Compliance, Mapped to Your Cloud

Assess your AWS, Azure, and Google Cloud environments against the industry frameworks and regulations your auditors expect.

56
Frameworks Supported
18
Standards Families
3
Cloud Providers
5 min
To First Results
ASecureCloud compliance report preview
AWS logo

NIST CSF v2.0

71 controls
173 checks mapped

The NIST Cybersecurity Framework (CSF) organizes security activities around its core functions — Identify, Protect, Detect, Respond, and Recover.

Controls assessed

Detect (DE) - Continuous Monitoring (CM) DE.CM-0113

Networks and network services are monitored to find potentially adverse events.

Detect (DE) - Continuous Monitoring (CM) DE.CM-025

The physical environment is monitored to find potentially adverse events.

Detect (DE) - Continuous Monitoring (CM) DE.CM-0311

Personnel activity and technology usage are monitored to find potentially adverse events.

Detect (DE) - Continuous Monitoring (CM) DE.CM-063

External service provider activities and services are monitored to find potentially adverse events.

Detect (DE) - Continuous Monitoring (CM) DE.CM-0917

Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events.

Detect (DE) - Adverse Event Analysis (AE) - DE.AE-0214

Potentially adverse events are analyzed to better understand associated activities.

Detect (DE) - Adverse Event Analysis (AE) - DE.AE-0314

Information is correlated from multiple sources.

Detect (DE) - Adverse Event Analysis (AE) - DE.AE-0414

The estimated impact and scope of adverse events are understood.

Detect (DE) - Adverse Event Analysis (AE) - DE.AE-0614

Information on adverse events is provided to authorized staff and tools.

Detect (DE) - Adverse Event Analysis (AE) - DE.AE-0714

Cyber threat intelligence and other contextual information are integrated into the analysis.

Detect (DE) - Adverse Event Analysis (AE) - DE.AE-0814

Incidents are declared when adverse events meet the defined incident criteria.

Govern (GV) - Organizational Context (OC) - GV.OC-029

Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered.

Govern (GV) - Organizational Context (OC) - GV.OC-033

Legal, regulatory, and contractual requirements regarding cybersecurity — including privacy and civil liberties obligations — are understood and managed.

Govern (GV) - Risk Management (RM) - GV.RM-032

Cybersecurity risk management activities and outcomes are included in enterprise risk management processes.

Govern (GV) - Roles, Responsibilities, and Authorities (RR) - GV.RR-011

Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving.

Govern (GV) - Roles, Responsibilities, and Authorities (RR) - GV.RR-021

Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced.

Govern (GV) - Roles, Responsibilities, and Authorities (RR) - GV.RR-044

Cybersecurity is included in human resources practices.

Govern (GV) - Cybersecurity Supply Chain Risk Management (SC) - GV.SC-022

Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally.

Identify (ID) - Asset Management (AM) - ID.AM-014

Inventories of hardware managed by the organization are maintained.

Identify (ID) - Asset Management (AM) - ID.AM-025

Inventories of software, services, and systems managed by the organization are maintained.

Identify (ID) - Asset Management (AM) - ID.AM-038

Representations of the organization's authorized network communication and internal and external network data flows are maintained.

Identify (ID) - Asset Management (AM) - ID.AM-052

Assets are prioritized based on classification, criticality, resources, and impact on the mission.

Identify (ID) - Asset Management (AM) - ID.AM-079

Inventories of data and corresponding metadata for designated data types are maintained.

Identify (ID) - Asset Management (AM) - ID.AM-0818

Systems, hardware, software, services, and data are managed throughout their life cycles.

Identify (ID) - Risk Assessment (RA) - ID.RA-014

Vulnerabilities in assets are identified, validated, and recorded.

Identify (ID) - Risk Assessment (RA) - ID.RA-032

Internal and external threats to the organization are identified and recorded.

Identify (ID) - Risk Assessment (RA) - ID.RA-044

Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded.

Identify (ID) - Risk Assessment (RA) - ID.RA-0529

Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization.

Identify (ID) - Risk Assessment (RA) - ID.RA-082

Processes for receiving, analyzing, and responding to vulnerability disclosures are established.

Identify (ID) - Risk Assessment (RA) - ID.RA-094

The authenticity and integrity of hardware and software are assessed prior to acquisition and use.

Identify (ID) - Improvement (IM) - ID.IM-013

Improvements are identified from evaluations.

Identify (ID) - Improvement (IM) - ID.IM-023

Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties.

Protect (PR) - Identity Management, Authentication, and Access Control (AA) - PR.AA-0119

Identities and credentials for authorized users, services, and hardware are managed by the organization.

Protect (PR) - Identity Management, Authentication, and Access Control (AA) - PR.AA-0216

Identities are proofed and bound to credentials based on the context of interactions.

Protect (PR) - Identity Management, Authentication, and Access Control (AA) - PR.AA-0319

Users, services, and hardware are authenticated.

Protect (PR) - Identity Management, Authentication, and Access Control (AA) - PR.AA-0412

Identity assertions are protected, conveyed, and verified.

Protect (PR) - Identity Management, Authentication, and Access Control (AA) - PR.AA-0510

Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties.

Protect (PR) - Data Security (DS) - PR.DS-0118

The confidentiality, integrity, and availability of data-at-rest are protected.

Protect (PR) - Data Security (DS) - PR.DS-0211

The confidentiality, integrity, and availability of data-in-transit are protected.

Protect (PR) - Data Security (DS) - PR.DS-1113

Backups of data are created, protected, maintained, and tested.

Protect (PR) - Platform Security (PS) - PR.PS-0112

Configuration management practices are established and applied.

Protect (PR) - Platform Security (PS) - PR.PS-026

Software is maintained, replaced, and removed commensurate with risk.

Protect (PR) - Platform Security (PS) - PR.PS-038

Hardware is maintained, replaced, and removed commensurate with risk.

Protect (PR) - Platform Security (PS) - PR.PS-0423

Log records are generated and made available for continuous monitoring.

Protect (PR) - Platform Security (PS) - PR.PS-057

Installation and execution of unauthorized software are prevented.

Protect (PR) - Platform Security (PS) - PR.PS-065

Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle.

Protect (PR) - Technology Infrastructure Resilience (IR) - PR.IR-0115

Networks and environments are protected from unauthorized logical access and usage.

Protect (PR) - Technology Infrastructure Resilience (IR) - PR.IR-0213

The organization’s technology assets are protected from environmental threats.

Protect (PR) - Technology Infrastructure Resilience (IR) - PR.IR-0314

Mechanisms are implemented to achieve resilience requirements in normal and adverse situations.

Protect (PR) - Technology Infrastructure Resilience (IR) - PR.IR-048

Adequate resource capacity to ensure availability is maintained.

Recover (RC) - Incident Recovery Plan Execution (RP) - RC.RP-017

The recovery portion of the incident response plan is executed once initiated from the incident response process.

Recover (RC) - Incident Recovery Plan Execution (RP) - RC.RP-0220

Recovery actions are selected, scoped, prioritized, and performed.

Recover (RC) - Incident Recovery Plan Execution (RP) - RC.RP-031

The integrity of backups and other restoration assets is verified before using them for restoration.

Recover (RC) - Incident Recovery Plan Execution (RP) - RC.RP-0417

Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms.

Recover (RC) - Incident Recovery Plan Execution (RP) - RC.RP-0511

The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed.

Recover (RC) - Incident Recovery Plan Execution (RP) - RC.RP-064

The end of incident recovery is declared based on criteria, and incident-related documentation is completed.

Recover (RC) - Incident Recovery Communication (CO) - RC.CO-033

Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders.

Recover (RC) - Incident Recovery Communication (CO) - RC.CO-043

Public updates on incident recovery are shared using approved methods and messaging.

Respond (RS) - Incident Management (MA) - RS.MA-015

The incident response plan is executed in coordination with relevant third parties once an incident is declared.

Respond (RS) - Incident Management (MA) - RS.MA-023

Incident reports are triaged and validated.

Respond (RS) - Incident Management (MA) - RS.MA-034

Incidents are categorized and prioritized.

Respond (RS) - Incident Management (MA) - RS.MA-047

Incidents are escalated or elevated as needed.

Respond (RS) - Incident Management (MA) - RS.MA-0511

The criteria for initiating incident recovery are applied.

Respond (RS) - Incident Analysis (AN) - RS.AN-0310

Analysis is performed to establish what has taken place during an incident and the root cause of the incident.

Respond (RS) - Incident Analysis (AN) - RS.AN-0610

Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved.

Respond (RS) - Incident Analysis (AN) - RS.AN-0710

Incident data and metadata are collected, and their integrity and provenance are preserved.

Respond (RS) - Incident Analysis (AN) - RS.AN-089

An incident's magnitude is estimated and validated.

Respond (RS) - Incident Response Reporting and Communication (CO) RS.CO-0210

Internal and external stakeholders are notified of incidents.

Respond (RS) - Incident Response Reporting and Communication (CO) RS.CO-0310

Information is shared with designated internal and external stakeholders.

Respond (RS) - Incident Mitigation (MI) - RS.MI-0116

Incidents are contained.

Respond (RS) - Incident Mitigation (MI) - RS.MI-0216

Incidents are eradicated.

See where you stand against any framework

Connect an account and get a full compliance breakdown with mapped findings and remediation guidance — free to start.