Secure VPC for Financial Regulation Compliance

Job ID: 40209811

Budget: €18 – €36 EUR

Project Overview
This proof-of-concept will demonstrate a regulator-grade, fully secured VPC hosting a central authority and multiple financial-institution tenants, while automating supervision and compliance checks using native AWS services.

Scope
The environment will be logically segmented into public and private subnets for each participant. The central authority resides in its own network segment and can observe, query, and enforce policies across all other institutions without exposing sensitive resources publicly.

Key Services

AWS Lambda for event-driven oversight logic and scheduled compliance sweeps

AWS RDS for the authoritative supervisory data store

AWS S3 as the immutable audit and reporting repository

Security & Compliance
Networking, IAM, logging, encryption, and traffic inspection must adhere to high financial-regulatory standards. This includes:

End-to-end TLS

KMS-managed encryption

Fine-grained IAM policies

VPC flow logs streaming to CloudWatch/S3

Auditable change control

Deliverables

Terraform, CloudFormation, or CDK templates to provision the VPC, subnets, route tables, NAT gateways, and security groups

Deployment scripts and Lambda code that trigger compliance checks and write results to RDS and S3

A concise runbook describing how the central authority dashboard calls the Lambdas, reviews reports, and updates policies

Architecture diagram (PDF or draw.io) showing components, trust boundaries, and data flows

Final walkthrough or recorded demo showing a non-compliant event being detected and logged within the same VPC

Acceptance Criteria

The stack deploys cleanly in a fresh AWS account

Passes a CIS Level 1 benchmark scan without modifications

Correctly stores a sample regulatory breach in the audit bucket, accessible only from the central authority subnet

All detailed functional requirements, sample data, and compliance rules will be provided after project kickoff.