aws AWS Security Blog ·

AWS LZA Now Provides Independent Report & Tool for Faster IRAP Assessments

blogawsgaarchitectgovernment
announcement feature

AWS has released a new independent assessment report for Landing Zone Accelerator (LZA), detailing its coverage of Australian Government Information Security Manual (ISM) controls and available on AWS Artifact. Conducted by gwi.digital, this report offers a validated foundation for Australian public sector, defense, and critical infrastructure organizations to accelerate IRAP assessment readiness. Additionally, AWS developed the Controls Acceptance Testing Suite (CATS), a private beta solution for automated compliance validation and continuous drift detection, which generated evidence for the assessment. This combination aims to significantly reduce IRAP assessment timelines and improve compliance outcomes.

  • Controls Acceptance Testing Suite (CATS) for Continuous Validation
  • Independent Assessment Report for LZA on AWS Artifact
  • Key Findings of the ISM Control Assessment
  • ISM-Optimized Configuration Recommendations for LZA
Features (1)
  • Controls Acceptance Testing Suite (CATS) for Continuous Validation

    AWS developed the Controls Acceptance Testing Suite (CATS), an automated compliance validation engine that runs purpose-built tests against the security configuration baseline deployed by LZA UC. For Australian customers, CATS enables automated evidence generation, ISM-enriched reporting, OSCAL export, and continuous drift detection. CATS is currently available as a private beta solution through AWS Professional Services.

Enhancements (1)
  • ISM-Optimized Configuration Recommendations for LZA

    The assessment identified specific configuration adjustments to elevate control ratings from Partial to Full with minimal effort, such as increasing default password length or adjusting log retention. These recommendations have been communicated to the LZA UC team for inclusion in a future ISM-specific guidance section within LZA GitHub documentation.

Notes (2)
  • Independent Assessment Report for LZA on AWS Artifact

    AWS announced the availability of a new independent assessment report for Landing Zone Accelerator (LZA) on AWS Artifact. This report, conducted by AWS Partner gwi.digital, analyzes how LZA can automatically deploy multi-account environments with Australian Government Information Security Manual (ISM) security controls coverage at scale. It provides a documented and validated foundation to accelerate IRAP assessment readiness for Australian customers.

  • Key Findings of the ISM Control Assessment

    The assessment evaluated LZA's Universal Configuration against 1,081 ISM controls, finding that LZA achieves Full or Partial coverage for 234 of the 256 addressable controls (91%). The report also introduces a three-tier shared responsibility model (AWS, LZA, Customer) to help organizations quickly determine which controls require their attention, streamlining IRAP assessment scoping and documentation.

Read the original announcement →

https://aws.amazon.com/blogs/security/fast-track-ism-ready-cloud-environments-and-irap-assessments-with-landing-zone-accelerator-on-aws/

Related releases