Topics

Compliance and audit evidence on AWS

Turning what your pipeline and your account already produce into evidence an auditor accepts.

CPS 234 and its 2025 sibling CPS 230 don't grade your AWS account directly — they grade whether you can prove your controls held, on demand. That's the thread through this group: CPS 234 control mapping ties each requirement to an AWS service and Config rule, CPS 230 covers what changed since it took effect on 1 July 2025 for landing-zone and provider-dependency work, and the evidence an auditor actually asks for is the export, not the screenshot.

Two lessons push past the checklist: which CPS 234 controls are theatre versus real risk reduction, and the 72-hour incident notification runbook, which treats the deadline as an engineering problem rather than a policy paragraph.

AWS ships its own starting point — the CPG 234 conformance pack maps roughly 130 Config rules to APRA's guidance — and Essential Eight at Maturity Level 3 translates ACSC's on-prem-era strategies to AWS-native controls. The last two close the loop from finding to narrative: turning Security Hub output into APRA-paragraph text with Bedrock, and Assure, the open-source CLI that automates that translation into a board-ready report.

Lessons

Common questions

Does CPS 234 apply to my AWS account directly?
It applies to the regulated entity. Your AWS configuration is how you demonstrate the control, not the obligation itself.