Writing
Lab notes and framework writeups. NIST 800-53 Rev 5, FedRAMP High, and CJIS v6.1 when the control is the point.
-
The Bucket Everything Else Trusts: A WORM Evidence Bucket in Terraform
SSE-KMS with a customer-managed CMK, Object Lock WORM retention, a TLS-only policy, and account-wide EBS encryption-by-default: the compliant-storage baseline every audit artifact in this series lands in, mapped to NIST 800-53 Rev 5, FedRAMP High, and CJIS v6.1.
aws-lab s3 kms terraform compliance-as-code nist-800-53 cjis-v6.1 -
IAM Hardening on a Brownfield AWS Account: Assess, Remediate, Prove
I hardened the study account I had been clicking around in for months. A credential report found a 203-day access key, no password-reuse prevention, and no cost guardrail. I assessed, remediated, and proved the baseline against NIST 800-53 Rev 5, FedRAMP High, and CJIS v6.0.
aws-lab iam identity-governance nist-800-53 cjis-v6.0