Compliance, Mapped to Your Cloud

Assess your AWS, Azure, and Google Cloud environments against the industry frameworks and regulations your auditors expect.

56
Frameworks Supported
18
Standards Families
3
Cloud Providers
5 min
To First Results
ASecureCloud compliance report preview
AWS logo

NIST CSF

41 controls
132 checks mapped

The NIST Cybersecurity Framework (CSF) organizes security activities around its core functions — Identify, Protect, Detect, Respond, and Recover.

Controls assessed

Detect (DE) - Anomalies and Events (DE.AE) - DE.AE-116

A baseline of network operations and expected data flows for users and systems is established and managed.

Detect (DE) - Anomalies and Events (DE.AE) - DE.AE-22

Detected events are analyzed to understand attack targets and methods.

Detect (DE) - Anomalies and Events (DE.AE) - DE.AE-311

Event data are collected and correlated from multiple sources and sensors.

Detect (DE) - Anomalies and Events (DE.AE) - DE.AE-49

Impact of events is determined.

Detect (DE) - Anomalies and Events (DE.AE) - DE.AE-53

Incident alert thresholds are established.

Detect (DE) - Security Continuous Monitoring (DE.CM) - DE.CM-114

The network is monitored to detect potential cybersecurity events.

Detect (DE) - Security Continuous Monitoring (DE.CM) - DE.CM-37

Personnel activity is monitored to detect potential cybersecurity events.

Detect (DE) - Security Continuous Monitoring (DE.CM) - DE.CM-42

Malicious code is detected.

Detect (DE) - Security Continuous Monitoring (DE.CM) - DE.CM-67

External service provider activity is monitored to detect potential cybersecurity events.

Detect (DE) - Security Continuous Monitoring (DE.CM) - DE.CM-714

Monitoring for unauthorized personnel, connections, devices, and software is performed.

Detect (DE) - Detection Processes (DE.DP) - DE.DP-41

Event detection information is communicated.

Detect (DE) - Detection Processes (DE.DP) - DE.DP-51

Detection processes are continuously improved.

Identify (ID) - Asset Management (ID.AM) - ID.AM-27

Software platforms and applications within the organization are inventoried.

Identify (ID) - Asset Management (ID.AM) - ID.AM-313

Organizational communication and data flows are mapped.

Identify (ID) - Asset Management (ID.AM) - ID.AM-66

Cybersecurity roles and responsibilities for the entire workforce and third-party stakeholders (e.g., suppliers, customers, partners) are established.

Identify (ID) - Business Environment (ID.BE) - ID.BE-59

Resilience requirements to support delivery of critical services are established for all operating states (e.g. under duress/attack, during recovery, normal operations)

Identify (ID) - Business Environment (ID.RA) - ID.RA-13

Asset vulnerabilities are identified and documented.

Identify (ID) - Business Environment (ID.RA) - ID.RA-22

Asset vulnerabilities are identified and documented.

Identify (ID) - Business Environment (ID.RA) - ID.RA-32

Asset vulnerabilities are identified and documented.

Protect (PR) - Identity Management and Access Control (PR.AC) - PR.AC-116

Identities and credentials are issued, managed, verified, revoked, and audited for authorized devices, users and processes.

Protect (PR) - Identity Management and Access Control (PR.AC) - PR.AC-328

Remote access is managed.

Protect (PR) - Identity Management and Access Control (PR.AC) - PR.AC-411

Access permissions and authorizations are managed, incorporating the principles of least privilege and separation of duties.

Protect (PR) - Identity Management and Access Control (PR.AC) - PR.AC-526

Network integrity is protected (e.g., network segregation, network segmentation).

Protect (PR) - Identity Management and Access Control (PR.AC) - PR.AC-66

Identities are proofed and bound to credentials and asserted in interactions.

Protect (PR) - Identity Management and Access Control (PR.AC) - PR.AC-73

Users, devices, and other assets are authenticated (e.g., single-factor, multi-factor) commensurate with the risk of the transaction (e.g., individuals’ security and privacy risks and other organizational risks).

Protect (PR) - Data Security (PR.DS) - PR.DS-117

Data-at-rest is protected.

Protect (PR) - Data Security (PR.DS) - PR.DS-24

Data-in-transit is protected.

Protect (PR) - Data Security (PR.DS) - PR.DS-34

Assets are formally managed throughout removal, transfers, and disposition.

Protect (PR) - Data Security (PR.DS) - PR.DS-49

Adequate capacity to ensure availability is maintained.

Protect (PR) - Data Security (PR.DS) - PR.DS-519

Protections against data leaks are implemented.

Protect (PR) - Data Security (PR.DS) - PR.DS-61

Integrity checking mechanisms are used to verify software, firmware, and information integrity.

Protect (PR) - Information Protection Processes and Procedures (PR.IP) - PR.IP-18

A baseline configuration of information technology/industrial control systems is created and maintained incorporating security principles (e.g. concept of least functionality).

Protect (PR) - Information Protection Processes and Procedures (PR.IP) - PR.IP-31

Configuration change control processes are in place.

Protect (PR) - Information Protection Processes and Procedures (PR.IP) - PR.IP-45

Backups of information are conducted, maintained, and tested periodically.

Protect (PR) - Information Protection Processes and Procedures (PR.IP) - PR.IP-71

Protection processes are improved.

Protect (PR) - Maintenance (PR.MA) - PR.MA-22

Remote maintenance of organizational assets is approved, logged, and performed in a manner that prevents unauthorized access.

Protect (PR) - Protective Technology (PR.PT) - PR.PT-17

Audit/log records are determined, documented, implemented, and reviewed in accordance with policy.

Protect (PR) - Protective Technology (PR.PT) - PR.PT-310

Access to systems and assets is controlled, incorporating the principle of least functionality.

Protect (PR) - Protective Technology (PR.PT) - PR.PT-410

Communications and control networks are protected.

Protect (PR) - Protective Technology (PR.PT) - PR.PT-58

Mechanisms (e.g., failsafe, load balancing, hot swap) are implemented to achieve resilience requirements in normal and adverse situations.

Respond (RS) - Analysis (RS.AN) - RS.AN-25

The impact of the incident is understood.

See where you stand against any framework

Connect an account and get a full compliance breakdown with mapped findings and remediation guidance — free to start.