Evidence-Graph-Based Continuous Attestation for AWS Platform Foundations

Authors

  • Naga Krishna Reddy Muppidi

Keywords:

AWS, cloud governance, regulated financial services, platform engineering, infrastructure as code, policy as code, DevOps, audit evidence, security automation.

Abstract

Regulated cloud platforms increasingly depend on self-service infrastructure, policy-as-code, and internal developer platforms. A recurring research and operations gap is point-in-time compliance evidence that cannot explain historical platform state. This paper presents a continuous evidence graph for compliance attestation in AWS-centered enterprise platforms. The work models governance decisions as reproducible evidence objects and evaluates them across security, reliability, auditability, and developer-throughput dimensions. The paper contributes a problem formalization, reference architecture, evidence schema, scoring and control-loop design, evaluation methodology, and threats-to-validity analysis. The evaluation design uses controlled multi-account traces and anonymized operational data when available, avoiding unsupported claims about production results.

Downloads

Download data is not yet available.

References

Amazon Web Services, “AWS Control Tower User Guide,” 2024.

Amazon Web Services, “AWS Organizations User Guide,” 2024.

Amazon Web Services, “AWS Config Developer Guide,” 2024.

Amazon Web Services, “AWS CloudTrail User Guide,” 2024.

Amazon Web Services, “AWS Well-Architected Framework,” 2024.

National Institute of Standards and Technology, “Security and Privacy Controls for Information Systems and Organizations, SP 800-53 Rev. 5,” 2020.

National Institute of Standards and Technology, “Risk Management Framework for Information Systems and Organizations, SP 800-37 Rev. 2,” 2018.

National Institute of Standards and Technology, “The NIST Cybersecurity Framework 2.0,” 2024.

International Organization for Standardization, “ISO/IEC 27001:2022 Information Security Management Systems,” 2022.

Open Policy Agent, “OPA and Rego Documentation,” 2024.

HashiCorp, “Terraform Documentation,” 2024.

B. Beyer, C. Jones, J. Petoff, and N. R. Murphy, Eds., Site Reliability Engineering. O’Reilly Media, 2016.

N. Forsgren, J. Humble, and G. Kim, Accelerate. IT Revolution, 2018.

J. Humble and D. Farley, Continuous Delivery. Addison-Wesley, 2010.

G. Kim, J. Humble, P. Debois, and J. Willis, The DevOps Handbook, 2nd ed. IT Revolution, 2021.

Neo4j, “Graph Data Modeling Guidelines,” 2024.

Amazon Web Services, “AWS Audit Manager User Guide,” 2024.

Amazon Web Services, “Amazon Security Lake User Guide,” 2024.

Open Cybersecurity Schema Framework, “OCSF Schema,” 2024.

W3C, “PROV-O: The PROV Ontology,” 2013.

A. Hogan et al., “Knowledge Graphs,” ACM Comput. Surv., vol. 54, no. 4, 2021.

NIST, “Information Security Continuous Monitoring, SP 800-137,” 2011.

Amazon Web Services, “Conformance Packs in AWS Config,” 2024.

W3C, “RDF 1.1 Concepts and Abstract Syntax,” 2014.

Sigstore Project, “Sigstore Documentation,” 2024.

NIST, “Secure Software Development Framework, SP 800-218,” 2022.

NIST, “Cybersecurity Supply Chain Risk Management Practices, SP 800-161 Rev. 1,” 2022.

OpenSSF, “Supply-chain Levels for Software Artifacts (SLSA) Specification v1.0,” 2023.

The Linux Foundation, “SPDX Specification v3.0,” 2024.

OWASP Foundation, “CycloneDX Specification v1.5,” 2023.

Downloads

Published

30.12.2024

How to Cite

Naga Krishna Reddy Muppidi. (2024). Evidence-Graph-Based Continuous Attestation for AWS Platform Foundations. International Journal of Intelligent Systems and Applications in Engineering, 12(23s), 4414–4420. Retrieved from https://www.ijisae.org/index.php/IJISAE/article/view/8457

Issue

Section

Research Article