Key Takeaways

  • Effectual built a self-service AWS solution for a federal government customer, letting them securely provision new accounts on their own.
  • Everything was built as Infrastructure as Code with strict GitLab-based change control and custom CI/CD pipelines.
  • The engagement achieved a FISMA Moderate Authority to Operate (ATO) alongside the technical build.
  • Automation eliminated the original scalability bottleneck; a fully compliant environment can now be deployed in about one hour.
  • Provisioning a new account dropped from roughly a month to about one minute, with consistent, reusable, least-privilege deployments.

Effectual enabled a Federal Government customer to set up a self-service cloud solution which is secure, compliant, and automated to scale up and down as necessary.

Customer Needs

The Customer wanted to scale out compliant accounts to meet security concerns such as accessing only approved services, protecting centrally managed resources, and ensuring logging and change activity was being captured. The overall issue was ability to consistently provision AWS accounts in a scalable fashion and manage them over time, keeping them up-to-date with newly approved AWS Services. The goal was to provide secure and compliant cloud hosting options while setting up a customer self-service solution.

Our Approach

We assisted the client in creating their entire environment from Infrastructure as Code while implementing a strict change control processes via GitLab. Custom pipelines were created based off the CI/CD framework for structured code. Overall the entire process was automated, eliminating the scalability issue of provisioning accounts. Our resources worked directly alongside the agency resources to document and achieve a FISMA Moderate ATO.

The Benefits

Scalability

The customer was able to quickly provision accounts in a consistent method across multiple geographical locations and regions. The entire environment can be deployed in one hour.

Self-Service

We enabled the customer to securely provision their own infrastructure, standardized methodology, and least-privileged architecture. This methodology ensures security in the cloud for the client.

Management of Resources

The services in AWS monitor both on-premises and AWS cloud environments. The time to provision new accounts was reduced from a month to one minute. The deployments are now consistent and can be saved for later use.

Frequently Asked Questions

What problem was this federal customer trying to solve?

They needed to scale out secure, compliant AWS accounts consistently, approving only certain services, protecting centrally managed resources, and capturing full logging and change activity.

How did Effectual approach the solution?

By building the entire environment as Infrastructure as Code with strict GitLab-based change control and custom CI/CD pipelines, automating account provisioning end-to-end.

Did the solution meet federal compliance requirements?

Yes, Effectual worked directly with agency resources to document and achieve a FISMA Moderate Authority to Operate (ATO).

How much faster is account provisioning now?

Provisioning a new account dropped from roughly one month to about one minute, with the full environment deployable in about an hour.

What does self-service mean in this context?

The customer can securely provision their own infrastructure using a standardized, least-privilege methodology, without needing Effectual involved in every deployment.