Compliance, Mapped to Your Cloud
Assess your AWS, Azure, and Google Cloud environments against the industry frameworks and regulations your auditors expect.

NIST CSF
The NIST Cybersecurity Framework (CSF) organizes security activities around its core functions — Identify, Protect, Detect, Respond, and Recover.
Controls assessed
A baseline of network operations and expected data flows for users and systems is established and managed.
Detected events are analyzed to understand attack targets and methods.
Event data are collected and correlated from multiple sources and sensors.
Impact of events is determined.
Incident alert thresholds are established.
The network is monitored to detect potential cybersecurity events.
Personnel activity is monitored to detect potential cybersecurity events.
Malicious code is detected.
External service provider activity is monitored to detect potential cybersecurity events.
Monitoring for unauthorized personnel, connections, devices, and software is performed.
Event detection information is communicated.
Detection processes are continuously improved.
Software platforms and applications within the organization are inventoried.
Organizational communication and data flows are mapped.
Cybersecurity roles and responsibilities for the entire workforce and third-party stakeholders (e.g., suppliers, customers, partners) are established.
Resilience requirements to support delivery of critical services are established for all operating states (e.g. under duress/attack, during recovery, normal operations)
Asset vulnerabilities are identified and documented.
Asset vulnerabilities are identified and documented.
Asset vulnerabilities are identified and documented.
Identities and credentials are issued, managed, verified, revoked, and audited for authorized devices, users and processes.
Remote access is managed.
Access permissions and authorizations are managed, incorporating the principles of least privilege and separation of duties.
Network integrity is protected (e.g., network segregation, network segmentation).
Identities are proofed and bound to credentials and asserted in interactions.
Users, devices, and other assets are authenticated (e.g., single-factor, multi-factor) commensurate with the risk of the transaction (e.g., individuals’ security and privacy risks and other organizational risks).
Data-at-rest is protected.
Data-in-transit is protected.
Assets are formally managed throughout removal, transfers, and disposition.
Adequate capacity to ensure availability is maintained.
Protections against data leaks are implemented.
Integrity checking mechanisms are used to verify software, firmware, and information integrity.
A baseline configuration of information technology/industrial control systems is created and maintained incorporating security principles (e.g. concept of least functionality).
Configuration change control processes are in place.
Backups of information are conducted, maintained, and tested periodically.
Protection processes are improved.
Remote maintenance of organizational assets is approved, logged, and performed in a manner that prevents unauthorized access.
Audit/log records are determined, documented, implemented, and reviewed in accordance with policy.
Access to systems and assets is controlled, incorporating the principle of least functionality.
Communications and control networks are protected.
Mechanisms (e.g., failsafe, load balancing, hot swap) are implemented to achieve resilience requirements in normal and adverse situations.
The impact of the incident is understood.
See where you stand against any framework
Connect an account and get a full compliance breakdown with mapped findings and remediation guidance — free to start.
