DIAMONDBACK

Check your AWS accounts against FedRAMP, the Australian ISM, or public hardening benchmarks.

FedRAMP's 2026 rules replaced the baselines with 46 Key Security Indicators and 246 requirements on fixed dates. Diamondback shows which you can evidence from live configuration today, and which deadlines are closing.

AWS CLOUDSHELL curl -sL https://diamondback.run/install.sh | bash -s -- --region us-east-1
CloudShell opens in a new tab — copy the command above and paste it in. It can't auto-run for you.

Diamondback turns live AWS configuration into FedRAMP evidence — and says plainly which indicators it cannot speak to.

Evidence, not assertions

19 of FedRAMP's 46 Key Security Indicators, evidenced from real configuration and joined to each indicator through the NIST controls it names — not a mapping drawn by hand.

Deadlines that bind you

246 requirements, filtered to your certification type, path and class. VDR and VER bind on 7 December 2026 under CISA BOD 26-04, and the register leads with what is closing.

Hardened pragmatically

CIS AWS Foundations, AWS FSBP and NIST 800-53 from our own checks — no Security Hub subscription, no per-finding bill.

What Diamondback sees

One read-only pass over your account — every enabled region, and every account in your AWS Organization if you point it there — turned into evidence against FedRAMP's indicators. Everything it can't prove, it says so, plainly.

How it runs

In your account

One CloudFormation stack in your own AWS account — App Runner, RDS, Cognito. Your configuration never leaves it.

Read-only by construction

SecurityAudit + ViewOnlyAccess and nothing else. Every call is a describe, list or get — checkable in source, and refused by IAM if it weren't.

Asks, explained

When a check needs a service you haven't enabled, Diamondback says which, why, what it unlocks, and the exact aws command — including what it will cost you.

One account or all of them

Point it at your AWS Organization and it assumes a read-only role in each member account and sweeps them together. Every finding still names the account it came from — and any account it could not reach is named too, as unassessed.

Obvious identity

The console reads its own role back from IAM and shows you the policies attached — not a claim in a brochure, a live check.

What you need to install

One command in AWS CloudShell, in the account you want assessed — no local tooling:

AWS CLOUDSHELL curl -sL https://diamondback.run/install.sh | bash -s -- --region us-east-1

AWS permissions

Permission to create a CloudFormation stack containing IAM roles, RDS, Cognito, VPC and App Runner. The installer creates them and attaches Diamondback's role read-only SecurityAudit + ViewOnlyAccess.

Sign-in

A Cognito user pool is created for you. Operators are invited by email — no self-registration, MFA available, and a 15-character password floor to match the ISM's own.

AWS-authored evidence (optional)

Enable Security Hub and Diamondback reads its failing CIS/FSBP controls as AWS-authored evidence. It is charged per check, so it stays your call — every control below is assessed without it.

What Diamondback ends up holding

Two AWS managed read-only policies. No write path, no standing secret, and no access to the contents of your buckets or databases — it assesses configuration, not data. Teardown is one command.

What it refuses to say

The reason to trust a compliance tool is what it declines to claim.

No indicator is "met"

A KSI statement is broader than any check that informs it. Diamondback reports evidence, currently clean at the very most. Whether the indicator is met is a 3PAO's determination, and the status vocabulary has no word for it.

Absence is never a pass

No evidence is not assessed. A missing prerequisite is no visibility. A permission error is no visibility — never mistaken for "no resources exist".

The 246 rules are not graded

They are programme and process obligations — independent assessment, marketplace listing, change notification. Grading them from an AWS account would be nonsense, so Diamondback carries the register and the dates, and assesses none of it.

Unscanned is not clean

Before a scan has run, indicators show unscanned rather than clean, because clean would be an artefact of having no findings to show.

An account it could not reach is not an account with nothing wrong

The two look identical: both produce no findings. So every report states which accounts it covered and names the ones it did not, and if your organisation could not even be listed it says the number of accounts it missed is unknown.

Mapped to what you're assessed against

One scan, every framework a finding touches — pinned to real published versions. FedRAMP leads; the Australian ISM is still carried in full for customers who need both.

FedRAMP Consolidated Rules 2026 NIST SP 800-53 Rev. 5 CIS AWS Foundations v3.0.0 AWS FSBP v1.0.0 AWS Well-Architected, Security Pillar ACSC Essential Eight (Nov 2023) ISM PROTECTED (ASD OSCAL)

Pricing

$100 USD / month
USD, per install — one Diamondback deployment in your account
Subscribe
Everything included. No feature gates, no per-seat charge, no control limits. Every install gets the FedRAMP indicator coverage and requirements register, the full 986-control ISM assessment, all five evidence planes, the attestation and decision workspace, and the PDF, SSP and Annex artefacts.
Unlimited regions and users. One install scans every region enabled in the account, and everyone you invite to the Cognito pool can use it.
Updates included. FedRAMP revises the Consolidated Rules and ASD revises the ISM; released updates carry the new datasets, and upgrading is one command that keeps your attestations and decisions.
Cancel any time. Monthly, no lock-in. Uninstall is one command and leaves nothing behind.
Plus your own AWS costs. Diamondback runs in your account, so you pay AWS directly for the infrastructure it uses — one App Runner service, a db.t4g.micro RDS Postgres, and a NAT gateway, typically ~$70–95 USD/month at current list prices (the NAT gateway is roughly a third of it). Nothing is billed through us, and you can tear it down whenever you like. Costs vary by region and usage; check the AWS pricing calculator for your own estimate.

Who's behind it

Built by Abhijit Ghosh — nearly a decade in national-government cyber security, including several years at the Australian Cyber Security Centre (ACSC) and the Australian Signals Directorate (ASD), assessing cloud systems against exactly this kind of control framework.

Diamondback is the tool that assessment work kept calling for: a control framework turned into something you can run, read, and hand to an assessor — with the honest gaps shown, not a spreadsheet re-filled by hand each quarter. It reads only, holds nothing but two AWS read-only policies, and keeps your data in your own account.

Independent and unaffiliated. Diamondback is an independent product. It is not endorsed by, affiliated with, sponsored by, or produced on behalf of the Australian Signals Directorate, the Australian Cyber Security Centre, or the Australian Government, and the author's prior public service does not imply any such endorsement. Diamondback is built entirely from publicly available information — the published ISM and the public benchmarks it maps to — and contains no material derived from any position of employment. "ISM", "ACSC", "ASD", "Essential Eight" and "IRAP" are used nominatively to describe the frameworks assessed.

Security audits welcome

Diamondback is built to be approvable in an afternoon. The install templates are public, and the full source is available to security teams on request — read the code, verify there's no write path, watch it hold nothing but SecurityAudit and ViewOnlyAccess. Reach us at security@diamondback.run.

No warranty; no liability. Diamondback is provided "as is", without warranty of any kind, express or implied. To the maximum extent permitted by law, the authors and copyright holder accept no liability for any claim, loss or damage arising from its use. It is an assessment aid, not a guarantee of security or compliance; you remain responsible for your own compliance decisions and their verification.

Independence. Diamondback is an independent assessment aid. It is not endorsed by, affiliated with, accredited or recognised by FedRAMP, the GSA, CISA, any United States government body, the Australian Signals Directorate, the ACSC, or the Australian Government. It is not a 3PAO and performs no independent assessment. It reports observed configuration against published frameworks; it does not grant, confer or predict a FedRAMP authorisation, an IRAP assessment or any accreditation. Whether a Key Security Indicator is met is a determination for an assessor, never for this tool. "FedRAMP", "ISM", "Essential Eight", "ACSC" and "IRAP" are used nominatively to describe the frameworks referenced. Framework control identifiers are curated references pinned to the versions shown and should be verified against the source.