From fragmented posture to a secure, repeatable deployment pattern aligned to EO 14028 and NIST 800-53 Rev 5.
71 → 0
POA&Ms
1.53 → 3.00
Zero Trust maturity target
< 60 min
Infra deploy via Terraform
0 critical/high
CSA findings
Snapshot
Client
U.S. Department of Health & Human Services (HHS)
Industry
Federal – Health & Human Services
Compliance
NIST 800-53 R5 • EO 14028 • FedRAMP
Mission & Challenge
HHS required continuity of services for the Human Resources Management Enterprise Services Bus (HRMESB) on Azure while measurably improving cyber resilience. The mandate: reduce inherited POA&Ms, enable disaster recovery in a target region, and move to a secure, repeatable deployment pattern – minimizing tenant-wide permissions and modernizing legacy SFTP.
What We Did
Fix
Resolved legacy POA&Ms with evidenceable remediation steps.
Hardened baselines and IAM; standardized RBAC.
Centralized logging and alerting for faster issue triage.
Fortify
DR target-region and operational runbooks.
Terraform for consistent, environment-based deployments.
Replaced VM-based SFTP with Azure Blob SFTP and event-driven processing.
Future-Proof
Zero Trust roadmap aligned to HHS priorities.
User-Assigned Managed Identity (UAMI) per environment to enforce least privilege.
Defender for Cloud coverage and alerting.
71 → 0
POA&Ms
1.53 → 3.00
ZTA
< 60 min
Deploy
0
Crit/High
Impact to Date
POA&Ms: Reduced from 71 to 0, tracked in the CSA/evidence log.
Zero Trust: Path from 1.53 to 3.00 with mapped control families.
Speed & repeatability: Infra spin-up in under 60 minutes using Terraform + GitHub Actions.