Security and Compliance Services
Onedata Software Solutions · Cybersecurity & IT
Certification per AWS Marketplace.
Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
OneData Software’s Security Posture Review offering provides a robust and multi-layered assessment of AWS environments, designed to enhance cloud security and ensure regulatory alignment. As both an AWS Well-Architected Partner and an AWS Managed Services Provider, OneData combines deep architectural evaluation with automated security tooling and continuous monitoring.
🔧*** Core Components of the Service:***
Show the rest of the publisher’s description (36 more lines)
**1. Comprehensive Discovery & Assessment**
Certified AWS professionals conduct deep evaluations across all six pillars of the AWS Well-Architected Framework, with an emphasis on the Security Pillar. The review focuses on IAM, encryption, network security, and data protection practices, identifying architectural flaws and control weaknesses.
**2. Automated Security Diagnostics with AWS Native Tools**
*Using services like AWS Security Hub, GuardDuty, Inspector, Macie, and AWS Config, OneData performs real-time scans across accounts and regions to detect:*
o Exposed resources
o Misconfigured IAM roles
o Lack of encryption
o Suspicious activity or threats
o Compliance drift based on frameworks like CIS Benchmarks, NIST SP 800-53, and AWS Foundational Security Best Practices
**3. Security Findings Dashboard & Risk Scoring**
Findings are centralized into a Security Hub dashboard and custom visualizations. OneData assigns security scores, tracks high-risk issues (HRIs), and maps vulnerabilities to compliance controls for prioritization.
**4. Customized Remediation Roadmap**
*Based on posture findings, OneData delivers a tailored remediation plan, covering:*
o IAM policy fixes
o Encryption enforcement
o Logging and monitoring enhancements
o EventBridge-based automation workflows for continuous remediation
o Network access refinements (e.g., security groups, ACLs)
**5. Compliance Readiness Mapping**
*Reviews are tailored to align with regulatory mandates:*
o HIPAA – ePHI protection, audit logging, BAA support
o PCI DSS – Cardholder data security, access control, and scanning
o ISO 27001 – ISMS alignment, control implementation, audit readiness
o NIST – Policy alignment and technical safeguards
**6. Continuous Monitoring & Governance**
*Post-review, OneData enables continuous oversight through:*
o AWS Config – Resource compliance and drift tracking
o CloudTrail – Full-stack audit logging
o Security Lake – Log aggregation for SIEM integration
o Periodic reassessments to maintain posture and adapt to changes
*Aligned with AWS’s shared responsibility model and security best practices, OneData’s Security Posture Review touches on:*
- Identity & Access Management – IAM reviews, MFA enforcement, and access governance
- Infrastructure & Data Protection – Encryption, network security, vulnerability scans
- Threat Detection & Monitoring – GuardDuty, Security Hub, real-time alerting
- Compliance & Risk Management – Mapping to HIPAA, PCI DSS, ISO 27001, NIST
- Operational Excellence – Secure-by-default designs and policy automation
Highlights
Highlighted by the publisher on AWS Marketplace.
• Security Posture Review • AWS Well-Architected Framework • AWS Security Hub • GuardDuty • Amazon Inspector • Macie • CIS Benchmarks
• NIST SP 800-53 • PCI DSS • HIPAA Compliance • ISO 27001 Readiness • IAM Policy Review
• Encryption Enforcement • CloudTrail Logging • AWS Config • EventBridge Automation • Compliance Dashboard • Risk Prioritization
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Sources
Linked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

