Compliance, Mapped to Your Cloud

Assess your AWS, Azure, and Google Cloud environments against the industry frameworks and regulations your auditors expect.

56
Frameworks Supported
18
Standards Families
3
Cloud Providers
5 min
To First Results
ASecureCloud compliance report preview
AWS logo

PBMM (Protected B)

63 controls
118 checks mapped

The Government of Canada Protected B / Medium Integrity / Medium Availability (PBMM) profile secures sensitive government cloud workloads.

Controls assessed

AC-2: ACCOUNT MANAGEMENT28

1. The organization identifies and selects the following types of information system accounts to support organizational missions/business functions: \[_Assignment: organization-defined information system account types_\]. 2. The organization assigns account managers for information system accounts. 3. The organization establishes conditions for group and role membership. 4. The organization specifies authorized users of the information system, group and role membership, and access authorizations (i.e., privileges) and other attributes (as required) for each account. 5. The organization requires approvals by \[_Assignment: organization-defined personnel or roles_\] for requests to create information system accounts. 6. The organization creates, enables, modifies, disables, and removes information system accounts in accordance with \[_Assignment: organization-defined procedures or conditions_\]. 7. The organization monitors the use of information system accounts. 8. The organization notifies account managers: 1. When accounts are no longer required; 2. When users are terminated or transferred; and 3. When individual information system usage or need-to-know changes. 9. The organization authorizes access to the information system based on: 1. A valid access authorization; 2. Intended system usage; and 3. Other attributes as required by the organization or associated missions/business functions. 10. The organization reviews accounts for compliance with account management requirements \[_Assignment: organization-defined frequency_\]. 11. The organization establishes a process for reissuing shared/group account credentials (if deployed) when individuals are removed from the group.

AC-2(1): ACCOUNT MANAGEMENT | AUTOMATED SYSTEM ACCOUNT MANAGEMENT13

The organization employs automated mechanisms to support the management of information system accounts.

AC-2(12): ACCOUNT MANAGEMENT | ACCOUNT MONITORING / ATYPICAL USAGE2

1. The organization monitors information system accounts for \[_Assignment: organization-defined atypical use_\]; and 2. The organization reports atypical usage of information system accounts to \[_Assignment: organization-defined personnel or roles_\].

AC-2(3): ACCOUNT MANAGEMENT | DISABLE INACTIVE ACCOUNTS1

The information system automatically disables inactive accounts after \[_Assignment: organization-defined time period_\].

AC-2(4): ACCOUNT MANAGEMENT | AUTOMATED AUDIT ACTIONS9

The information system automatically audits account creation, modification, enabling, disabling, and removal actions, and notifies \[_Assignment: organization-defined personnel or roles_\]. Related controls: AU-2, AU-12.

AC-21: USER-BASED COLLABORATION AND INFORMATION SHARING11

1. The organization facilitates information sharing by enabling authorized users to determine if access authorizations assigned to the sharing partner match the access restrictions on the information for \[_Assignment: organization-defined information sharing circumstances where user discretion is required_\]; and 2. The organization employs \[_Assignment: organization-defined automated mechanisms or manual processes_\] to assist users in making information sharing/collaboration decisions.

AC-3(3): ACCESS ENFORCEMENT | MANDATORY ACCESS CONTROL1

The information system enforces \[_Assignment: organization-defined mandatory access control policies_\] over all subjects and objects where the policy specifies that: 1. The policy is uniformly enforced across all subjects and objects within the boundary of the information system; 2. A subject that has been granted access to information is constrained from doing any of the following; * Passing the information to unauthorized subjects or objects; * Granting its privileges to other subjects; * Changing one or more security attributes on subjects, objects, the information system, or information system components; * Choosing the security attributes and attribute values to be associated with newly created or modified objects; or * Changing the rules governing access control; and 3. \[_Assignment: Organized-defined subjects_\] may explicitly be granted \[_Assignment: organization-defined privileges (i.e., they are trusted subjects)_\] such that they are not limited by some or all of the above constraints.

AC-3: ACCESS ENFORCEMENT15

1. The information system enforces approved authorizations for logical access to information and system resources in accordance with applicable access control policies.

AC-4: INFORMATION FLOW ENFORCEMENT21

1. The information system enforces approved authorizations for controlling the flow of information within the system and between interconnected systems based on \[_Assignment: organization-defined information flow control policies_\]

AC-5: SEPARATION OF DUTIES5

1. The organization: 1. Separates \[_Assignment: organization-defined duties of individuals_\]; 2. Documents separation of duties of individuals; and 3. Defines information system access authorizations to support separation of duties.

AC-6: LEAST PRIVILEGE21

1. The organization employs the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with organizational missions and business functions.

AC-6(10): LEAST PRIVILEGE | PROHIBIT NON-PRIVILEGED USERS FROM EXECUTING PRIVILEGED FUNCTIONS1

The information system prevents non-privileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures.

AC-17(1): REMOTE ACCESS | AUTOMATED MONITORING / CONTROL2

The information system monitors and controls remote access methods.

AC-17(2): REMOTE ACCESS | PROTECTION OF CONFIDENTIALITY / INTEGRITY USING ENCRYPTION7

The information system implements cryptographic mechanisms to protect the confidentiality and integrity of remote access sessions. The cryptography must be compliant with the requirements of SC-13.

AC-17(3): REMOTE ACCESS | MANAGED ACCESS CONTROL POINTS1

The information system routes all remote accesses through \[Assignment: organization-defined number\] managed network access control points.

AU-2: AUDITABLE EVENTS13

1. The organization determines that the information system is capable of auditing the following events: \[_Assignment: organization-defined auditable events_\]. 2. The organization coordinates the security audit function with other organizational entities requiring audit-related information to enhance mutual support and to help guide the selection of auditable events. 3. The organization provides a rationale for why the auditable events are deemed to be adequate to support after-the-fact investigations of security incidents. 4. The organization determines that the following events are to be audited within the information system: \[_Assignment: organization-defined audited events (the subset of the auditable events defined in AU-2 a.) along with the frequency of (or situation requiring) auditing for each identified event_\].

AU-3: CONTENT OF AUDIT RECORDS13

1. The information system generates audit records containing information that establishes what type of event occurred, when the event occurred, where the event occurred, the source of the event, the outcome of the event, and the identity of any individuals or subjects associated with the event.

AU-6(1): AUDIT REVIEW, ANALYSIS, AND REPORTING | PROCESS INTEGRATION4

The organization employs automated mechanisms to integrate audit review, analysis, and reporting processes to support organizational processes for investigation and response to suspicious activities.

AU-7(1): AUDIT REDUCTION AND REPORT GENERATION | AUTOMATIC PROCESSING2

The information system provides the capability to process audit records for events of interest based on \[_Assignment: organization-defined audit fields within audit records_\].

AU-9: PROTECTION OF AUDIT INFORMATION2

1. The information system protects audit information and audit tools from unauthorized access, modification, and deletion.

AU-9(2): PROTECTION OF AUDIT INFORMATION | AUDIT BACKUP ON SEPARATE PHYSICAL SYSTEMS / COMPONENTS1

The information system backs up audit records \[_Assignment: organization-defined frequency_\] onto a physically different system or system component than the system or component being audited.

AU-11: AUDIT RECORD RETENTION1

1. The organization retains audit records for \[_Assignment: organization-defined time period consistent with records retention policy_\] to provide support for after-the-fact investigations of security incidents and to meet regulatory and organizational information retention requirements.

AU-12: AUDIT GENERATION13

1. The information system provides audit record generation capability for the auditable events defined in AU-2 a. at \[_Assignment: organization-defined information system components_\]. 2. The information system allows \[_Assignment: organization-defined personnel or roles_\] to select which auditable events are to be audited by specific components of the information system. 3. The information system generates audit records for the events defined in AU-2 d. with the content defined in AU-3.

CA-7: CONTINUOUS MONITORING6

1. The organization develops a continuous monitoring strategy and implements a continuous monitoring program that includes establishment of \[_Assignment: organization-defined metrics_\] to be monitored. 2. The organization develops a continuous monitoring strategy and implements a continuous monitoring program that includes establishment of \[_Assignment: organization-defined frequencies_\] for monitoring and \[_Assignment: organization-defined frequencies_\] for assessments supporting such monitoring. 3. The organization develops a continuous monitoring strategy and implements a continuous monitoring program that includes ongoing security control assessments in accordance with the organizational continuous monitoring strategy. 4. The organization develops a continuous monitoring strategy and implements a continuous monitoring program that includes ongoing security status monitoring of organization-defined metrics in accordance with the organizational continuous monitoring strategy. 5. The organization develops a continuous monitoring strategy and implements a continuous monitoring program that includes correlation and analysis of security-related information generated by assessments and monitoring. 6. The organization develops a continuous monitoring strategy and implements a continuous monitoring program that includes response actions to address results of the analysis of security-related information. 7. The organization develops a continuous monitoring strategy and implements a continuous monitoring program that includes reporting the security status of organization and the information system to \[_Assignment: organization-defined personnel or roles\] \[Assignment: organization-defined frequency_\].

CM-2: BASELINE CONFIGURATION12

1. The organization develops, documents, and maintains under configuration control, a current baseline configuration of the information system.

CM-7: LEAST FUNCTIONALITY2

1. The organization configures the information system to provide only essential capabilities. 2. The organization prohibits or restricts the use of the following functions, ports, protocols, and/or services: \[_Assignment: organization-defined prohibited or restricted functions, ports, protocols, and/or services_\].

CM-8(1): INFORMATION SYSTEM COMPONENT INVENTORY | UPDATES DURING INSTALLATIONS / REMOVALS 1

The organization updates the inventory of information system components as an integral part of component installations, removals, and information system updates.

CM-8(3): INFORMATION SYSTEM COMPONENT INVENTORY | AUTOMATED UNAUTHORIZED COMPONENT DETECTION 3

1. The organization employs automated mechanisms \[_Assignment: organization-defined frequency_\] to detect the presence of unauthorized hardware, software, and firmware components within the information system; and 2. The organization takes the following actions when unauthorized components are detected: \[_Selection (one or more): disables network access by such components; isolates the components; notifies \[Assignment: organization-defined personnel or roles_\]\].

CP-9: INFORMATION SYSTEM BACKUP12

1. The organization conducts backups of user-level information contained in the information system \[_Assignment: organization-defined frequency consistent with recovery time and recovery point objectives_\]. 2. The organization conducts backups of system-level information contained in the information system \[_Assignment: organization-defined frequency consistent with recovery time and recovery point objectives_\]. 3. The organization conducts backups of information system documentation including security-related documentation \[_Assignment: organization-defined frequency consistent with recovery time and recovery point objectives_\]. 4. The organization protects the confidentiality, integrity, and availability of backup information at storage locations. 5. The organization determines retention periods for essential business information and archived backups.

CP-10: INFORMATION SYSTEM RECOVERY AND RECONSTITUTION18

1. The organization provides for the recovery and reconstitution of the information system to a known state after a disruption, compromise, or failure.

IA-2: IDENTIFICATION AND AUTHENTICATION (ORGANIZATIONAL USERS)7

1. The information system uniquely identifies and authenticates organizational users (or processes acting on behalf of organizational users).

IA-2(1): IDENTIFICATION AND AUTHENTICATION | NETWORK ACCESS TO PRIVILEGED ACCOUNTS3

The information system implements multifactor authentication for network access to privileged accounts.

IA-5(1): AUTHENTICATOR MANAGEMENT | PASSWORD-BASED AUTHENTICATION 7

1. The information system, for password-based authentication, enforces minimum password complexity of \[_Assignment: organization-defined requirements for case sensitivity, number of characters, mix of upper-case letters, lower-case letters, numbers, and special characters, including minimum requirements for each type_\]; 2. The information system, for password-based authentication, enforces at least the following number of changed characters when new passwords are created: \[_Assignment: organization-defined number_\]; 3. The information system, for password-based authentication, stores and transmits only cryptographically-protected passwords; 4. The information system, for password-based authentication, enforces password minimum and maximum lifetime restrictions of \[_Assignment: organization-defined numbers for lifetime minimum, lifetime maximum_\]; 5. The information system, for password-based authentication prohibits password reuse for \[_Assignment: organization-defined number_\] generations; and 6. The information system, for password-based authentication allows the use of a temporary password for system logons with an immediate change to a permanent password.

IA-5(4): AUTHENTICATOR MANAGEMENT | AUTOMATED SUPPORT FOR PASSWORD STRENGTH DETERMINATION7

The organization employs automated tools to determine if password authenticators are sufficiently strong to satisfy \[_Assignment: organization-defined requirements_\].

IA-5(7): AUTHENTICATOR MANAGEMENT | NO EMBEDDED UNENCRYPTED STATIC AUTHENTICATORS 1

The organization ensures that unencrypted static authenticators are not embedded in applications or access scripts or stored on function keys.

IR-4(1): INCIDENT HANDLING | AUTOMATED INCIDENT HANDLING PROCESSES 2

The organization employs automated mechanisms to support the incident handling process.

IR-6(1): INCIDENT REPORTING | AUTOMATED REPORTING 1

The organization employs automated mechanisms to assist in the reporting of security incidents.

IR-7(1): INCIDENT RESPONSE ASSISTANCE | AUTOMATION SUPPORT FOR AVAILABILITY OF INFORMATION / SUPPORT 1

The organization employs automated mechanisms to increase the availability of incident response-related information and support.

RA-5: VULNERABILITY SCANNING2

1. The organization scans for vulnerabilities in the information system and hosted applications \[_Assignment: organization-defined frequency and/or randomly in accordance with organization-defined process_\] and when new vulnerabilities potentially affecting the system/applications are identified and reported. 2. The organization employs vulnerability scanning tools and techniques that facilitate interoperability among tools and automate parts of the vulnerability management process by using standards for: 1. Enumerating platforms, software flaws, and improper configurations; 2. Formatting checklists and test procedures; and 3. Measuring vulnerability impact. 3. The organization analyzes vulnerability scan reports and results from security control assessments. 4. The organization remediates legitimate vulnerabilities \[_Assignment: organization-defined response times_\] in accordance with an organizational assessment of risk. 5. The organization shares information obtained from the vulnerability scanning process and security control assessments with \[_Assignment: organization-defined personnel or roles_\] to help eliminate similar vulnerabilities in other information systems (i.e., systemic weaknesses or deficiencies).

SA-3: SYSTEM DEVELOPMENT LIFECYCLE2

1. The organization manages the information system using \[_Assignment: organization-defined system development life cycle_\] that incorporates information security considerations. 2. The organization defines and documents information security roles and responsibilities throughout the system development life cycle. 3. The organization identifies individuals having information security roles and responsibilities. 4. The organization integrates the organizational information security risk management process into system development life cycle activities.

SA-10: DEVELOPER CONFIGURATION MANAGEMENT4

1. The organization requires the developer of the information system, system component, or information system service to perform configuration management during system, component, or service \[_Selection (one or more): design; development; implementation; operation_\]; 2. The organization requires the developer of the information system, system component, or information system service to document, manage, and control the integrity of changes to \[_Assignment: organization-defined configuration items under configuration management_\]; 3. The organization requires the developer of the information system, system component, or information system service to implement only organization-approved changes to the system, component, or service; 4. The organization requires the developer of the information system, system component, or information system service to document approved changes to the system, component, or service and the potential security impacts of such changes; and 5. The organization requires the developer of the information system, system component, or information system service to track security flaws and flaw resolution within the system, component, or service and report findings to \[_Assignment: organization-defined personnel_\].

SC-2: APPLICATION PARTITIONING3

1. The information system separates user functionality (including user interface services) from information system management functionality.

SC-4: INFORMATION IN SHARED RESOURCES1

1. The information system prevents unauthorized and unintended information transfer via shared system resources.

SC-5: DENIAL OF SERVICE PROTECTION6

1. The information system protects against or limits the effects of the following types of denial of service attacks: \[_Assignment: organization-defined types of denial of service attacks or reference to source for such information_\] by employing \[_Assignment: organization-defined security safeguards_\].

SC-7: BOUNDARY PROTECTION29

1. The information system monitors and controls communications at the external boundary of the system and at key internal boundaries within the system. 2. The information system implements sub-networks for publicly accessible system components that are \[_Selection: physically; logically_\] separated from internal organizational networks. 3. The information system connects to external networks or information systems only through managed interfaces consisting of boundary protection devices arranged in accordance with an organizational security architecture.

SC-7(3): BOUNDARY PROTECTION | ACCESS POINTS20

The organization limits the number of external network connections to the information system.

SC-8: TRANSMISSION CONFIDENTIALITY AND INTEGRITY7

1. The information system protects the \[_Selection (one or more): confidentiality; integrity_\] of transmitted information.

SC-8(1): TRANSMISSION CONFIDENTIALITY AND INTEGRITY | CRYPTOGRAPHIC OR ALTERNATE PHYSICAL PROTECTION7

The information system implements cryptographic mechanisms to \[_Selection (one or more): prevent unauthorized disclosure of information; detect changes to information_\] during transmission unless otherwise protected by \[_Assignment: organization-defined alternative physical safeguards_\]. The cryptography must be compliant with the requirements of control SC-13.

SC-12: CRYPTOGRAPHIC KEY ESTABLISHMENT AND MANAGEMENT3

1. The organization establishes and manages cryptographic keys for required cryptography employed within the information system in accordance with \[_Assignment: organization-defined requirements for key generation, distribution, storage, access, and destruction_\].

SC-13: USE OF CRYPTOGRAPHY18

1. The information system implements \[_Assignment: organization-defined cryptographic uses and type of cryptography required for each use_\] in accordance with applicable GC legislation and TBS policies, directives and standards.

SC-23: SESSION AUTHENTICITY3

1. The information system protects the authenticity of communications sessions.

SC-28: PROTECTION OF INFORMATION AT REST17

1. The information system protects the \[_Selection (one or more): confidentiality; integrity_\] of \[_Assignment: organization-defined information at rest_\].

SC-36: DISTRIBUTED PROCESSING AND STORAGE2

1. The organization distributes \[_Assignment: organization-defined processing and storage_\] across multiple physical locations.

SI-2(2): FLAW REMEDIATION | AUTOMATED FLAW REMEDIATION STATUS3

The organization employs automated mechanisms \[_Assignment: organization-defined frequency_\] to determine the state of information system components with regard to flaw remediation.

SI-4(1): INFORMATION SYSTEM MONITORING | SYSTEM-WIDE INTRUSION DETECTION SYSTEM1

The organization connects and configures individual intrusion detection tools into an information system-wide intrusion detection system.

SI-4(16): INFORMATION SYSTEM MONITORING | CORRELATE MONITORING INFORMATION2

The organization correlates information from monitoring tools employed throughout the information system.

SI-4(2): INFORMATION SYSTEM MONITORING | AUTOMATED TOOLS FOR REAL-TIME ANALYSIS5

The organization employs automated tools to support near real-time analysis of events.

SI-4(4): INFORMATION SYSTEM MONITORING | INBOUND AND OUTBOUND COMMUNICATIONS TRAFFIC4

The information system monitors inbound and outbound communications traffic \[_Assignment: organization-defined frequency_\] for unusual or unauthorized activities or conditions.

SI-4(5): INFORMATION SYSTEM MONITORING | SYSTEM-GENERATED ALERTS4

The information system alerts \[_Assignment: organization-defined personnel or roles_\] when the following indications of compromise or potential compromise occur: \[_Assignment: organization-defined compromise indicators_\].

SI-4: INFORMATION SYSTEM MONITORING8

1. The organization monitors the information system to detect: 1. Attacks and indicators of potential attacks in accordance with \[_Assignment: organization-defined monitoring objectives_\]; and 2. Unauthorized local, network, and remote connections; 2. The organization identifies unauthorized use of the information system through \[_Assignment: organization-defined techniques and methods_\]. 3. The organization deploys monitoring devices: (i) strategically within the information system to collect organization-determined essential information; and (ii) at ad hoc locations within the system to track specific types of transactions of interest to the organization. 4. The organization protects information obtained from intrusion-monitoring tools from unauthorized access, modification, and deletion. 5. The organization heightens the level of information system monitoring activity whenever there is an indication of increased risk to organizational operations and assets, individuals, other organizations, or Canada based on law enforcement information, intelligence information, or other credible sources of information. 6. The organization obtains legal opinion with regard to information system monitoring activities in accordance with GC legislation and TBS policies, directives and standards. 7. The organization provides \[_Assignment: organization-defined information system monitoring information\] to \[Assignment: organization-defined personnel or roles\] \[Selection (one or more): as needed; \[Assignment: organization-defined frequency_\]\].

SI-7: SOFTWARE, FIRMWARE, AND INFORMATION INTEGRITY1

1. The organization employs integrity verification tools to detect unauthorized changes to \[_Assignment: organization-defined software, firmware, and information_\].

SI-7(1): SOFTWARE, FIRMWARE, AND INFORMATION INTEGRITY | INTEGRITY CHECKS3

The information system performs an integrity check of \[_Assignment: organization-defined software, firmware, and information\] \[Selection (one or more): at start-up; at \[Assignment: organization-defined transitional states or security-relevant events\]; \[Assignment: organization-defined frequency_\]\].

SI-12: INFORMATION OUTPUT HANDLING AND RETENTION13

1. The organization handles and retains information within the information system and information output from the system in accordance with applicable GC legislation and TBS policies, directives and standards.

See where you stand against any framework

Connect an account and get a full compliance breakdown with mapped findings and remediation guidance — free to start.