Compliance, Mapped to Your Cloud

Assess your AWS, Azure, and Google Cloud environments against the industry frameworks and regulations your auditors expect.

56
Frameworks Supported
18
Standards Families
3
Cloud Providers
5 min
To First Results
ASecureCloud compliance report preview
AWS logo

CMMC 2.0 Level 2

46 controls
119 checks mapped

The Cybersecurity Maturity Model Certification (CMMC) verifies the safeguards protecting Federal Contract Information and CUI across the defense supply chain.

Controls assessed

AC.L1-3.1.1 – Access Control – Authorized Access Control35

Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems). This involves identifying authorized users, processes, and devices and ensuring system access is limited accordingly.

AC.L1-3.1.2 – Access Control – Transaction & Function Control35

Limit system access to the types of transactions and functions that authorized users are permitted to execute. This involves defining types of transactions and functions for users and ensuring system access aligns with these definitions.

AC.L1-3.1.20 – Access Control – External Connections16

Verify and control/limit connections to and use of external systems. This includes identifying connections to external systems, verifying their use, and ensuring they are controlled and limited as defined.

AC.L2-3.1.3 – Access Control – Control CUI Flow23

Control the flow of Controlled Unclassified Information (CUI) in accordance with approved authorizations. This involves defining policies and methods for information flow, identifying sources and destinations, and enforcing authorized controls.

AC.L2-3.1.4 – Access Control – Separation of Duties8

Separate the duties of individuals to reduce the risk of malevolent activity without collusion. This involves defining duties requiring separation, assigning responsibilities, and granting access privileges to separate individuals.

AC.L2-3.1.5 – Access Control – Least Privilege23

Employ the principle of least privilege, including for specific security functions and privileged accounts. This involves identifying privileged accounts, authorizing access based on the principle of least privilege, and ensuring access is limited accordingly.

AC.L2-3.1.6 – Access Control – Non-Privileged Account Use8

Use non-privileged accounts or roles when accessing nonsecurity functions. This involves identifying nonsecurity functions and ensuring users are required to use non-privileged accounts.

AC.L2-3.1.7 – Access Control – Privileged Functions17

Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs. This involves defining and protecting privileged functions and ensuring traceability through audit logs.

AC.L2-3.1.12 – Access Control – Control Remote Access4

Monitor and control remote access sessions. This involves identifying permitted types of remote access, controlling access sessions, and monitoring them for compliance.

AC.L2-3.1.13 – Access Control – Remote Access Confidentiality6

Employ cryptographic mechanisms to protect the confidentiality of remote access sessions. This involves using validated cryptography for securing remote connections.

AU.L2-3.3.1 – Audit and Accountability – System Auditing11

Create and retain system audit logs and records to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity. This involves defining event types, ensuring audit records are created, and retaining them as necessary.

AU.L2-3.3.2 – Audit and Accountability – User Accountability10

Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions. This involves defining the content of audit records and ensuring their traceability.

AU.L2-3.3.4 – Audit and Accountability – Audit Failure Alerting4

Alert in the event of an audit logging process failure. This involves identifying alert recipients, defining failure types, and ensuring alerts are triggered when failures occur.

AU.L2-3.3.5 – Audit and Accountability – Audit Correlation2

Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity. This involves ensuring integration across different audit repositories.

AU.L2-3.3.8 – Audit and Accountability – Audit Protection9

Protect audit information and audit logging tools from unauthorized access, modification, and deletion. This involves ensuring only authorized individuals have access and implementing safeguards.

CA.L2-3.12.2 – Security Assessment – Operational Plan of Action2

Develop and maintain an operational plan of action to identify and address temporary vulnerabilities and deficiencies in security implementations.

CA.L2-3.12.3 – Security Assessment – Security Control Monitoring2

Monitor security controls on an ongoing basis to ensure they remain effective in mitigating risks.

CM.L2-3.4.1 – Configuration Management – System Baselining5

Establish and maintain baseline configurations and inventories of organizational systems throughout their lifecycle to ensure consistency and accountability.

CM.L2-3.4.2 – Configuration Management – Security Configuration Enforcement11

Establish and enforce security configuration settings for IT products to meet organizational security requirements.

CM.L2-3.4.3 – Configuration Management – System Change Management13

Track, review, approve or disapprove, and log changes to organizational systems to ensure security impacts are analyzed and addressed.

CM.L2-3.4.6 – Configuration Management – Least Functionality22

Employ the principle of least functionality by configuring systems to provide only essential capabilities and disabling unnecessary features.

CM.L2-3.4.7 – Configuration Management – Nonessential Functionality15

Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.

CM.L2-3.4.9 – Configuration Management – User-Installed Software3

Control and monitor user-installed software to prevent unauthorized or insecure applications from being used.

IA.L1-3.5.1 – Identification and Authentication – Identification10

Identify users, processes, and devices accessing organizational systems to ensure access is authorized.

IA.L1-3.5.2 – Identification and Authentication – Authentication11

Authenticate users, processes, and devices accessing systems to verify their identities.

IA.L2-3.5.3 – Identification and Authentication – Multifactor Authentication3

Implement multifactor authentication for access to systems, ensuring users provide multiple forms of identity verification.

IA.L2-3.5.6 – Identification and Authentication – Identifier Handling1

Disable identifiers after a defined period of inactivity.

IA.L2-3.5.7 – Identification and Authentication – Password Complexity6

Enforce password complexity requirements to enhance security against unauthorized access attempts.

IA.L2-3.5.8 – Identification and Authentication – Password Reuse1

Restrict password reuse to prevent vulnerabilities from compromised credentials being reused.

IA.L2-3.5.10 – Identification and Authentication – Cryptographically-Protected Passwords18

Store and transmit only cryptographically-protected passwords.

IR.L2-3.6.1 – Incident Response – Incident Handling4

Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.

MA.L2-3.7.5 – Maintenance – Nonlocal Maintenance1

Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.

RA.L2-3.11.2 – Risk Assessment – Vulnerability Scan4

Conduct vulnerability scans to identify potential security weaknesses in systems and remediate them promptly.

SC.L1-3.13.1 – System and Communications Protection – Boundary Protection28

Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems.

SC.L2-3.13.2 – System and Communications Protection – Security Engineering44

Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.

SC.L2-3.13.4 – System and Communications Protection – Shared Resource Control14

Restrict access to shared resources to prevent unauthorized access to system functions or data.

SC.L2-3.13.8 – System and Communications Protection – Data in Transit7

Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.

SC.L2-3.13.10 – System and Communications Protection – Key Management2

Manage cryptographic keys securely to ensure they are protected from unauthorized access or misuse.

SC.L2-3.13.15 – System and Communications Protection – Communications Authenticity3

Ensure the authenticity of communications to prevent impersonation and data tampering.

SC.L2-3.13.16 – System and Communications Protection – Data at Rest14

Protect data at rest using cryptographic techniques to prevent unauthorized access.

SI.L1-3.14.1 – System and Information Integrity – Flaw Remediation3

Identify, report, and remediate software flaws and vulnerabilities promptly to ensure system integrity.

SI.L1-3.14.2 – System and Information Integrity – Malicious Code Protection1

Implement mechanisms to detect and protect against malicious code, including antivirus and other threat detection tools.

SI.L1-3.14.5 – System and Information Integrity – System & File Scanning1

Conduct regular system and file scans to detect and remediate threats or vulnerabilities.

SI.L2-3.14.3 – System and Information Integrity – Security Alerts & Advisories9

Disseminate security alerts and advisories to inform personnel of potential threats or vulnerabilities.

SI.L2-3.14.6 – System and Information Integrity – Monitor Communications for Attacks8

Monitor communications for attack patterns or indicators of compromise to prevent security incidents.

SI.L2-3.14.7 – System and Information Integrity – Identify Unauthorized Use13

Detect and respond to unauthorized system use to prevent data breaches and security incidents.

See where you stand against any framework

Connect an account and get a full compliance breakdown with mapped findings and remediation guidance — free to start.