Evidence-Graph-Based Continuous Attestation for AWS Platform Foundations
Keywords:
AWS, cloud governance, regulated financial services, platform engineering, infrastructure as code, policy as code, DevOps, audit evidence, security automation.Abstract
Regulated cloud platforms increasingly depend on self-service infrastructure, policy-as-code, and internal developer platforms. A recurring research and operations gap is point-in-time compliance evidence that cannot explain historical platform state. This paper presents a continuous evidence graph for compliance attestation in AWS-centered enterprise platforms. The work models governance decisions as reproducible evidence objects and evaluates them across security, reliability, auditability, and developer-throughput dimensions. The paper contributes a problem formalization, reference architecture, evidence schema, scoring and control-loop design, evaluation methodology, and threats-to-validity analysis. The evaluation design uses controlled multi-account traces and anonymized operational data when available, avoiding unsupported claims about production results.
Downloads
References
Amazon Web Services, “AWS Control Tower User Guide,” 2024.
Amazon Web Services, “AWS Organizations User Guide,” 2024.
Amazon Web Services, “AWS Config Developer Guide,” 2024.
Amazon Web Services, “AWS CloudTrail User Guide,” 2024.
Amazon Web Services, “AWS Well-Architected Framework,” 2024.
National Institute of Standards and Technology, “Security and Privacy Controls for Information Systems and Organizations, SP 800-53 Rev. 5,” 2020.
National Institute of Standards and Technology, “Risk Management Framework for Information Systems and Organizations, SP 800-37 Rev. 2,” 2018.
National Institute of Standards and Technology, “The NIST Cybersecurity Framework 2.0,” 2024.
International Organization for Standardization, “ISO/IEC 27001:2022 Information Security Management Systems,” 2022.
Open Policy Agent, “OPA and Rego Documentation,” 2024.
HashiCorp, “Terraform Documentation,” 2024.
B. Beyer, C. Jones, J. Petoff, and N. R. Murphy, Eds., Site Reliability Engineering. O’Reilly Media, 2016.
N. Forsgren, J. Humble, and G. Kim, Accelerate. IT Revolution, 2018.
J. Humble and D. Farley, Continuous Delivery. Addison-Wesley, 2010.
G. Kim, J. Humble, P. Debois, and J. Willis, The DevOps Handbook, 2nd ed. IT Revolution, 2021.
Neo4j, “Graph Data Modeling Guidelines,” 2024.
Amazon Web Services, “AWS Audit Manager User Guide,” 2024.
Amazon Web Services, “Amazon Security Lake User Guide,” 2024.
Open Cybersecurity Schema Framework, “OCSF Schema,” 2024.
W3C, “PROV-O: The PROV Ontology,” 2013.
A. Hogan et al., “Knowledge Graphs,” ACM Comput. Surv., vol. 54, no. 4, 2021.
NIST, “Information Security Continuous Monitoring, SP 800-137,” 2011.
Amazon Web Services, “Conformance Packs in AWS Config,” 2024.
W3C, “RDF 1.1 Concepts and Abstract Syntax,” 2014.
Sigstore Project, “Sigstore Documentation,” 2024.
NIST, “Secure Software Development Framework, SP 800-218,” 2022.
NIST, “Cybersecurity Supply Chain Risk Management Practices, SP 800-161 Rev. 1,” 2022.
OpenSSF, “Supply-chain Levels for Software Artifacts (SLSA) Specification v1.0,” 2023.
The Linux Foundation, “SPDX Specification v3.0,” 2024.
OWASP Foundation, “CycloneDX Specification v1.5,” 2023.
Downloads
Published
How to Cite
Issue
Section
License

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
All papers should be submitted electronically. All submitted manuscripts must be original work that is not under submission at another journal or under consideration for publication in another form, such as a monograph or chapter of a book. Authors of submitted papers are obligated not to submit their paper for publication elsewhere until an editorial decision is rendered on their submission. Further, authors of accepted papers are prohibited from publishing the results in other publications that appear before the paper is published in the Journal unless they receive approval for doing so from the Editor-In-Chief.
IJISAE open access articles are licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. This license lets the audience to give appropriate credit, provide a link to the license, and indicate if changes were made and if they remix, transform, or build upon the material, they must distribute contributions under the same license as the original.


