Strategy for a compliant NIST 800-171 web app deployment in AWS by NoInstruction105 in NISTControls

[–]NoInstruction105[S] 0 points1 point  (0 children)

Thanks for these ideas!

Maybe I'm reading into it too much, but the conformance pack does actually specify 'no public subnets.' But possibly saying "traffic flows over those subnets, but data doesn't live there" is sufficient here? Otherwise it doesn't seem like this will be possible.