Compliance, Mapped to Your Cloud
Assess your AWS, Azure, and Google Cloud environments against the industry frameworks and regulations your auditors expect.

CMMC 2.0 Level 2
The Cybersecurity Maturity Model Certification (CMMC) verifies the safeguards protecting Federal Contract Information and CUI across the defense supply chain.
Controls assessed
Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems). This involves identifying authorized users, processes, and devices and ensuring system access is limited accordingly.
Limit system access to the types of transactions and functions that authorized users are permitted to execute. This involves defining types of transactions and functions for users and ensuring system access aligns with these definitions.
Verify and control/limit connections to and use of external systems. This includes identifying connections to external systems, verifying their use, and ensuring they are controlled and limited as defined.
Control the flow of Controlled Unclassified Information (CUI) in accordance with approved authorizations. This involves defining policies and methods for information flow, identifying sources and destinations, and enforcing authorized controls.
Separate the duties of individuals to reduce the risk of malevolent activity without collusion. This involves defining duties requiring separation, assigning responsibilities, and granting access privileges to separate individuals.
Employ the principle of least privilege, including for specific security functions and privileged accounts. This involves identifying privileged accounts, authorizing access based on the principle of least privilege, and ensuring access is limited accordingly.
Use non-privileged accounts or roles when accessing nonsecurity functions. This involves identifying nonsecurity functions and ensuring users are required to use non-privileged accounts.
Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs. This involves defining and protecting privileged functions and ensuring traceability through audit logs.
Monitor and control remote access sessions. This involves identifying permitted types of remote access, controlling access sessions, and monitoring them for compliance.
Employ cryptographic mechanisms to protect the confidentiality of remote access sessions. This involves using validated cryptography for securing remote connections.
Create and retain system audit logs and records to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity. This involves defining event types, ensuring audit records are created, and retaining them as necessary.
Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions. This involves defining the content of audit records and ensuring their traceability.
Alert in the event of an audit logging process failure. This involves identifying alert recipients, defining failure types, and ensuring alerts are triggered when failures occur.
Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity. This involves ensuring integration across different audit repositories.
Protect audit information and audit logging tools from unauthorized access, modification, and deletion. This involves ensuring only authorized individuals have access and implementing safeguards.
Develop and maintain an operational plan of action to identify and address temporary vulnerabilities and deficiencies in security implementations.
Monitor security controls on an ongoing basis to ensure they remain effective in mitigating risks.
Establish and maintain baseline configurations and inventories of organizational systems throughout their lifecycle to ensure consistency and accountability.
Establish and enforce security configuration settings for IT products to meet organizational security requirements.
Track, review, approve or disapprove, and log changes to organizational systems to ensure security impacts are analyzed and addressed.
Employ the principle of least functionality by configuring systems to provide only essential capabilities and disabling unnecessary features.
Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.
Control and monitor user-installed software to prevent unauthorized or insecure applications from being used.
Identify users, processes, and devices accessing organizational systems to ensure access is authorized.
Authenticate users, processes, and devices accessing systems to verify their identities.
Implement multifactor authentication for access to systems, ensuring users provide multiple forms of identity verification.
Disable identifiers after a defined period of inactivity.
Enforce password complexity requirements to enhance security against unauthorized access attempts.
Restrict password reuse to prevent vulnerabilities from compromised credentials being reused.
Store and transmit only cryptographically-protected passwords.
Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.
Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.
Conduct vulnerability scans to identify potential security weaknesses in systems and remediate them promptly.
Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems.
Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.
Restrict access to shared resources to prevent unauthorized access to system functions or data.
Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.
Manage cryptographic keys securely to ensure they are protected from unauthorized access or misuse.
Ensure the authenticity of communications to prevent impersonation and data tampering.
Protect data at rest using cryptographic techniques to prevent unauthorized access.
Identify, report, and remediate software flaws and vulnerabilities promptly to ensure system integrity.
Implement mechanisms to detect and protect against malicious code, including antivirus and other threat detection tools.
Conduct regular system and file scans to detect and remediate threats or vulnerabilities.
Disseminate security alerts and advisories to inform personnel of potential threats or vulnerabilities.
Monitor communications for attack patterns or indicators of compromise to prevent security incidents.
Detect and respond to unauthorized system use to prevent data breaches and security incidents.
See where you stand against any framework
Connect an account and get a full compliance breakdown with mapped findings and remediation guidance — free to start.
