Amazon Route 53
What this tool proves, in the authored overlay. Every recipe below names Amazon Route 53; the controls are what their output is evidence for. The mapping is this project’s opinion (overlay v3.0.0) — the upstream FedRAMP rules name no vendor and no product.
Capabilities
Named separately by the recipes that call them, and counted here too. A recipe naming both this tool and one of its capabilities is one recipe, not two.
Recipes calling Amazon Route 53 (3)
- partialroute53-dnssec-signingweekly
DNSSEC signing status of every public hosted zone, with the key-signing key state and the DS record that carries the chain of trust to the parent
- partialroute53-resolver-dnssec-validationweekly
Per-VPC DNSSEC validation status of the Route 53 Resolver, joined against the full VPC inventory so that a VPC which never enabled validation is visible rather than absent
- partialname-resolution-role-separationcontinuous
The hosted zones that serve name resolution, each marked private or public so internal and external resolution can be shown to be served by separate zones, and the Resolver endpoints that carry queries across the VPC boundary with their direction and operational status
Controls it carries evidence for (3)
The reverse of the join above. A mark here is the control’s own grade across the whole corpus, not its grade from this tool alone — a control this tool partly proves may be fully proved with another.
Tool names are canonical, from data/overlays/aws-services.json and data/overlays/pipeline-tools.json. The two overlays that name services spelled five of them two ways; a page keyed on the raw string would have split those in half.