure-as-code reconstitution from this repo
SR-3Supply Chain Controls and ProcessesSatisfied
AWSFoundation
ECR image scanning + immutability; CodeArtifact for vetted packages
CA-7Continuous MonitoringSatisfied
Foundation
AWS Config conformance pack; Security Hub; GuardDuty
SA-11Developer Testing & EvaluationPartial
FoundationApp
cfn-guard + cfn_nag in CI; app-layer testing is customer-owned
PL-2System Security PlanCustomer
Customer
Customer artifact — SSP is outside this repo

Cross-framework Crosswalk

Capabilities in this stack mapped to their equivalents in other frameworks. 6 capabilities relevant to FedRAMP High.