Compliance, Mapped to Your Cloud
Assess your AWS, Azure, and Google Cloud environments against the industry frameworks and regulations your auditors expect.

PBMM (Protected B)
The Government of Canada Protected B / Medium Integrity / Medium Availability (PBMM) profile secures sensitive government cloud workloads.
Controls assessed
1. The organization identifies and selects the following types of information system accounts to support organizational missions/business functions: \[_Assignment: organization-defined information system account types_\]. 2. The organization assigns account managers for information system accounts. 3. The organization establishes conditions for group and role membership. 4. The organization specifies authorized users of the information system, group and role membership, and access authorizations (i.e., privileges) and other attributes (as required) for each account. 5. The organization requires approvals by \[_Assignment: organization-defined personnel or roles_\] for requests to create information system accounts. 6. The organization creates, enables, modifies, disables, and removes information system accounts in accordance with \[_Assignment: organization-defined procedures or conditions_\]. 7. The organization monitors the use of information system accounts. 8. The organization notifies account managers: 1. When accounts are no longer required; 2. When users are terminated or transferred; and 3. When individual information system usage or need-to-know changes. 9. The organization authorizes access to the information system based on: 1. A valid access authorization; 2. Intended system usage; and 3. Other attributes as required by the organization or associated missions/business functions. 10. The organization reviews accounts for compliance with account management requirements \[_Assignment: organization-defined frequency_\]. 11. The organization establishes a process for reissuing shared/group account credentials (if deployed) when individuals are removed from the group.
The organization employs automated mechanisms to support the management of information system accounts.
1. The organization monitors information system accounts for \[_Assignment: organization-defined atypical use_\]; and 2. The organization reports atypical usage of information system accounts to \[_Assignment: organization-defined personnel or roles_\].
The information system automatically disables inactive accounts after \[_Assignment: organization-defined time period_\].
The information system automatically audits account creation, modification, enabling, disabling, and removal actions, and notifies \[_Assignment: organization-defined personnel or roles_\]. Related controls: AU-2, AU-12.
1. The organization facilitates information sharing by enabling authorized users to determine if access authorizations assigned to the sharing partner match the access restrictions on the information for \[_Assignment: organization-defined information sharing circumstances where user discretion is required_\]; and 2. The organization employs \[_Assignment: organization-defined automated mechanisms or manual processes_\] to assist users in making information sharing/collaboration decisions.
The information system enforces \[_Assignment: organization-defined mandatory access control policies_\] over all subjects and objects where the policy specifies that: 1. The policy is uniformly enforced across all subjects and objects within the boundary of the information system; 2. A subject that has been granted access to information is constrained from doing any of the following; * Passing the information to unauthorized subjects or objects; * Granting its privileges to other subjects; * Changing one or more security attributes on subjects, objects, the information system, or information system components; * Choosing the security attributes and attribute values to be associated with newly created or modified objects; or * Changing the rules governing access control; and 3. \[_Assignment: Organized-defined subjects_\] may explicitly be granted \[_Assignment: organization-defined privileges (i.e., they are trusted subjects)_\] such that they are not limited by some or all of the above constraints.
1. The information system enforces approved authorizations for logical access to information and system resources in accordance with applicable access control policies.
1. The information system enforces approved authorizations for controlling the flow of information within the system and between interconnected systems based on \[_Assignment: organization-defined information flow control policies_\]
1. The organization: 1. Separates \[_Assignment: organization-defined duties of individuals_\]; 2. Documents separation of duties of individuals; and 3. Defines information system access authorizations to support separation of duties.
1. The organization employs the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with organizational missions and business functions.
The information system prevents non-privileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures.
The information system monitors and controls remote access methods.
The information system implements cryptographic mechanisms to protect the confidentiality and integrity of remote access sessions. The cryptography must be compliant with the requirements of SC-13.
The information system routes all remote accesses through \[Assignment: organization-defined number\] managed network access control points.
1. The organization determines that the information system is capable of auditing the following events: \[_Assignment: organization-defined auditable events_\]. 2. The organization coordinates the security audit function with other organizational entities requiring audit-related information to enhance mutual support and to help guide the selection of auditable events. 3. The organization provides a rationale for why the auditable events are deemed to be adequate to support after-the-fact investigations of security incidents. 4. The organization determines that the following events are to be audited within the information system: \[_Assignment: organization-defined audited events (the subset of the auditable events defined in AU-2 a.) along with the frequency of (or situation requiring) auditing for each identified event_\].
1. The information system generates audit records containing information that establishes what type of event occurred, when the event occurred, where the event occurred, the source of the event, the outcome of the event, and the identity of any individuals or subjects associated with the event.
The organization employs automated mechanisms to integrate audit review, analysis, and reporting processes to support organizational processes for investigation and response to suspicious activities.
The information system provides the capability to process audit records for events of interest based on \[_Assignment: organization-defined audit fields within audit records_\].
1. The information system protects audit information and audit tools from unauthorized access, modification, and deletion.
The information system backs up audit records \[_Assignment: organization-defined frequency_\] onto a physically different system or system component than the system or component being audited.
1. The organization retains audit records for \[_Assignment: organization-defined time period consistent with records retention policy_\] to provide support for after-the-fact investigations of security incidents and to meet regulatory and organizational information retention requirements.
1. The information system provides audit record generation capability for the auditable events defined in AU-2 a. at \[_Assignment: organization-defined information system components_\]. 2. The information system allows \[_Assignment: organization-defined personnel or roles_\] to select which auditable events are to be audited by specific components of the information system. 3. The information system generates audit records for the events defined in AU-2 d. with the content defined in AU-3.
1. The organization develops a continuous monitoring strategy and implements a continuous monitoring program that includes establishment of \[_Assignment: organization-defined metrics_\] to be monitored. 2. The organization develops a continuous monitoring strategy and implements a continuous monitoring program that includes establishment of \[_Assignment: organization-defined frequencies_\] for monitoring and \[_Assignment: organization-defined frequencies_\] for assessments supporting such monitoring. 3. The organization develops a continuous monitoring strategy and implements a continuous monitoring program that includes ongoing security control assessments in accordance with the organizational continuous monitoring strategy. 4. The organization develops a continuous monitoring strategy and implements a continuous monitoring program that includes ongoing security status monitoring of organization-defined metrics in accordance with the organizational continuous monitoring strategy. 5. The organization develops a continuous monitoring strategy and implements a continuous monitoring program that includes correlation and analysis of security-related information generated by assessments and monitoring. 6. The organization develops a continuous monitoring strategy and implements a continuous monitoring program that includes response actions to address results of the analysis of security-related information. 7. The organization develops a continuous monitoring strategy and implements a continuous monitoring program that includes reporting the security status of organization and the information system to \[_Assignment: organization-defined personnel or roles\] \[Assignment: organization-defined frequency_\].
1. The organization develops, documents, and maintains under configuration control, a current baseline configuration of the information system.
1. The organization configures the information system to provide only essential capabilities. 2. The organization prohibits or restricts the use of the following functions, ports, protocols, and/or services: \[_Assignment: organization-defined prohibited or restricted functions, ports, protocols, and/or services_\].
The organization updates the inventory of information system components as an integral part of component installations, removals, and information system updates.
1. The organization employs automated mechanisms \[_Assignment: organization-defined frequency_\] to detect the presence of unauthorized hardware, software, and firmware components within the information system; and 2. The organization takes the following actions when unauthorized components are detected: \[_Selection (one or more): disables network access by such components; isolates the components; notifies \[Assignment: organization-defined personnel or roles_\]\].
1. The organization conducts backups of user-level information contained in the information system \[_Assignment: organization-defined frequency consistent with recovery time and recovery point objectives_\]. 2. The organization conducts backups of system-level information contained in the information system \[_Assignment: organization-defined frequency consistent with recovery time and recovery point objectives_\]. 3. The organization conducts backups of information system documentation including security-related documentation \[_Assignment: organization-defined frequency consistent with recovery time and recovery point objectives_\]. 4. The organization protects the confidentiality, integrity, and availability of backup information at storage locations. 5. The organization determines retention periods for essential business information and archived backups.
1. The organization provides for the recovery and reconstitution of the information system to a known state after a disruption, compromise, or failure.
1. The information system uniquely identifies and authenticates organizational users (or processes acting on behalf of organizational users).
The information system implements multifactor authentication for network access to privileged accounts.
1. The information system, for password-based authentication, enforces minimum password complexity of \[_Assignment: organization-defined requirements for case sensitivity, number of characters, mix of upper-case letters, lower-case letters, numbers, and special characters, including minimum requirements for each type_\]; 2. The information system, for password-based authentication, enforces at least the following number of changed characters when new passwords are created: \[_Assignment: organization-defined number_\]; 3. The information system, for password-based authentication, stores and transmits only cryptographically-protected passwords; 4. The information system, for password-based authentication, enforces password minimum and maximum lifetime restrictions of \[_Assignment: organization-defined numbers for lifetime minimum, lifetime maximum_\]; 5. The information system, for password-based authentication prohibits password reuse for \[_Assignment: organization-defined number_\] generations; and 6. The information system, for password-based authentication allows the use of a temporary password for system logons with an immediate change to a permanent password.
The organization employs automated tools to determine if password authenticators are sufficiently strong to satisfy \[_Assignment: organization-defined requirements_\].
The organization ensures that unencrypted static authenticators are not embedded in applications or access scripts or stored on function keys.
The organization employs automated mechanisms to support the incident handling process.
The organization employs automated mechanisms to assist in the reporting of security incidents.
The organization employs automated mechanisms to increase the availability of incident response-related information and support.
1. The organization scans for vulnerabilities in the information system and hosted applications \[_Assignment: organization-defined frequency and/or randomly in accordance with organization-defined process_\] and when new vulnerabilities potentially affecting the system/applications are identified and reported. 2. The organization employs vulnerability scanning tools and techniques that facilitate interoperability among tools and automate parts of the vulnerability management process by using standards for: 1. Enumerating platforms, software flaws, and improper configurations; 2. Formatting checklists and test procedures; and 3. Measuring vulnerability impact. 3. The organization analyzes vulnerability scan reports and results from security control assessments. 4. The organization remediates legitimate vulnerabilities \[_Assignment: organization-defined response times_\] in accordance with an organizational assessment of risk. 5. The organization shares information obtained from the vulnerability scanning process and security control assessments with \[_Assignment: organization-defined personnel or roles_\] to help eliminate similar vulnerabilities in other information systems (i.e., systemic weaknesses or deficiencies).
1. The organization manages the information system using \[_Assignment: organization-defined system development life cycle_\] that incorporates information security considerations. 2. The organization defines and documents information security roles and responsibilities throughout the system development life cycle. 3. The organization identifies individuals having information security roles and responsibilities. 4. The organization integrates the organizational information security risk management process into system development life cycle activities.
1. The organization requires the developer of the information system, system component, or information system service to perform configuration management during system, component, or service \[_Selection (one or more): design; development; implementation; operation_\]; 2. The organization requires the developer of the information system, system component, or information system service to document, manage, and control the integrity of changes to \[_Assignment: organization-defined configuration items under configuration management_\]; 3. The organization requires the developer of the information system, system component, or information system service to implement only organization-approved changes to the system, component, or service; 4. The organization requires the developer of the information system, system component, or information system service to document approved changes to the system, component, or service and the potential security impacts of such changes; and 5. The organization requires the developer of the information system, system component, or information system service to track security flaws and flaw resolution within the system, component, or service and report findings to \[_Assignment: organization-defined personnel_\].
1. The information system separates user functionality (including user interface services) from information system management functionality.
1. The information system prevents unauthorized and unintended information transfer via shared system resources.
1. The information system protects against or limits the effects of the following types of denial of service attacks: \[_Assignment: organization-defined types of denial of service attacks or reference to source for such information_\] by employing \[_Assignment: organization-defined security safeguards_\].
1. The information system monitors and controls communications at the external boundary of the system and at key internal boundaries within the system. 2. The information system implements sub-networks for publicly accessible system components that are \[_Selection: physically; logically_\] separated from internal organizational networks. 3. The information system connects to external networks or information systems only through managed interfaces consisting of boundary protection devices arranged in accordance with an organizational security architecture.
The organization limits the number of external network connections to the information system.
1. The information system protects the \[_Selection (one or more): confidentiality; integrity_\] of transmitted information.
The information system implements cryptographic mechanisms to \[_Selection (one or more): prevent unauthorized disclosure of information; detect changes to information_\] during transmission unless otherwise protected by \[_Assignment: organization-defined alternative physical safeguards_\]. The cryptography must be compliant with the requirements of control SC-13.
1. The organization establishes and manages cryptographic keys for required cryptography employed within the information system in accordance with \[_Assignment: organization-defined requirements for key generation, distribution, storage, access, and destruction_\].
1. The information system implements \[_Assignment: organization-defined cryptographic uses and type of cryptography required for each use_\] in accordance with applicable GC legislation and TBS policies, directives and standards.
1. The information system protects the authenticity of communications sessions.
1. The information system protects the \[_Selection (one or more): confidentiality; integrity_\] of \[_Assignment: organization-defined information at rest_\].
1. The organization distributes \[_Assignment: organization-defined processing and storage_\] across multiple physical locations.
The organization employs automated mechanisms \[_Assignment: organization-defined frequency_\] to determine the state of information system components with regard to flaw remediation.
The organization connects and configures individual intrusion detection tools into an information system-wide intrusion detection system.
The organization correlates information from monitoring tools employed throughout the information system.
The organization employs automated tools to support near real-time analysis of events.
The information system monitors inbound and outbound communications traffic \[_Assignment: organization-defined frequency_\] for unusual or unauthorized activities or conditions.
The information system alerts \[_Assignment: organization-defined personnel or roles_\] when the following indications of compromise or potential compromise occur: \[_Assignment: organization-defined compromise indicators_\].
1. The organization monitors the information system to detect: 1. Attacks and indicators of potential attacks in accordance with \[_Assignment: organization-defined monitoring objectives_\]; and 2. Unauthorized local, network, and remote connections; 2. The organization identifies unauthorized use of the information system through \[_Assignment: organization-defined techniques and methods_\]. 3. The organization deploys monitoring devices: (i) strategically within the information system to collect organization-determined essential information; and (ii) at ad hoc locations within the system to track specific types of transactions of interest to the organization. 4. The organization protects information obtained from intrusion-monitoring tools from unauthorized access, modification, and deletion. 5. The organization heightens the level of information system monitoring activity whenever there is an indication of increased risk to organizational operations and assets, individuals, other organizations, or Canada based on law enforcement information, intelligence information, or other credible sources of information. 6. The organization obtains legal opinion with regard to information system monitoring activities in accordance with GC legislation and TBS policies, directives and standards. 7. The organization provides \[_Assignment: organization-defined information system monitoring information\] to \[Assignment: organization-defined personnel or roles\] \[Selection (one or more): as needed; \[Assignment: organization-defined frequency_\]\].
1. The organization employs integrity verification tools to detect unauthorized changes to \[_Assignment: organization-defined software, firmware, and information_\].
The information system performs an integrity check of \[_Assignment: organization-defined software, firmware, and information\] \[Selection (one or more): at start-up; at \[Assignment: organization-defined transitional states or security-relevant events\]; \[Assignment: organization-defined frequency_\]\].
1. The organization handles and retains information within the information system and information output from the system in accordance with applicable GC legislation and TBS policies, directives and standards.
See where you stand against any framework
Connect an account and get a full compliance breakdown with mapped findings and remediation guidance — free to start.
