The AWS Security team has published an independent assessment report on AWS Artifact that evaluates the Landing Zone Accelerator (LZA) against the Australian Government Information Security Manual (ISM). The report, produced with partner gwi.digital, shows that LZA’s universal configuration can automatically provision multi‑account environments while covering a large portion of ISM technical controls, which shortens the effort required for IRAP readiness.
What the report measures
The analysis examined all 1,081 ISM controls and identified 256 controls that are technically addressable by LZA. Of those, LZA provides full or partial coverage for 234 controls, representing a 91 % coverage rate. The remaining 825 controls fall outside LZA’s scope because they relate to physical security, personnel, governance, or classification‑level exclusions.
How LZA aligns with ISM and other frameworks
Since October 2025, LZA includes a Universal Configuration (UC) and a Compliance Workbook that map the deployed guardrails to requirements from 17 global compliance frameworks. The workbook, also available on AWS Artifact, documents the technical mapping, making it easier for teams to trace which LZA resources satisfy specific controls. The ISM assessment builds on this foundation, confirming that the automated guardrails align with the ISM’s technical infrastructure requirements.
Operational implications for Australian cloud workloads
Practitioners can now rely on a documented, third‑party‑validated baseline when building new accounts in the ap‑southeast‑2 (Sydney) region. The key operational takeaways are:
- Accelerated IRAP preparation: Evidence of control implementation is generated automatically by LZA, reducing manual evidence‑gathering.
- Configuration drift detection: The report mentions a new testing mechanism for measuring drift, suggesting that teams should incorporate regular drift scans into their CI/CD pipelines.
- Shared responsibility clarity: The assessment introduces a three‑tier view—AWS‑provided services, LZA‑enabled controls, and customer responsibilities—helping teams allocate ownership for each control.
- Underlying service assurance: Core AWS services used by LZA have been independently assessed at the PROTECTED level by CyberCX, providing an additional layer of confidence.
Related CloudNinjas coverage: AWS.
What This Means For Practitioners
Teams building or operating Australian government workloads should evaluate LZA as a baseline for ISM technical controls. Verify that the 234 covered controls match your project’s control set, and plan supplemental processes for the out‑of‑scope items (physical security, personnel, governance). Integrate the drift‑measurement mechanism into your monitoring stack to maintain compliance over time. Finally, treat the report as a professional evaluation—not an official IRAP authorization—and be prepared to provide additional evidence for the controls that LZA does not address.

