Compliance, Mapped to Your Cloud

Assess your AWS, Azure, and Google Cloud environments against the industry frameworks and regulations your auditors expect.

56
Frameworks Supported
18
Standards Families
3
Cloud Providers
5 min
To First Results
ASecureCloud compliance report preview
AWS logo

NIST 800-53

65 controls
121 checks mapped

NIST SP 800-53 provides a comprehensive catalog of security and privacy controls for federal information systems and the organizations that operate them.

Controls assessed

Access Control (AC) - Account Management (AC-2)27

Manage system accounts, group memberships, privileges, workflow, notifications, deactivations, and authorizations.

Access Control (AC) - Account Management (AC-2) - AC-2(1) Automated System Account Management13

The organization employs automated mechanisms to support the management of information system accounts.

Access Control (AC) - Account Management (AC-2) - AC-2(3) Disable Inactive Accounts1

The information system automatically disables inactive accounts after 90 days for user accounts.

Access Control (AC) - Account Management (AC-2) - AC-2(4) Automated Audit Actions9

The information system automatically audits account creation, modification, enabling, disabling, and removal actions, and notifies \[Assignment: organization-defined personnel or roles\].

Access Control (AC) - Account Management (AC-2) - AC-2(12) Account Monitoring2

Monitors and reports atypical usage of information system accounts to organization-defined personnel or roles.

Access Control (AC) - Access Enforcement (AC-3)17

The information system enforces approved authorizations for logical access to information and system resources in accordance with applicable access control policies.

Access Control (AC) - Information Flow Enforcement (AC-4)26

The information system enforces approved authorizations for controlling the flow of information within the system and between interconnected systems based on organization-defined information flow control policies.

Access Control (AC) - Separation Of Duties (AC-5)4

Separate duties of individuals to prevent malevolent activity. automate separation of duties and access authorizations.

Access Control (AC) - Least Privilege (AC-6)22

The organization employs the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with organizational missions and business functions.

Access Control (AC) - Least Privilege (AC-6) - AC-6(10) Prohibit Non-Privileged Users From Executing Privileged Functions3

The information system prevents non-privileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures.

Access Control (AC) - Remote Access (AC-17) - AC-17(1) Automated Monitoring/Control2

The information system monitors and controls remote access methods.

Access Control (AC) - Remote Access (AC-17) - AC-17(2) Protection Of Confidentiality/Integrity Using Encryption7

The information system implements cryptographic mechanisms to protect the confidentiality and integrity of remote access sessions.

Access Control (AC) - Remote Access (AC-17) - AC-17(3) Managed Access Control Points1

The information system routes all remote accesses through organization-defined managed network access control points.

Access Control (AC) - Information Sharing (AC-21)13

Facilitate information sharing. Enable authorized users to grant access to partners.

Audit and Accountability (AU) - Event Logging (AU-2)13

Automate security audit function with other organizational entities. Enable mutual support of audit of auditable events.

Audit and Accountability (AU) - Content of Audit Records (AU-3)13

The information system generates audit records containing information that establishes what type of event occurred, when the event occurred, where the event occurred, the source of the event, the outcome of the event, and the identity of any individuals or subjects associated with the event.

Audit and Accountability (AU) - Audit Review, Analysis And Reporting (AU-6) - AU-6(1) Process Integration4

The organization employs automated mechanisms to integrate audit review, analysis,and reporting processes to support organizational processes for investigation and response to suspicious activities.

Audit and Accountability (AU) - Audit Review, Analysis And Reporting (AU-6) - AU-6(3) Correlate Audit Repositories4

The organization analyzes and correlates audit records across different repositories to gain organization-wide situational awareness.

Audit and Accountability (AU) - Audit Reduction And Report Generation (AU-7) - AU-7(1) Automatic Processing2

The information system provides the capability to process audit records for events of interest based on \[Assignment: organization-defined audit fields within audit records\].

Audit and Accountability (AU) - Protection of Audit Information (AU-9)2

The information system protects audit information and audit tools from unauthorized access, modification, and deletion.

Audit and Accountability (AU) - Protection of Audit Information (AU-9) - AU-9(2) Audit Backup On Separate Physical Systems / Components1

The information system backs up audit records \[Assignment: organization-defined frequency\] onto a physically different system or system component than the system or component being audited.

Audit and Accountability (AU) - Audit Record Retention (AU-11)1

The organization retains audit records for \[Assignment: organization-defined time period consistent with records retention policy\] to provide support for after-the-fact investigations of security incidents and to meet regulatory and organizational information retention requirements.

Audit and Accountability (AU) - Audit Generation (AU-12)13

Audit events defined in AU-2. Allow trusted personnel to select which events to audit. Generate audit records for events.

Security Assessment And Authorization (CA) - Continuous Monitoring (CA-7)6

Continuously monitor configuration management processes. Determine security impact, environment and operational risks.

Configuration Management (CM) - Baseline Configuration (CM-2)16

The organization develops, documents, and maintains under configuration control, a current baseline configuration of the information system.

Configuration Management (CM) - Least Functionality (CM-7)2

The organization configures the information system to provide only essential capabilities and prohibits or restricts the use of the functions, ports, protocols, and/or services.

Configuration Management (CM) - Information System Component Inventory (CM-8) - CM-8(1) Updates During Installation / Removals1

The organization updates the inventory of information system components as an integral part of component installations, removals, and information system updates.

Configuration Management (CM) - Information System Component Inventory (CM-8) - CM-8(3) Automated Unauthorized Component Detection3

The organization employs automated mechanisms to detect the presence of unauthorized hardware, software, and firmware components within the information system and takes actions (disables network access by such components, isolates the components etc) when unauthorized components are detected.

Contingency Planning (CP) - Information System Backup (CP-9)11

The organization conducts backups of user-level information, system-level information and information system documentation including security-related documentation contained in the information system and protects the confidentiality, integrity, and availability of backup information at storage locations.

Contingency Planning (CP) - Information System Recovery And Reconstitution (CP-10)17

The organization provides for the recovery and reconstitution of the information system to a known state after a disruption, compromise, or failure.

Identification and Authentication (IA) - Identification and Authentication (Organizational users) (IA-2)7

The information system uniquely identifies and authenticates organizational users (or processes acting on behalf of organizational users).

Identification and Authentication (IA) - Identification and Authentication (Organizational users) (IA-2) - IA-2(1) Network Access To Privileged Accounts3

The information system implements multi-factor authentication for network access to privileged accounts.

Identification and Authentication (IA) - Identification and Authentication (Organizational users) (IA-2) - IA-2(2) Network Access To Non-Privileged Accounts1

The information system implements multifactor authentication for network access to non-privileged accounts.

Identification and Authentication (IA) - Identification and Authentication (Organizational users) (IA-2) - IA-2(11) Remote Access - Separate3

The information system implements multifactor authentication for remote access to privileged and non-privileged accounts such that one of the factors is provided by a device separate from the system gaining access and the device meets \[Assignment: organization-defined strength of mechanism requirements\].

Identification and Authentication (IA) - IA-5(1) Password-Based Authentication7

The information system, for password-based authentication that enforces minimum password complexity, stores and transmits only cryptographically-protected passwords, enforces password minimum and maximum lifetime restrictions, prohibits password reuse, allows the use of a temporary password for system logons with an immediate change to a permanent password etc.

Identification and Authentication (IA) - IA-5(4) Automated Support For Password Strength Determination7

The organization employs automated tools to determine if password authenticators are sufficiently strong to satisfy \[Assignment: organization-defined requirements\].

Identification and Authentication (IA) - IA-5(7) No Embedded Unencrypted Static Authenticators1

The organization ensures that unencrypted static authenticators are not embedded in applications or access scripts or stored on function keys.

Incident Response (IR) - Incident Handling (IR-4) - IR-4(1) Automated Incident Handling Processes2

The organization employs automated mechanisms to support the incident handling process.

Incident Response (IR) - Incident Reporting (IR-6) - IR-6(1) Automated Reporting1

The organization report suspected security incidents to the organizational incident response capability within organization-defined time period.

Incident Response (IR) - Incident Response Assistance (IR-7) - IR-7(1) Automation Support For Availability Of Information / Support1

The organization employs automated mechanisms to increase the availability of incident response-related information and support.

Risk Assessment (RA) - Vulnerability Scanning (RA-5)2

Scan for system vulnerabilities. Share vulnerability information and security controls that eliminate vulnerabilities.

System and Services Acquisition (SA) - System Development Life Cycle (SA-3)3

The organization manages the information system using organization-defined system development life cycle, defines and documents information security roles and responsibilities throughout the system development life cycle, identifies individuals having information security roles and responsibilities and integrates the organizational information security risk management process into system development life cycle activities.

System and Services Acquisition (SA) - Developer Configuration Management (SA-10)4

The organization requires the developer of the information system, system component, or information system service to: a. Perform configuration management during system, component, or service \[Selection (one or more): design; development; implementation; operation\]; b. Document, manage, and control the integrity of changes to \[Assignment: organization-defined configuration items under configuration management\]; c. Implement only organization-approved changes to the system, component, or service; d. Document approved changes to the system, component, or service and the potential security impacts of such changes; and e. Track security flaws and flaw resolution within the system, component, or service and report findings to \[Assignment: organization-defined personnel\].

System and Communications Protection (SC) - Application Partitioning (SC-2)2

The information system separates user functionality (including user interface services) from information system management functionality.

System and Communications Protection (SC) - Information In Shared Resources (SC-4)1

The information system prevents unauthorized and unintended information transfer via shared system resources.

System and Communications Protection (SC) - Denial Of Service Protection (SC-5)6

The information system protects against or limits the effects of the following types of denial of service attacks: \[Assignment: organization-defined types of denial of service attacks or references to sources for such information\] by employing \[Assignment: organization-defined security safeguards\].

System and Communications Protection (SC) - Boundary Protection (SC-7)33

The information system: a. Monitors and controls communications at the external boundary of the system and at key internal boundaries within the system; b. Implements subnetworks for publicly accessible system components that are \[Selection: physically; logically\] separated from internal organizational networks; and c. Connects to external networks or information systems only through managed interfaces consisting of boundary protection devices arranged in accordance with an organizational security architecture.

System and Communications Protection (SC) - Boundary Protection (SC-7) - SC-7(3) Access Points24

The organization limits the number of external network connections to the information system.

System and Communications Protection (SC) - Transmission Confidentiality And Integrity (SC-8)7

The information system protects the \[Selection (one or more): confidentiality; integrity\] of transmitted information.

System and Communications Protection (SC) - Transmission Confidentiality And Integrity (SC-8) - SC-8(1) Cryptographic Or Alternate Physical Protection7

The information system implements cryptographic mechanisms to \[Selection (one or more): prevent unauthorized disclosure of information; detect changes to information\] during transmission unless otherwise protected by \[Assignment: organization-defined alternative physical safeguards\].

System and Communications Protection (SC) - Cryptographic Key Establishment And Management (SC-12)3

The organization establishes and manages cryptographic keys for required cryptography employed within the information system in accordance with \[Assignment: organization-defined requirements for key generation, distribution, storage, access, and destruction\].

System and Communications Protection (SC) - Cryptographic Protection (SC-13)17

The information system implements \[Assignment: organization-defined cryptographic uses and type of cryptography required for each use\] in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.

System and Communications Protection (SC) - Session Authenticity (SC-23)3

TThe information system protects the authenticity of communications sessions.

System and Communications Protection (SC) - Protection Of Information At Rest (SC-28)17

The information system protects the \[Selection (one or more): confidentiality; integrity\] of \[Assignment: organization-defined information at rest\].

SC-362
System and Information integrity (SI) - Flaw Remediation (SI-2) - SI-2(2) Automates Flaw Remediation Status3

The organization employs automated mechanisms to determine the state of information system components with regard to flaw remediation.

System and Information integrity (SI) - Information System Monitoring (SI-4)8

The organization: a.Monitors the information system to detect: 1. Attacks and indicators of potential attacks in accordance with \[Assignment: organization-defined monitoring objectives\]; and 2.Unauthorized local, network, and remote connections; b. Identifies unauthorized use of the information system through \[Assignment: organization-defined techniques and methods\]; c. Deploys monitoring devices: 1. Strategically within the information system to collect organization-determined essential information; and 2. At ad hoc locations within the system to track specific types of transactions of interest to the organization; d. Protects information obtained from intrusion-monitoring tools from unauthorized access, modification, and deletion; e. Heightens the level of information system monitoring activity whenever there is an indication of increased risk to organizational operations and assets, individuals, other organizations, or the Nation based on law enforcement information, intelligence information, or other credible sources of information; f. Obtains legal opinion with regard to information system monitoring activities in accordance with applicable federal laws, Executive Orders, directives, policies, or regulations; and g. Provides \[Assignment: organization-defined information system monitoring information\] to \[Assignment: organization-defined personnel or roles\] \[Selection (one or more): as needed; \[Assignment: organization-defined frequency\]\].

System and Information integrity (SI) - Information System Monitoring (SI-4) - SI-4(1) System-Wide Intrusion Detection System1

The organization connects and configures individual intrusion detection tools into an information system-wide intrusion detection system.

System and Information integrity (SI) - Information System Monitoring (SI-4) - SI-4(2) Automated Tools For Real-Time Analysis5

The organization employs automated tools to support near real-time analysis of events.

System and Information integrity (SI) - Information System Monitoring (SI-4) - SI-4(4) Inbound and Outbound Communications Traffic4

The information system monitors inbound and outbound communications traffic continuously for unusual or unauthorized activities or conditions.

System and Information integrity (SI) - Information System Monitoring (SI-4) - SI-4(5) System-Generated Alerts4

The information system alerts organization-defined personnel or roles when the following indications of compromise or potential compromise occur: \[Assignment: organization-defined compromise indicators\].

System and Information integrity (SI) - Information System Monitoring (SI-4) - SI-4(16) Correlate Monitoring Information2

The organization correlates information from monitoring tools employed throughout the information system.

System and Information integrity (SI) - Software, Firmware, and Information Integrity (SI-7)1

The organization employs integrity verification tools to detect unauthorized changes to \[Assignment: organization-defined software, firmware, and information\].

System and Information integrity (SI) - Software, Firmware, and Information Integrity (SI-7) - SI-7(1) Integrity Checks3

The information system performs an integrity check of security relevant events at least monthly.

System and Information integrity (SI) - Information Handling and Retention (SI-12)12

The organization handles and retains information within the information system and information output from the system in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and operational requirements.

See where you stand against any framework

Connect an account and get a full compliance breakdown with mapped findings and remediation guidance — free to start.