C5 (Germany)AWS Well-Architected Security Pillar

C5 (Germany) covers 49.2% of AWS Well-Architected Security Pillar

31 of the 63 controls in AWS Well-Architected Security Pillar are already satisfied by evidence you collected for C5 (Germany). 32 are genuine gaps. Every claim below was judged against both control sets and then argued against; the ones that did not survive are published further down with the reason each failed.

49.2%
of the target already covered
31
controls evidenced
32
genuine gaps
2
claims rejected in review

This number is directional. It says how much of AWS Well-Architected Security Pillar your C5 (Germany) evidence satisfies. The reverse pair is a different number, often very different, because a security standard has enormous depth for access control and almost none for lawful basis or data subject rights.

97 candidate mappings were examined and 2 were removed. Signed off 2026-08-19, review level machine verified. Mappings were judged by Claude Code rather than read line by line by a practitioner. Every claim shows its reasoning so you can check it. Ask and a practitioner will review this pair.

Where the gaps are

Coverage is never evenly spread. A source standard usually satisfies one part of a target almost completely and barely touches another, and which part is which is the thing worth knowing before you plan the work.

Data Protection7 of 11 evidenced, 4 to do
Security Foundations5 of 8 evidenced, 3 to do
Application Security4 of 8 evidenced, 4 to do
Detection2 of 4 evidenced, 2 to do
Identity & Access Management7 of 15 evidenced, 8 to do
Infrastructure Protection4 of 9 evidenced, 5 to do
Incident Response2 of 8 evidenced, 6 to do

Theme level, not control level, deliberately. The per-control list of what is evidenced and what is a gap is the report itself, so publishing it here would be publishing the thing being sold.

Claims that held

A sample. Each one names the control whose evidence does the work, the control it satisfies, and why.

C5-SIM-01SEC 10: How do you anticipate, respond to, and recover from incidents? | SEC10-BP02argued against and upheld
Develop incident management plans

C5's incident policy defines classification, prioritisation and escalation rules, a standing response team and timely customer notification.

C5-SIM-05SEC 10: How do you anticipate, respond to, and recover from incidents? | SEC10-BP08argued against and upheld
Establish a framework for learning from incidents

C5 measures and monitors incident type and volume and uses the analysis to decide where further protection is needed.

C5-DEV-04SEC 11: How do you incorporate and validate the security properties of applications? | SEC11-BP01argued against and upheld
Train for application security

C5 runs a recurring audience-specific training programme on secure software development, delivery and the tools involved.

C5-DEV-06SEC 11: How do you incorporate and validate the security properties of applications? | SEC11-BP02argued against and upheld
Automate testing throughout the development and release lifecycle

C5 tests each change to a depth matching its risk rating and rates and remediates defects against defined severity criteria.

C5-OPS-19SEC 11: How do you incorporate and validate the security properties of applications? | SEC11-BP03argued against and upheld
Perform regular penetration testing

C5 commissions penetration tests at least annually under a documented methodology across risk-identified components.

C5-DEV-09SEC 11: How do you incorporate and validate the security properties of applications? | SEC11-BP06argued against and upheld
Deploy software programmatically

C5 requires authorised personnel or approval components to release each change into production against defined criteria.

C5-DEV-07SEC 11: How do you incorporate and validate the security properties of applications? | SEC11-BP06argued against and upheld
Deploy software programmatically

C5 places deployment tooling under enforced authorisation and logs every production change traceably.

C5-OPS-24SEC 1: How do you securely operate your workload? | SEC01-BP01argued against and upheld
Separate workloads using accounts

C5 strictly separates customer data held on shared virtual and physical resources under a documented risk derived approach.

Claims that did not hold

2 proposed mappings for this pair were rejected. They are kept in the graph rather than deleted, so what was thrown out is as inspectable as what survived. A crosswalk that never rejects anything is not being judged.

C5-OPS-13SEC 4: How do you detect and investigate security events? | SEC04-BP01
Configure service and application logging

judged against C5 criterion titles before the framework carried requirement text; does not hold against the real criterion; C5-OPS-13 requires automated analysis and correlation of log data; configuring and enabling service and application logging is OPS-10

Claimed at high confidence before it was rejected.

C5-IDM-07SEC 8: How do you protect your data at rest? | SEC08-BP04
Enforce access control

judged against C5 criterion titles before the framework carried requirement text; does not hold against the real criterion; C5-IDM-07 requires the customer be notified of provider access to unencrypted data; it enforces no access control over data

Claimed at high confidence before it was rejected.

The full report

Everything above is a sample. The report is every evidenced control and every gap, with the reasoning and the source document behind each one, in a form you can hand to an assessor. $299, emailed immediately.

Buy this crosswalk