Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
Cloud InfrastructurePLAIN-LANGUAGE GUIDE

Amazon Web Services setup guide

Servers, storage, databases, and networking you rent by the hour. Work through the ten requirements below — each has a diagram and a checklist you can follow click by click.

Print checklist ↧
Before you store CUI here

For CUI and ITAR data, use AWS GovCloud (US) with FedRAMP High and DoD Impact Level 4–5 authorized services.

REQUIREMENT 01 OF 10

Phishing-Resistant Multi-Factor Authentication

IT-013.5.3IA.L2-3.5.3
IN PLAIN WORDS

Multi-factor authentication (MFA) means you need two things to log in: something you know (a password) and something you hold (a security key). A phishing-resistant key like a FIDO2 security key or passkey proves it is really you and cannot be tricked by a fake website. It is like a house key that only turns in your own front door, so a copied photo of the key is useless.

WHY IT MATTERS

If you skip it, a stolen or guessed password lets an attacker walk right into your cloud and reach defense data.

TOOLS YOU WILL USE
AWS IAM Identity CenterAWS Identity and Access Management (IAM)AWS Organizations
HOW THE SETUP FLOWS
  1. 1Enable Identity Center
  2. 2Require MFA
  3. 3Allow FIDO2 only
  4. 4Register keys
  5. 5Protect root user
  6. 6Verify login
STEP-BY-STEP CHECKLIST
Pro tip

Give each admin a second backup security key and store it safely, or a lost key can lock you out.

Government cloud & CUI

In AWS GovCloud (US), use IAM Identity Center with FIDO2 keys the same way, and prefer FIPS 140-3 validated authenticators to meet CUI and ITAR expectations.

EVIDENCE TO KEEP
Identity Center authentication settings screenshotList of users with registered FIDO2 devicesRoot account MFA-enabled proof
See the full IT-01 practice guide →
FAQ

Frequently asked questions

What does the Amazon Web Services setup guide cover?

It walks through ten security requirements — including phishing-resistant multi-factor authentication, least-privilege access control, asset & account inventory, and more — mapped to the DoW Brilliant at the Basics IT Top 10 and to NIST SP 800-171 / CMMC Level 2. Each requirement has a plain-language explanation, a process-flow diagram, and a click-by-click checklist.

Where do I perform these AWS steps?

In the AWS Management Console. Every step names the exact portal or console path to follow.

Is my checklist progress saved anywhere?

Your step checklist progress is saved only in your own browser (local storage). Nothing is sent to the site, and you can reset it at any time.

Can I use AWS for CUI?

For CUI and ITAR data, use AWS GovCloud (US), which is FedRAMP High and authorized to DoD Impact Level 4-5. Keep CUI inside the GovCloud boundary.

Do these steps work in AWS GovCloud?

Yes. The same services used in this guide — IAM Identity Center, AWS Config, GuardDuty, KMS, Security Hub CSPM, and others — are available in AWS GovCloud (US).