KITC

CASE STUDY

U.S. Air Force

Cloud Hosting, Managed Services, and Security

Client U.S. Air Force (via GSD&M)
Start Date October 2022
Status Ongoing
11
Mission Websites
Managed
14
AWS Accounts
Under Management
100%
RMF & FISMA
Compliance
0
Critical Security
Incidents
CHALLENGE

Securing Mission-Critical Digital Assets

The U.S. Air Force required a secure and scalable AWS environment to host and maintain its public-facing mission websites, including airforce.com and spaceforce.com. The objective was to improve performance, reduce operational costs, and maintain continuous compliance with federal cybersecurity frameworks such as the NIST Risk Management Framework (RMF) and FISMA.

SOLUTION

End-to-End AWS Managed Services

KITC serves as the Air Force's AWS Managed Service Provider, delivering comprehensive hosting, security, and optimization services. The team manages development and production environments across 14 AWS accounts, implements cost-management and performance-monitoring practices, and coordinates with Air Force Recruiting Service (AFRS) and Information System Security Officers (ISSOs) to maintain compliance.

TECHNOLOGY STACK

AWS Environment

Amazon EC2
Scalable compute infrastructure for web applications
Amazon S3
Secure object storage for static assets
Amazon CloudFront
Global content delivery network
AWS IAM
Identity and access management
AWS KMS
Encryption key management service
AWS Security Hub
Unified security and compliance monitoring
IMPLEMENTATION

Partner Support Activities

Planning and Preparation

  • Developed the cloud architecture roadmap for multi-account AWS management
  • Integrated authentication between on-premise Active Directory and AWS resources
  • Built secure development and production environments with account-level guardrails

Ongoing Support

  • Continuous monitoring and incident response using AWS Security Hub and CrowdStrike
  • Regular penetration testing and infrastructure reviews
  • Cost and usage optimization through FinOps practices using CloudCheckr
  • Quarterly Well-Architected Reviews to assess resiliency, security, and performance
RESULTS

Key Outcomes

Securely hosts 11 mission websites within 14 AWS accounts
Maintains compliance with RMF and FISMA security controls
Applies multi-layered security protections across all hosted environments
Enhances website performance and reliability through CloudFront and CDN configuration
Supports authentication modernization through Active Directory federation

Engagement Summary

KITC's AWS Managed Service engagement provides the Air Force with secure, compliant, and cost-efficient cloud operations. Through structured monitoring, FinOps practices, and continuous security management, KITC ensures that mission-critical websites remain available, optimized, and aligned with federal cybersecurity standards.