Compliance, Mapped to Your Cloud

Assess your AWS, Azure, and Google Cloud environments against the industry frameworks and regulations your auditors expect.

56
Frameworks Supported
18
Standards Families
3
Cloud Providers
5 min
To First Results
ASecureCloud compliance report preview
AWS logo

FedRAMP Moderate

63 controls
142 checks mapped

FedRAMP standardizes the security assessment, authorization, and continuous monitoring of cloud services used by U.S. federal agencies.

Controls assessed

AC-2(1) ACCOUNT MANAGEMENT | AUTOMATED SYSTEM ACCOUNT MANAGEMENT15

The organization employs automated mechanisms to support the management of information system accounts.

AC-2(4) ACCOUNT MANAGEMENT | AUTOMATED AUDIT ACTIONS12

The information system automatically audits account creation, modification, enabling, disabling, and removal actions, and notifies \[Assignment: organization-defined personnel or roles\].

AC-2(12)(a) ACCOUNT MANAGEMENT | ACCOUNT MONITORING / ATYPICAL USAGE2

The organization: * a. Monitors information system accounts for \[Assignment: organization-defined atypical use\].

AC-2(f) ACCOUNT MANAGEMENT13

The organization: * f. Creates, enables, modifies, disables, and removes information system accounts in accordance with \[Assignment: organization-defined procedures or conditions\].

AC-2(g) ACCOUNT MANAGEMENT14

The organization: * g. Monitors the use of information system accounts.

AC-2(j) ACCOUNT MANAGEMENT24

The organization: * j. Reviews accounts for compliance with account management requirements \[Assignment: organization-defined frequency\].

AC-2(3) ACCOUNT MANAGEMENT | DISABLE INACTIVE ACCOUNTS2

The information system automatically disables inactive accounts after 90 days for user accounts.

AC-3 ACCESS ENFORCEMENT29

The information system enforces approved authorizations for logical access to information and system resources in accordance with applicable access control policies.

AC-4 INFORMATION FLOW ENFORCEMENT29

The information system enforces approved authorizations for controlling the flow of information within the system and between interconnected systems based on \[Assignment: organization-defined information flow control policies\].

AC-5(c) SEPARATION OF DUTIES13

The organization: * c. Defines information system access authorizations to support separation of duties.

AC-6 LEAST PRIVILEGE26

The organization employs the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with organizational missions and business functions.

AC-6(10) LEAST PRIVILEGE | PROHIBIT NON-PRIVILEGED USERS FROM EXECUTING PRIVILEGED FUNCTIONS7

The information system prevents non-privileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures.

AC-17(1) REMOTE ACCESS | AUTOMATED MONITORING / CONTROL33

The information system monitors and controls remote access methods.

AC-17(2) REMOTE ACCESS | PROTECTION OF CONFIDENTIALITY / INTEGRITY USING ENCRYPTION6

The information system implements cryptographic mechanisms to protect the confidentiality and integrity of remote access sessions.

AC-21(b) INFORMATION SHARING30

The organization: * b. Employs \[Assignment: organization-defined automated mechanisms or manual processes\] to assist users in making information sharing/collaboration decisions.

AU-2(a)(d) AUDIT EVENTS13

The organization: * a. Determines that the information system is capable of auditing the following events: Successful and unsuccessful account logon events, account management events, object access, policy change, privilege functions, process tracking, and system events. For Web applications: all administrator activity, authentication checks, authorization checks, data deletions, data access, data changes, and permission changes. * d. Determines that the following events are to be audited within the information system: \[organization-defined subset of the auditable events defined in AU-2 a to be audited continually for each identified event\].

AU-3 CONTENT OF AUDIT RECORDS13

The information system generates audit records containing information that establishes what type of event occurred, when the event occurred, where the event occurred, the source of the event, the outcome of the event, and the identity of any individuals or subjects associated with the event.

AU-6(1)(3) AUDIT REVIEW, ANALYSIS, AND REPORTING | PROCESS INTEGRATION | CORRELATE AUDIT REPOSITORIES17

* (1) The organization employs automated mechanisms to integrate audit review, analysis, and reporting processes to support organizational processes for investigation and response to suspicious activities. * (3) The organization analyzes and correlates audit records across different repositories to gain organization-wide situational awareness.

AU-7(1) AUDIT REDUCTION AND REPORT GENERATION | AUTOMATIC PROCESSING2

The information system provides the capability to process audit records for events of interest based on \[Assignment: organization-defined audit fields within audit records\].

AU-9 PROTECTION OF AUDIT INFORMATION3

The information system protects audit information and audit tools from unauthorized access, modification, and deletion.

AU-9(2) PROTECTION OF AUDIT INFORMATION | AUDIT BACKUP ON SEPARATE PHYSICAL SYSTEMS / COMPONENTS2

The information system backs up audit records at least weekly onto a physically different system or system component than the system or component being audited.

AU-11 AUDIT RECORD RETENTION1

The organization retains audit records for at least 90 days to provide support for after-the-fact investigations of security incidents and to meet regulatory and organizational information retention requirements.

AU-12(a)(c) AUDIT GENERATION13

The information system: * a. Provides audit record generation capability for the auditable events defined in AU-2 a. at all information system and network components where audit capability is deployed/available * c. Generates audit records for the events defined in AU-2 d. with the content defined in AU-3.

CA-7(a)(b) CONTINUOUS MONITORING15

The organization develops a continuous monitoring strategy and implements a continuous monitoring program that includes: * a. Establishment of \[Assignment: organization-defined metrics\] to be monitored; * b. Establishment of \[Assignment: organization-defined frequencies\] for monitoring and \[Assignment: organization-defined frequencies\] for assessments supporting such monitoring

CM-2 BASELINE CONFIGURATION40

The organization develops, documents, and maintains under configuration control, a current baseline configuration of the information system.

CM-7(a) LEAST FUNCTIONALITY2

The organization: * a. Configures the information system to provide only essential capabilities.

CM-8(1) INFORMATION SYSTEM COMPONENT INVENTORY | UPDATES DURING INSTALLATIONS / REMOVALS2

The organization updates the inventory of information system components as an integral part of component installations, removals, and information system updates.

CM-8(3)(a) INFORMATION SYSTEM COMPONENT INVENTORY | AUTOMATED UNAUTHORIZED COMPONENT DETECTION 4

The organization: * a. Employs automated mechanisms continuously, using automated mechanisms with a maximum five-minute delay in detection, to detect the presence of unauthorized hardware, software, and firmware components within the information system

CP-9(b) INFORMATION SYSTEM BACKUP15

The organization: * b. Conducts backups of system-level information contained in the information system (daily incremental; weekly full).

CP-10 INFORMATION SYSTEM RECOVERY AND RECONSTITUTION21

The organization provides for the recovery and reconstitution of the information system to a known state after a disruption, compromise, or failure.

IA-2 IDENTIFICATION AND AUTHENTICATION (ORGANIZATIONAL USERS)2

The information system uniquely identifies and authenticates organizational users (or processes acting on behalf of organizational users).

IA-2(1) IDENTIFICATION AND AUTHENTICATION | NETWORK ACCESS TO PRIVILEGED ACCOUNTS3

(1) The information system implements multifactor authentication for network access to privileged accounts.

IA-2(1)(2) IDENTIFICATION AND AUTHENTICATION | NETWORK ACCESS TO PRIVILEGED ACCOUNTS | NETWORK ACCESS TO NON-PRIVILEGED ACCOUNTS3

* (1) The information system implements multifactor authentication for network access to privileged accounts. * (2) The information system implements multifactor authentication for network access to non- privileged accounts.

IA-5(1)(a)(d)(e) AUTHENTICATOR MANAGEMENT | PASSWORD-BASED AUTHENTICATION1

The information system, for password-based authentication: * a. Enforces minimum password complexity of \[Assignment: organization-defined requirements for case sensitivity, number of characters, mix of upper-case letters, lower-case letters, numbers, and special characters, including minimum requirements for each type\]; * d. Enforces password minimum and maximum lifetime restrictions of \[Assignment: organization- defined numbers for lifetime minimum, lifetime maximum\]; * e. Prohibits password reuse for 24 generations

IA-5(4) AUTHENTICATOR MANAGEMENT | AUTOMATED SUPPORT FOR PASSWORD STRENGTH DETERMINATION1

The organization employs automated tools to determine if password authenticators are sufficiently strong to satisfy \[Assignment: organization-defined requirements\].

IA-5(7) AUTHENTICATOR MANAGEMENT | NO EMBEDDED UNENCRYPTED STATIC AUTHENTICATORS1

The organization ensures that unencrypted static authenticators are not embedded in applications or access scripts or stored on function keys.

IR-4(1) INCIDENT HANDLING | AUTOMATED INCIDENT HANDLING PROCESSES5

The organization employs automated mechanisms to support the incident handling process.

IR-6(1) INCIDENT REPORTING | AUTOMATED REPORTING3

The organization employs automated mechanisms to assist in the reporting of security incidents.

IR-7(1) INCIDENT RESPONSE ASSISTANCE | AUTOMATION SUPPORT FOR AVAILABILITY OF INFORMATION / SUPPORT3

The organization employs automated mechanisms to increase the availability of incident response-related information and support.

RA-5 VULNERABILITY SCANNING2

The organization: * a. Scans for vulnerabilities in the information system and hosted applications monthly \[operating system/infrastructure; monthly web applications and databases\] and when new vulnerabilities potentially affecting the system/applications are identified and reported; * b. Employs vulnerability scanning tools and techniques that facilitate interoperability among tools and automate parts of the vulnerability management process by using standards for: 1. Enumerating platforms, software flaws, and improper configurations; 2. Formatting checklists and test procedures; and 3. Measuring vulnerability impact; * c. Analyzes vulnerability scan reports and results from security control assessments; * d. Remediates legitimate vulnerabilities: high-risk vulnerabilities mitigated within thirty (30) days from date of discovery; moderate-risk vulnerabilities mitigated within ninety (90) days from date of discovery; low risk vulnerabilities mitigated within one hundred and eighty (180) days from date of discovery, in accordance with an organizational assessment of risk; * e. Shares information obtained from the vulnerability scanning process and security control assessments with \[Assignment: organization-defined personnel or roles\] to help eliminate similar vulnerabilities in other information systems (i.e., systemic weaknesses or deficiencies).

SA-3(a) SYSTEM DEVELOPMENT LIFE CYCLE3

The organization: * a. Manages the information system using \[Assignment: organization-defined system development life cycle\] that incorporates information security considerations.

SA-10 DEVELOPER CONFIGURATION MANAGEMENT4

The organization requires the developer of the information system, system component, or information system service to: * a. Perform configuration management during system, component, or service development, implementation, AND operation; * b. Document, manage, and control the integrity of changes to \[Assignment: organization-defined configuration items under configuration management\]; * c. Implement only organization-approved changes to the system, component, or service; * d. Document approved changes to the system, component, or service and the potential security impacts of such changes; * e. Track security flaws and flaw resolution within the system, component, or service and report findings to \[Assignment: organization-defined personnel\].

SC-2 APPLICATION PARTITIONING6

The information system separates user functionality (including user interface services) from information system management functionality.

SC-4 INFORMATION IN SHARED RESOURCES27

The information system prevents unauthorized and unintended information transfer via shared system resources.

SC-5 DENIAL OF SERVICE PROTECTION13

The information system protects against or limits the effects of the following types of denial of service attacks: \[Assignment: organization-defined types of denial of service attacks or references to sources for such information\] by employing \[Assignment: organization-defined security safeguards\].

SC-7 BOUNDARY PROTECTION39

The information system: * a. Monitors and controls communications at the external boundary of the system and at key internal boundaries within the system; * b. Implements subnetworks for publicly accessible system components that are \[Selection: physically; logically\] separated from internal organizational networks; * c. Connects to external networks or information systems only through managed interfaces consisting of boundary protection devices arranged in accordance with an organizational security architecture.

SC-7(3) BOUNDARY PROTECTION | ACCESS POINTS32

The organization limits the number of external network connections to the information system.

SC-8 TRANSMISSION CONFIDENTIALITY AND INTEGRITY7

The information system protects the confidentiality AND integrity of transmitted information.

SC-8(1) TRANSMISSION CONFIDENTIALITY AND INTEGRITY | CRYPTOGRAPHIC OR ALTERNATE PHYSICAL PROTECTION7

The information system implements cryptographic mechanisms to \[Selection (one or more): prevent unauthorized disclosure of information; detect changes to information\] during transmission unless otherwise protected by \[Assignment: organization-defined alternative physical safeguards\].

SC-12 CRYPTOGRAPHIC KEY ESTABLISHMENT AND MANAGEMENT3

The organization establishes and manages cryptographic keys for required cryptography employed within the information system in accordance with \[Assignment: organization-defined requirements for key generation, distribution, storage, access, and destruction\].

SC-13 CRYPTOGRAPHIC PROTECTION7

The information system implements FIPS-validated or NSA-approved cryptography in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.

SC-23 SESSION AUTHENTICITY7

The information system protects the authenticity of communications sessions.

SC-28 PROTECTION OF INFORMATION AT REST | CRYPTOGRAPHIC PROTECTION18

The information system protects the confidentiality AND integrity of \[Assignment: organization-defined information at rest\].

SI-2(2) FLAW REMEDIATION | AUTOMATED FLAW REMEDIATION STATUS3

The organization employs automated mechanisms at least monthly to determine the state of information system components with regard to flaw remediation.

SI-4(1) INFORMATION SYSTEM MONITORING | SYSTEM-WIDE INTRUSION DETECTION SYSTEM1

The organization connects and configures individual intrusion detection tools into an information system-wide intrusion detection system.

SI-4(16) INFORMATION SYSTEM MONITORING | CORRELATE MONITORING INFORMATION8

The organization correlates information from monitoring tools employed throughout the information system.

SI-4(2) INFORMATION SYSTEM MONITORING | AUTOMATED TOOLS FOR REAL-TIME ANALYSIS10

The organization employs automated tools to support near real-time analysis of events.

SI-4(4) INFORMATION SYSTEM MONITORING | INBOUND AND OUTBOUND COMMUNICATIONS TRAFFIC4

The information system monitors inbound and outbound communications traffic continuously for unusual or unauthorized activities or conditions.

SI-4(5) INFORMATION SYSTEM MONITORING | SYSTEM-GENERATED ALERTS4

The information system alerts \[Assignment: organization-defined personnel or roles\] when the following indications of compromise or potential compromise occur: \[Assignment: organization- defined compromise indicators\].

SI-4(a)(b)(c) INFORMATION SYSTEM MONITORING9

The organization: * a. Monitors the information system to detect: 1. Attacks and indicators of potential attacks in accordance with \[Assignment: organization- defined monitoring objectives\]; and 2. Unauthorized local, network, and remote connections; * b. Identifies unauthorized use of the information system through \[Assignment: organization- defined techniques and methods\]; * c. Deploys monitoring devices: i. strategically within the information system to collect organization-determined essential information; and (ii) at ad hoc locations within the system to track specific types of transactions of interest to the organization.

SI-7 SOFTWARE, FIRMWARE, AND INFORMATION INTEGRITY1

The organization employs integrity verification tools to detect unauthorized changes to \[Assignment: organization-defined software, firmware, and information\].

SI-7(1) SOFTWARE, FIRMWARE, AND INFORMATION INTEGRITY | INTEGRITY CHECKS3

The information system performs an integrity check security relevant events at least monthly.

SI-12 INFORMATION HANDLING AND RETENTION15

The organization handles and retains information within the information system and information output from the system in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and operational requirements.

See where you stand against any framework

Connect an account and get a full compliance breakdown with mapped findings and remediation guidance — free to start.