FedRAMP Moderate Landing Zone on AWS GovCloud
Designed and built a compliant multi-account AWS GovCloud environment for an agency migrating from a commercial data center. Delivered a documented landing zone with Control Tower, SCPs, centralized logging, and a Security Hub aggregation account — all mapped to NIST 800-53 Rev 5 controls.
The challenge
The agency had an existing ATO for on-premises infrastructure but needed to extend it to AWS under FedRAMP Moderate. Their current AWS footprint was a single account with no guardrails, ad-hoc IAM, and no centralized audit logging.
What we built
We designed a 6-account structure (management, log archive, audit, shared services, workload prod, workload dev) deployed via Terraform with a remote state backend in S3 + DynamoDB. Control Tower enrollment, SCP enforcement, and Config Rules provided the continuous compliance posture required for ConMon. A SIEM integration forwarded CloudTrail and VPC Flow Logs to the agency's existing logging platform.
Outcomes
- ATO boundary extension completed within 90 days
- Zero critical findings in third-party assessment
- Centralized logging covering 100% of API activity from day one
- ConMon automation reduced manual evidence collection by ~80%