
Facilitating FedRAMP Compliance in AWS with Terraform
C2 Labs has built a wealth of experience in the world of cybersecurity and compliance. In a recent project, our client was pursuing FedRAMP authorization and needed to ensure that their AWS-based SaaS platform met the necessary compliance standards. C2 Labs was able to evaluate the client’s AWS setup to identify compliance issues and provide detailed fixes and recommendations to address those issues.
Thought Leadership
Provided detailed
recommendations and useful documentation concerning the steps necessary to harden
infrastructure and systems
and bring them into compliance.
Evaluated existing AWS
infrastructure to identify
compliance issues and
weak points.
Worked closely with the client’s engineers within the client’s change management processes to ensure they understood the changes and could maintain them going forward.
The Client
Our client is a company with an e-learning SaaS product hosted in AWS. They have
been building out their AWS infrastructure for several years, and recently began managing their AWS infrastructure using Terraform. However, the infrastructure they had built was not fully FedRAMP-ready.
Challenges
1. Complex Existing Codebase:
The client’s AWS infrastructure was largely managed by a mature and complex Terraform codebase. Locating the appropriate pieces of code that needed to be updated to change particular infrastructure objects in AWS required careful examination and an understanding of both AWS and Terraform.
2. Detailed but Non-Disruptive Changes to the Existing Architecture:
Some FedRAMP controls proved to require rather complex changes to the existing infrastructure. Implementing these changes without creating disruptions posed an additional challenge.
Solution
To address these challenges, our team carefully reviewed each compliance-related finding in AWS Security Hub, examined the relevant existing AWS infrastructure, and determined what changes were needed to bring the infrastructure into compliance.
​
Our team then provided detailed documentation of the findings, controls, and recommended changes. In addition, the team recommended changes to the Terraform code for review by the client’s engineering teams. After discussing the recommendations with the client’s engineering teams, the changes were implemented.
Results
As a result of our team’s engagement, CIS compliance benchmark scores were increased from 49% to 81%. Our team also provided detailed recommendations for addressing all of the remaining findings (19%). The overall Security Hub score increased from ~45% to ~70%. This brought the client much closer to FedRAMP compliance. Moreover, the detailed documentation provided by our team helped the client document the steps taken to ensure compliance.
FedRAMP enablement at your organization
FedRAMP authorization can be a difficult process. The process is complex and requires significant technical expertise and effort. Additional expertise can be valuable when pursuing any compliance program or simply working to improve cybersecurity.
