Build1 distinct publisher3 min readPublished
An independent gwi.digital review on AWS Artifact scores 234 of 256 addressable ISM controls as full or partial. The arithmetic on everything else is the part worth reading.
The Engineer · Build desk
Compiled by The EngineerSomething wrong?How this is made
Twenty-two controls inside the scope the accelerator claims for itself got neither full nor partial coverage [16], and 825 were never in scope at all [6]. Together that is 847 of the 1,081 ISM controls left for the customer to implement and evidence [17], about 78 percent of the manual [18]. The addressable slice is under a quarter of the ISM to begin with [19]; measured against the whole document, the accelerator reaches roughly 22 percent [20]. That is not a knock on the tool. It is the line the report draws, and the line is the useful part of it.
The coverage figure also merges two different states. Full and Partial were scored into one bucket [5], so a control where the landing zone switches on a log and leaves retention and review to you sits alongside one it closes outright. An assessor will separate them again, which makes the report read better as a work queue than as a score. The more durable contribution is the responsibility breakdown: rather than the AWS-or-customer binary, gwi.digital splits controls three ways, AWS provided, LZA enabled and customer responsibility, and subdivides the 825 out-of-scope controls into subcategories [11]. That is what a GRC team can plan against.
The result sits on an existing base and does not replace it. AWS states plainly that the report is not an IRAP authorization, certification or accreditation, only a professional evaluation of what the accelerator delivers out of the box and what it does not [8]. Underneath it, the AWS services themselves were most recently assessed at PROTECTED by CyberCX in the year before publication, according to AWS [10], and the gwi.digital work was positioned in Phase 2 of the ASD framework, aimed at consumers building on already-authorized services [7].
The drift-testing mechanism has the longest tail. ISM compliance is a continuing state and an assessment report is a photograph, so a way to keep measuring configuration against a tested baseline [14] is what turns an Artifact download into something an assessor can retest rather than accept on a date. It also runs the other way: once drift is measurable, a local deviation becomes a recorded one.
The commercial mechanics deserve naming. AWS is not really selling the accelerator here, it is pre-paying the documentation phase of an assessment that it says typically takes months of preparation, evidence gathering and testing [15]. The Compliance Workbook already mapped the Universal Configuration to 17 frameworks [12], and the accelerator automates close to 200 controls that apply themselves to new accounts as an estate grows [13]. What the ISM report adds is a third-party opinion in place of a vendor mapping. How much weight that carries is still an assessor's call [8].
Ranked by verification strength, evidence, and original report placement.
Of those 256 addressable controls, LZA achieves Full or Partial coverage for 234, which AWS states as 91 percent.
AWS announced availability of a new independent assessment report on AWS Artifact analyzing how Landing Zone Accelerator on AWS (LZA) can automatically deploy multi-account environments with Australian Government Information Security Manual (ISM) security control coverage at scale; findings come from an independent third-party analysis by AWS Partner gwi.digital, a consultancy specializing in cybersecurity and GRC with experience in IRAP assessments.
The ISM defines 1,081 security control requirements across 22 guideline chapters.
The gwi.digital team conducted an independent analysis and evaluation of the LZA Universal Configuration against all 1,081 ISM controls.
Of the 1,081 ISM controls, 256 are within the addressable scope of LZA, being the technical infrastructure controls such a solution can meaningfully address.
The remaining 825 controls are outside the scope of LZA: physical security, personnel, organizational governance, and classification-level exclusions.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed but single-sourced and gated
The cluster rests on one publisher — AWS's own security blog — describing an assessment of AWS's own solution. The numbers are specific and internally consistent (1,081 total, 256 addressable, 234 full/partial, 825 out of scope) and a named independent assessor with IRAP experience did the evaluation, which lifts this above marketing assertion. But the underlying report is behind AWS Artifact, no assessor or auditor statement appears independently, and the test conditions are a single greenfield ap-southeast-2 account on one LZA version, which AWS itself flags as version- and configuration-dependent.
Artifacts shipped, no user evidence
Concrete availability events exist: the ISM report on AWS Artifact, the October 2025 Universal Configuration and Compliance Workbook, and a 3,600-test CATS run across six accounts. But everything observed is vendor-produced supply, not demand — no customer deployments, agency names, IRAP outcomes, or usage counts are disclosed, and the continuous-validation component that carries most of the operational promise is a private beta reachable only through AWS Professional Services.
Headline denominator flatters the result
The framing leans on a 91 percent figure computed against a 256-control addressable subset, which is about 24 percent of the ISM; against the full 1,081 controls the covered set is roughly 22 percent, and 847 controls stay with the customer once out-of-scope and uncovered controls are combined. The post also promises reduced IRAP timelines without any measured before/after, while the mechanism that would generate that saving is a private beta and the report explicitly is not an authorization. The overstatement is one of emphasis rather than fabrication — every corrective number comes from AWS's own counts — so the gap is moderate, not severe.
Vendor post on vendor product, partner-assessed
The single source is AWS publishing about its own solution, on its own blog, with the detailed report distributed through its own compliance portal. The independent assessor is described as an AWS Partner, and the associated testing suite is reachable only by engaging AWS Professional Services — so both the validation and the remediation path route back to AWS commercial channels. Prior PROTECTED-level assessment of the underlying services is cited as supporting foundation, further aligning the narrative with AWS's sovereign-compliance sales position. Terms of the partner engagement are not disclosed.
Facts firm, interpretation single-sourced
Confidence in the raw counts is fairly high: they are stated precisely, internally consistent, and the corrective arithmetic (22 uncovered, 847 residual, ~22 percent of the ISM) derives directly from them without additional assumptions. Confidence in the significance is lower, because there is exactly one publisher, no independent verification of the assessment, no customer adoption data, and no measurement of the claimed timeline benefit.
build
Force the tool call, then hand Lightsail a long-lived key1 distinct publisher
build
CSA's 2026 threat list is a flat line, so ask which threats a config snapshot can prove1 distinct publisher
build
Axonius runs one agent per tenant on AgentCore, and tracks model cost the same way1 distinct publisher
build
AWS moves KubeRay chores into HyperPod, and the build-vs-buy math with them1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.